Showing posts with label Cyber Warfare. Show all posts
Showing posts with label Cyber Warfare. Show all posts

Friday, April 24, 2026

Satellites - Single Point of Failure

One of the worst things you can have in combat is a single point of failure;  a linchpin upon which an entire operation depends.  If it fails, you lose everything.  For example, let’s imagine a ship has several types of sensors and all are operated off electrical power that ultimately passes through a single cable.  That cable would represent a single point of failure.  Sever the cable and all the sensor systems would be rendered inoperative by a single component’s failure.  We have seen examples in industry and the military where supposedly redundant, independent systems have failed because of an unrecognized single point of failure.  In our example, we might be tempted to proudly proclaim that we have set up multiple independent sensor systems.  After all, they’re physically separated.  They use different frequencies.  They each have their own cooling systems.  Those that need motors each have their own.  Completely independent;  nothing in common ...  except for the single power cable that no one thought about and did not recognize as a single point of failure.
 
Our military is currently constructing a single point of failure on a very large scale in the form of satellite communications.  Consider the vast number of systems that all depend on satellite communications:  drones, weapons, command and control, sensors, and on and on.  If we lose satellite communications, we lose … well … a huge chunk of our entire military capability.
 
You might be tempted to argue that satellite communications are not a single point of failure because we have dozens/hundreds/thousands of satellites and no enemy could possibly eliminate all of them.  Setting aside the highly debatable nature of that assertion, think, what do all satellites have in common?  That’s right, a very small number of control/communication stations … approaching a single point of failure.  It doesn’t matter how many satellites you have if they all depend on a very few control stations.
 
Think further, what do all control stations have in common?  An even smaller number of software programs that run them.  If an enemy can hack/virus the software (we’ve seen that it’s almost impossible to prevent hacking of military or commercial networks and programs), it instantly renders all the control stations and their associated satellites useless.
 
Well, none of that could ever happen, you say.  Except that already has and we have at least one public example.
 
A global outage across Elon Musk’s satellite network ​affecting millions of Starlink users had left two dozen unmanned surface vessels bobbing off the California coast, disrupting communications and halting operations for almost an hour.
 
The incident, which involved drones ‌intended to bolster U.S. military options in a conflict with China, was one of several Navy test disruptions linked to SpaceX's Starlink that left operators unable to connect with autonomous boats, according to internal Navy documents reviewed by Reuters and a person familiar with the matter.[1]

Think even further.  What if a key individual (a single point of failure, by definition!) were to shut down or sabotage the entire satellite system, perhaps motivated by bribes/payoffs or coerced by Chinese threats against him or his family?  Couldn’t happen, you laugh?  How about this:
 
Reuters reported last year that [Elon] Musk unexpectedly switched off Starlink access to Ukrainian troops as they sought to retake territory from Russia, denting allies' trust in the billionaire.[1]

There you have a single (non-military!) individual shutting down a satellite system because he disagreed with the military and geopolitical actions.
 
Think further still.  The single point of failure doesn’t have to involve destruction of assets, cyber attacks, or rogue villains.  It could be as simple as routine mechanical/software failure.  Here’s an example.
 
In April 2025, during a series ​of Navy tests in California involving unmanned boats and flying drones, officials reported that Starlink struggled to provide a solid network connection due to the high data usage needed to control multiple systems, according to a Navy safety report of the tests reviewed by Reuters.[1]

Given the complexity of modern systems, sometimes you don’t even know why a system failed.
 
In the weeks leading up to the global Starlink outage in August, another ​series of Navy tests was disrupted by intermittent connection issues with the Starlink network, Navy documents reviewed by Reuters show. ​The causes of the network losses were not immediately clear.[1]

Now let’s close with one of the dumbest statements I’ve heard in a while, courtesy of Mr. Bryan Clark at the Hudson Institute.
 
Despite the setbacks, the upside of Starlink – a cheap and commercially available service – outweighs the risk of a potential outage disrupting future military operations, said Bryan Clark, an autonomous warfare expert at the Hudson Institute. “You ​accept those vulnerabilities because of the benefits you get from the ubiquity it provides,” he said.[1]

In peacetime you might accept the occasional failure because the downside isn’t all that serious.  It’s not life or death … just inconvenience.  In war, it most certainly is life and death and you can’t afford systems with known single points of failure and a known, not insignificant, failure rate to begin with.
 
 
Discussion
 
Given our overwhelming dependence on satellites, do you think the Chinese are going to allow us to continue to use them, unhindered?  Of course not!  They’ll attack them physically, electronically, digitally (software), and via human operator vulnerabilities.  Anyone want to bet that there aren’t Chinese agents embedded in the military or Starlink?  One way or another, I’d be very surprised if we have many operating satellites two weeks after the war starts.
 
We see that satellite communications could be disrupted in a variety of ways:  physical destruction, cyber attacks, software viruses, sabotage, and routine failure, among other methods.  Does it make sense that so much of our military, current and future, has, as its very foundation, satellite communications?  Would any sane individual purposely build a system with that many known, anticipatable vulnerabilities?  And yet we’re doing exactly that.  Worse, we’re increasing our use of, and dependence on, satellites instead of decreasing it.
 
Consider that the military, some years ago, recognized GPS as a significant vulnerability.  All of our navigation and most of our weapons depend on GPS.  GPS was recognized as a single point of failure and the military, to their slow and belated credit, has set about mitigating that dependence.  We’re now designing systems that use alternates to GPS.  We knew we couldn’t accept a single point of failure, like GPS, and yet we’re intentionally and enthusiastically embracing satellites as a single point of failure.  That’s baffling.
 
 
 
 
______________________________
 
[1]Reuters website, “Exclusive: Starlink outage hit drone tests, exposing Pentagon’s growing reliance on SpaceX”, David Jeans, 16-Apr-2026,
https://www.reuters.com/business/media-telecom/starlink-outage-hit-drone-tests-exposing-pentagons-growing-reliance-spacex-2026-04-16/

Wednesday, October 8, 2025

AI Hacked – How Would We Know?

Since the age of sail, sailors have mastered the skill of navigation on the open seas using the stars and a sextant.  What happened when we introduced the miracle of GPS?  We completely lost our navigating skills.  Aside from a few individual throwbacks who enjoy using a sextant as a hobby, no one in the Navy can navigate without GPS.  Unbelievably, in some of the recent spate of collisions and groundings, it was discovered that bridge navigation teams had even lost the skill of fixing a position by taking bearings on known landmarks.
 
Since time immemorial, explorers have traversed the land using the stars, a map, and dead reckoning.  Our overland navigational skills increased even further with the advent of the compass.  Today, the Army has lost the ability to navigate overland without GPS.
 
Pilots used to be able to navigate cross country and hit a time on target to the second with nothing more than a map, bearings, and a stopwatch.  Today, that’s a lost skill.
 
GPS, the miracle of technology, caused us to lose our navigational skills and has made us weaker and less competent.  We have become dependent on GPS.  When our GPS systems fail or are degraded or eliminated by the enemy, we have nothing to fall back on.  Exactly like a drug addict, we have become addicted to GPS and unable to function without it.
 
What’s the next miracle of technology that we’re working so hard to acquire?  Yes, artificial intelligence (AI).  Does anyone have the slightest doubt that we’ll become utterly dependent on AI?
 
Ask a college student to write a report without using AI.  He’ll produce gibberish.  He’s lost his ability (or never developed it) to conduct research, assemble a cogent thesis, and present an intelligible, written document.  Heck, forget AI;  ask a student to write a paper without the Grammarly app and see what results.  Even simpler, ask any young adult who’s gone to public school to calculate change for a purchase in his head, without a calculator, and watch the deer in the headlights, frozen response.  We’ve become dependent on calculators and can’t even do simple arithmetic in our heads anymore.
 
Does anyone have the slightest doubt that we’ll become utterly dependent on AI?
 
The military, by the way, is attempting to make AI the foundation of our entire command and control systems.  We believe, mistakenly, that AI will give us the advantage we need to beat China.  AI, we believe, will analyze all our data, make sense of the fog of war, tell us exactly what the enemy is going to do even before he knows, and will tell us how to counter and defeat the enemy.  AI.  Magic.  One and the same.
 
Those of us who grew up during the introduction of computers are all too familiar with the well known computer programming adage, Garbage In, Garbage Out (GIGO).  Bad data in, bad results out.  AI is not immune to this phenomenon.
 
Be honest.  Does anyone seriously question what they find on the Internet?  Sure, we’ll make jokes about the Internet but does anyone actually question what they read?  Of course not.
 
Does anyone have the slightest doubt that we’ll become utterly dependent on AI?
 
Where are we going with this?  Hang in there.  We’re almost at the point of the post.  One more tidbit to assimilate.
 
Does a week go by without hearing about high level computer systems and programs, both in the military and civilian worlds, being hacked?  Nope.  And those are just the incidents that are made public.  The military and government computers and programs are hacked on a daily basis but for security reasons the incidents are kept quiet.  Despite our best efforts, various state and criminal actors routinely hack our most secure systems.  For all practical purposes, they’re unstoppable.
 
So, now put those two bits together:  absolute dependency on new technology and unstoppable hacking, and ask yourself what the result will be? 
 
The answer is easy to predict.  China will routinely hack and compromise our AI-based systems and we’ll by absolutely paralyzed because of our dependency.
 
But wait, it gets worse.  What if China hacks our AI-based systems subtly and we don’t even know it?  What if they simply manipulate the AI to give us results that give them the advantage?  We’d blindly accept the results (that’s what dependency is), never questioning them and never knowing we were being mislead and manipulated.  In fact, it would never even occur to us to ask whether the AI output was valid.
 
But wait, it gets still worse.  Even if someone was inclined to question AI results, we have no one competent enough to know what a valid result should be.  You have to have subject matter knowledge and expertise to even have an idea that something might not be right and our so-called professional warriors have no expertise (you built a ship without galvanic corrosion protection!).  So, even someone who was inclined to question a result wouldn’t have the slightest idea whether the result was or was not valid.
 
A calculator is a great tool for someone who has been trained in classical math and can recognize a garbage out result.  It is a terrible tool for someone who has no useful math skills and is unable to recognize a garbage out result.  So too, an AI command and control program could be a useful tool to a thoroughly trained and experienced professional warrior who can recognize a garbage out result.  It is a terrible tool for someone who has no useful warfighting skills and is unable to recognize a garbage out result … such as entire current flag officer corps.
 
We all recognize that networked computers are a vulnerability because if one is hacked, they’re all hacked.  We aren’t doing much to address that vulnerability but we do recognize it.  Similarly, we must recognize that AI is a vulnerability, especially when it’s being used as the basis of our highest level command and control programs.
 
Right now, just like drug dealers, we’re being given a free taste of AI to get us hooked.  We need to halt the process before we become totally addicted and helplessly dependent.  We need to regain our unaided warfighting expertise.  We do that by eliminating all non-war education (diversity, equity, gender sensitivity, climate, etc.) at the service academies, eliminating diversity crap from the leadership and ranks, ruthlessly eliminating paperwork from the daily lives of officers, eliminating deployments, bringing the fleet home for maintenance and training, start promoting a culture of acceptance of aggressiveness and ‘good’ mistakes, and start conducting daily realistic warfighting exercises and force our incompetent leadership to learn their profession.
 

Thursday, January 19, 2023

Ukraine-Russia War Lessons - Cyber

I’m seeing more and more examples of military observers and analysts drawing conclusions about future warfare from the Ukraine-Russia war.  I suspect most of the desire to draw conclusions and lessons stems not from any attempt to better understand combat but, rather, to support pre-existing opinions and positions.  For example, the US military, has fully committed to the pursuit of networks and data over firepower despite absolutely no supporting evidence that networks and data can compensate for substantially reduced firepower. The military, then, is eager to latch onto any glimmer of news that would support and justify continued construction of networks as the primary ‘weapon’ of the US military.  Whether those conclusions and lessons would apply to any but an unbelievably incompetent enemy like Russia, is of no concern to US military leadership.  Their concern is to use the ‘lessons’ to obtain continued (or increased!) funding from Congress.

 

I cannot stress enough that the Ukraine-Russia war is exquisitely unique – and largely useless – as it relates to war with China.  Russia has been astoundingly inept in every facet of war.  It is extremely unlikely that China will be equally inept.  Therefore, attempts to draw lessons from Ukraine-Russia are likely invalid.

 

Even the US military has rare glimmers that something might be wrong with the attempt.

 

After watching Ukraine take on Russia in both the real world and in cyberspace, a top American cyber official [Mieke Eoyang, deputy assistant secretary of defense for cyber policy] said the Defense Department must “think very differently” about how it will fight in both realms in the future.[1]

 

According to Ms. Eoyang,

 

… one of the things she’s seeing “is the context of the armed conflict dwarfs the cyber impacts” of the war.

 

“When you think about the physical destruction relative to the cyber disruption of what happens here, things that Russians tried to disrupt via cyber… did not have the strategic impact that they wanted, and they sought to destroy those things physically,”[1]

 

A US military official coming to the conclusion that firepower has more of an impact than cyber actions?  I’m astounded!  Isn’t that exactly what I’ve been saying for the last several years? 

 

This completely upends US military thinking and beliefs.  The primacy of firepower over networks is sacrilegious to the orthodoxy of the US military which has ceded firepower superiority to the Chinese in the desperate, misguided hope that networks and data can, somehow, compensate for the lack of destructive firepower!

 

Unfortunately, just to prove that an isolated flash of insight into reality is just that – isolated - , here’s Eoyang’s overall conclusions and cyber objectives for the US military.

 

… Eoyang said DoD is now thinking about cyber operations in the context of armed conflict in four ways:

 

Making sure government-to-government communications and networks are secure, shown in how DoD’s communications with Ukraine have helped enable its defense and intelligence sharing.

 

The importance of secure communications within the military, like how Ukraine’s military has been able to share information with forward commanders.

 

In the informational space, thinking about what it means for Ukrainian citizens to be able to communicate with the world and tell their stories through social media platforms like TikTok, Twitter and Facebook, which “has denied Russian the information environment that they want to prosecute this conflict.”

 

The inherent value in ensuring “essential” government functions. “As you look at attempts to destroy the kind of essential data that makes a country a country…such as passport records, birth records, property records…What do governments need to be able to continue to operate its essential function?” Eoyang said.

 

Sure enough, most of those objectives have nothing to do with actually fighting and winning a war.  They’re mostly about non-critical, non-combat, government functions which, by definition, are generally worthless.

 

Eoyang seems to recognize that Russia is performing incompetently, to put it mildly.

 

“I think we were [expecting] much more significant impacts than what we saw,” she said.  “And I think it’s safe to say that Russian cyber forces, as well as their traditional military forces, underperformed expectations.”[1]

 

Despite this recognition, she wants to draw conclusions that will guide our future military preparations.  Unless we have reason to believe that China will perform just as incompetently, we should be very , very, very, very, wary of drawing conclusions and lessons from the Ukraine war.

 

As I constantly say, all the networks and data in the world won’t matter one iota when a horde of enemy soldiers armed with clubs bash your brains in because you didn’t have the firepower to stop them.

 

 

 

___________________________________

 

[1]Breaking Defense, “DoD must ‘think very differently’ about armed conflict, cyber in light of Ukraine war: Official”, Jaspreet Gill, 16-Nov-2022,

https://breakingdefense.com/2022/11/dod-must-think-very-differently-about-armed-conflict-cyber-in-light-of-ukraine-war-official/


Wednesday, June 26, 2019

The Next War

ComNavOps reads hundreds of articles, posts, reports, etc. every week.  Sometimes an idea that seemed uninteresting or unimportant at the time becomes relevant at some later date.  Unfortunately, it’s often difficult or impossible to find and credit the original source idea.  Today’s post is one such example.  I read a statement by some unremembered author speculating that the next war might be all digital.  While mildly interesting, I considered it unlikely and gave it little thought.  However, today’s news that the US acknowledged initiating a cyber attack against Iran as partial retaliation for Iran shooting down two US drones, among other acts of war, prompted me to reconsider the concept of an entirely digital war.

I’m afraid that there is a certain ‘appeal’ or ‘acceptability’ to a cyber war as opposed to a kinetic war, since one can inflict great harm on a country without directly killing people.  I say “directly” because an all out cyber war would, undoubtedly, result in deaths due to a country’s loss of electricity, water, transportation, etc. for prolonged periods.  For those who are squeamish to the point of paralysis about offending enemy countries who have nuclear powers, cyber war may offer an alternative form of confrontation that they can stomach and find acceptable.

In the US, we’ve acknowledged that our power grids, water supply distribution systems, water treatment systems, air traffic control systems, hospitals, etc. are extremely vulnerable to cyber attack.  The impact of the loss of even one of these systems for an extended period is unimaginable let alone multiple systems simultaneously.  Even very low level attacks such as against our street traffic lights would result in absolute gridlock and completely paralyze large cities.

One can easily imagine “salvos” of cyber attacks being launched back and forth between countries while the civilians stagger under the impact of the “hits” and attempt to carry on with their lives.  It would be very much like the Battle of Britain, less the actual bombs.

This is already happening, to a not insignificant extent, today.  China, Russia, NKorea, and others launch cyber attacks against our military and industrial networks on a daily basis.  Presumably, we’re doing the same - at least, one hopes so!  That’s war!  We’re already engaged in limited cyber war.  I say ‘limited’ because, thus far, there appears to be a tacit agreement not to harm utilities and services that would impact each other’s civilian populations.

Having established that cyber warfare is already occurring and recognizing the possibility that an all-out cyber war is possible in the future, we can now contemplate some additional questions and ramifications.

  • Could one actually win a cyber war?  Is it possible to inflict enough pain and damage to force the opponent to concede?  Or, would this be a never ending conflict?

  • Would a cyber war inevitably reach a point where the losing country resorts to conventional kinetic warfare to compensate for cyber losses?  In other words, would one country recognize that they are losing and can’t win a cyber war and switch tactics to kinetic warfare?

  • Are there boundaries, analogous to nuclear weapons, that wouldn’t be crossed in a cyber war?  For example, if a country had the ability, via cyber methods, to cause a dam to breach and kill thousands or tens of thousands of people, would that be considered an uncrossable line or would anything go?

  • Would we draft computer operators into the armed forces to fight a cyber war?  Would we nationalize civilian networks (power and water utilities being obvious examples) for defensive efforts?

  • Would shutting down the US Internet be considered a viable element of a cyber defense?  The impact of that would be incalculable!

It seems obvious that all-out cyber warfare could constitute a future war in and of itself and, at the very least, comprise a major portion of a conventional war.  It also seems that the obvious targets of an enemy’s cyber attacks would be civilian infrastructure even more so than military networks which already have at least some degree of protection.  Our power grids, water distribution systems, transportation systems, financial systems (shut down Wall Street and see what kind of chaos results!), and even basic Internet are completely vulnerable and make for easy targets with catastrophic results.

That being the case, why are we not ‘hardening’ our non-military networks (again, power grids and water distribution systems, among others)?  The consequences of cyber war are manifold and serious yet we seem not to be focusing on them.  Our military focus seems to be acquiring shiny new toys rather than protecting our vulnerable infrastructure.  Now, one can debate whether it’s the responsibility of the military to defend our civilian digital infrastructure but, clearly, some department of the government needs to be responsible and if the enemy were dropping shells on our infrastructure it would be the military’s responsibility to defend so a very good case can be made that defending our infrastructure from cyber ‘shells’ is also the military’s responsibility.

Regardless of who takes the lead, we, as a country, need to start cyber-hardening our infrastructure.  This could well be the future of war.

Thursday, April 25, 2019

Electronic Warfare Training – The Stupidity Is Stunning

ComNavOps has long stated that we should be conducting every training exercise with full electronic warfare (EW) being applied against the training force.  This would accomplish three things:

  • It would provide valuable experience for our own offensive EW forces.
  • It would make our forces learn how to function in a heavy EW environment when none of our networks, computers, GPS, comm links, and data sharing are working.
  • It would reveal where our EW vulnerabilities are so that we can begin to correct them.

Instead, we train with only very limited EW application.  Why?  The rationale is that if we applied full EW the training would grind to a halt and be of no value.  Do you see the stupidity in this view?  The unmitigated, staggering stupidity?  If EW can bring our training to a halt, that’s exactly what we need.  That’s exactly what the Russians and Chinese, both purportedly more advanced in EW than we are, will do to us.  What are we going to do in a real war when we encounter massive EW, stop because it’s too hard?  Apparently so, because that’s what we’re doing in our training.


In a Breaking Defense article about wargames and exercises and the impact of EW,

The US has wargamed cyber and electronic warfare in field exercises, Work [Robert Work, former Deputy Secretary of Defense] said, but the simulated enemy forces tend to shut down US networks so effectively that nothing works and nobody else gets any training done. “Whenever we have an exercise and the red force really destroys our command and control, we stop the exercise,” Work said, instead of trying to figure out how to keep fighting when your command post gives you nothing but blank screens and radio static. (1)

It’s too hard to deal with EW in exercises so we quit?????  Here’s a wild thought: instead of quitting, how about ramping up the EW even more until we figure out how to deal with it.  How about forcing our military leadership to confront the ugly truth about our vulnerability?

Maybe we’re just overstating the threat?  Maybe ComNavOps is just an alarmist?  Well, former DepSecDef Work is saying the same thing I am.  Consider his warning,

The Chinese call this “system destruction warfare,” Work said: They plan to “attack the American battle network at all levels, relentlessly, and they practice it all the time.” (1)

They practice it all the time.

They practice it all the time.

They practice it all the time.

And what do we do?

We quit.

The Russians are using their EW in the field, in real combat, in Ukraine and Syria.  They’re seeing what works and what doesn’t.  They’re even applying it against our front line aircraft and, by all accounts, quite successfully.  Do you remember our own Gen. Raymond Thomas making this statement?

“Right now in Syria we are operating in the most aggressive EW environment on the planet from our adversaries. They are testing us everyday, knocking our communications down, disabling our EC-130s, etcetera.” (2)

“Disabling our EC-130s”?????  Does anyone else find that just a tiny bit alarming?

Do you remember that claim some time ago that a Russian aircraft ‘shut down’ the Burke class destroyer, USS Donald Cook in the Black Sea? (3)  We all dismissed it, at the time, but since then we’ve seen the extensive and successful Russian EW being applied in Ukraine and Syria and now I can’t help but wonder if there was an element of truth to the story.

Regardless, it’s clear that our military has a ‘head in the sand’ approach to EW.  We aren’t good at offensive or defensive EW so, instead of doing the hard work to get better, we just stop our exercises.  The sheer stupidity is staggering to behold.

ComNavOps has long stated that our over-dependence on networks is arrogant, misplaced, and foolish and is laying the foundation for defeat by leading to a state of helplessness when our electronic toys stop working.  These statements from former DepSecDef Work confirm my warnings.  We must relearn how to function when our toys die.  Every exercise should be conducted with no GPS, no network, no comm links, and no data sharing unless we can do so in the face of full EW attacks.  It’s time to quit sniveling in a corner crying ‘woe is me’ and put our big boy pants on and start relearning how to fight without our precious toys.




_________________________________

(1)Breaking Defense, “US ‘Gets Its Ass Handed To It’ In Wargames: Here’s A $24 Billion Fix ”, Sydney J. Freedberg, Jr., 7-Mar-2019,
https://breakingdefense.com/2019/03/us-gets-its-ass-handed-to-it-in-wargames-heres-a-24-billion-fix/

(2)Breaking Defense, “Russia Widens EW War, ‘Disabling’ EC-130s OR AC-130s In Syria ”, Colin Clark, 24-Apr-2018,
https://breakingdefense.com/2018/04/russia-widens-ew-war-disabling-ec-130s-in-syria/

(3)Voltaire Network website, “What spooked the USS Donald Cook so much in the Black Sea?”8-Nov-2014,
https://www.voltairenet.org/article185860.html

Monday, November 19, 2018

Secrecy Is The Enemy Of Readiness


Just as perfect is the enemy of good, sometimes secrecy is the enemy of readiness.


Let's look at a few examples.


F-22

The F-22 is artificially limited in its performance during training exercises out of fear of revealing too much about its capabilities.

F-22 pilots may be restricted from flying the F-22 the way they would fly it in combat -- due to security concerns about exposing the F-22's unique capabilities," the report said. "These restrictions limit the value of the exercises and can result in pilots developing bad habits, according to Air Force officials. (1)

On a related note, this may be an explanation for those occasional stories about foreign aircraft/pilots who claim to have defeated F-22s – along with the desire by the American military not to embarrass foreign militaries during training exercises.

For many years, the Air Force refused to commit the F-22 to operational missions – missions which would have yielded vast amounts of actual performance data.  F-22 IOC was declared in 2005 but the first combat sortie did not occur until 2014 in Syria.


Virginia

Secrecy has crippled the ability of the Navy to evaluate the Virginia class submarines.

Because Navy security rules prevent the ability to collect useful operational test data from Virginia when conducting exercises with foreign ASW capable platforms, the Navy finished IOT&E without testing the Virginia class submarine against one of its primary threats, the foreign diesel electric submarine (SSK). (2)

Refusing to test against a primary threat because of secrecy concerns is insane.


B-2 Bomber

For many years, the Air Force refused to commit its B-2 bombers to operational missions – missions which would have yielded vast amounts of actual performance data.  The first B-2 was delivered in 1993 but the first mission did not occur until 1999 in Kosovo.


Electronic Warfare

The US military has many electronic warfare (EW) platforms and the Russian’s Ukrainian and Syrian involvements would seem to offer an excellent opportunity for some real world EW testing but, so far, we seem to be withholding much of our EW capability although it has been noted that EC-130 aircraft have been ‘disrupted’ over Syria.  EW is an area that is very difficult to find definitive information on so, to be fair, it’s difficult to determine the exact extent to which our EW is, or is not, being actively employed.  However, circumstantial evidence strongly suggests that we are greatly throttling back our EW other than monitoring Russian performance.


Conclusion

While there is a strong argument to be made for secrecy, if it is taken to the extreme where we don’t even know how our systems perform then it’s been taken too far.

Another key point is that there are very few real secrets anymore.  Cyber hacking by Russia, NKorea, Iran, and China has been so successful that attempting to preserve ‘secrecy’ is probably pointless.  The benefits of actual testing now far outweigh the dubious preservation of secrecy.

As an example, when the F-117 was developed the Air Force kept it under tight wraps, refusing to even admit its existence until it was used in Desert Storm.  At the time, this was probably appropriate and effective.  Today, however, the Chinese are probably seeing our F-35 technical data in near real time!  Thanks to the Internet and proliferation of networks, the days of physical isolation of a secret platform being able to ensure secrecy are long gone.

We need to start vigorous, real world testing and find out what works and what doesn’t.  Secrecy is no longer possible.



_________________________________________

(1)Military.com website, “Air Force Missing Out on Opportunities to Employ F-22, Report Finds”, Oriana Pawlyk, 20-Jul-2018,

(2)DOT&E Annual Report 2011, p. 176

Wednesday, June 6, 2018

The Bare Minimum

In a recent post, we noted that the Army seems to be beginning to understand what a future war will entail (see, “Army Gets It”).  In particular, the Army seemed to recognize that, in combat, communications and networks would be significantly degraded and that equipment design should focus on the bare minimum rather than the ultimate possible.  This is an incredibly important point and I give the Army full credit for recognizing it (we’ll see whether they act on it, or not!).

As described by Maj. Gen. Peter Gallagher, head of the Army’s network Cross-Functional Team in a Breaking Defense article,

“Instead of optimizing the network to provide the best user experience in normal circumstances — the current standard — you optimize it to provide acceptable performance in extreme circumstances.” [article’s emphasis] (1)

This is worth restating …  We need to design for the bare minimum acceptable performance and design it in such a way as to ensure that minimum level is met regardless of circumstances.  We need a bare minimum baseline level of performance that the enemy cannot hinder.

Yes, we can also design in greater performance and, if circumstances permit (the enemy’s countermeasures aren’t present or aren’t as effective as anticipated), then we can enjoy the enhanced performance.  The point is that we can’t train to, and become dependent on, a higher level of performance.  We need to train to the bare minimum.

Hand in hand with designing to the bare minimum acceptable performance, we need to test our designs to the maximum extent possible.  ComNavOps has harped on this and will continue to do so.  The typical scripted, simplistic tests that currently pass for operational testing have to be dropped in favor of the most difficult tests we can devise because that’s the level of difficulty we’ll face in combat.

We need to make every effort to break our own designs so that we can learn how to build them so that the bare minimum acceptable performance is available no matter the circumstances.

That networked cooperative engagement type of capability sounds great on paper but will it function in combat?  Let’s get our best electronic warfare aircraft to plan and execute an attack on a Navy surface group.  Let’s give them access to every spec and secret of our networking so that they can take advantage of weaknesses.  You can bet China has all our specs and secrets and will do exactly that.  Let’s see if the group can establish and maintain a coherent tactical picture and a functional network in the face of that kind of attack.  If not – and I doubt they can – then we need to define the bare minimum acceptable performance and ensure that it is so secure that nothing can disrupt it.




_________________________________________

(1)Breaking Defense website, “Can’t Stop The Signal: Army Strips Down Network To Survive Major War”, Sydney J. Freedberg Jr., 26-Mar-2018,


Thursday, September 14, 2017

USS McCain Cyber Attack Investigation

The Navy is investigating the possibility that cyber hacking was involved in the recent collision between the USS McCain and a merchant ship (1).  The Navy is doing this as a cyber warfare test case exercise rather than because anyone believes that cyber hacking occurred.  I so often criticize Navy leadership but this deserves accolades.  This is an excellent opportunity to do a live warfighting test of the Navy’s counter-cyber capabilities and to begin establishing procedures.  Who knows, maybe there was hacking involved?  Until you do the investigation, you won’t know.  Therefore, treat it like there was an attack until you prove otherwise.  That said, please don’t misconstrue what I’m saying.  I’m not even remotely suggesting that a cyber attack occurred.

One interesting aspect of this incident that the article points out is that a cyber attacker would have been more likely to hack the merchant ship’s systems, causing it to steer into the McCain, than to try hacking the destroyer’s systems.  That presents a challenge from an investigative perspective, in trying to get access to the merchant ship’s systems.  That, in itself, is a lesson learned, already!

I would also hope that the investigation might uncover cyber vulnerabilities, as they proceed, even they weren’t exploited.  There is nothing but good that can come from this.

This needs to become routine and, indeed, it appears that it will be.

“The Navy is making cyber investigations automatic after any mishap, starting with the at-sea collision that killed 10 sailors aboard the USSMcCain.”

That’s outstanding, if overdue.  We know that China, Russia, NKorea, and Iran are conducting cyber attacks on US systems routinely – and that’s only from the incidents that have been made public!  There are, undoubtedly, many more that have not been publicized.

I cannot say enough good about the Navy’s action on this.  In fact, the only negative is how long it has taken the Navy to initiate this investigation.  They should have been on the case immediately but, hey, this is the first test case so I’ll cut them some slack.

Well done, Navy!


___________________________________

(1)Breaking Defense website, "Was The Merchant Ship Hacked? McCain Collision Is First Run For Navy Cyber Investigators",Sydney J. Freedberg, Jr., 14-Sep-2017,