HMS Queen Elizabeth is 'running outdated Windows XP', raising cyber attack fears
telegraph.co.uk
telegraph.co.uk
I very much doubt when it says 'running XP' it means the general purpose computers for end-users to use.
Obviously, if these XP machines are not air-gapped, or behind hardware firewalls (with very restrictive rulesets) away from the general internet, then that's insane. Cynical as I am, I still have a hard time believing that these XP machines would be remotely accessible from outside the ship in question.
Edit: I've zoomed in on the image in question. Yes that's a Windows XP lock screen (the header of the dialog is blue, if it was Windows Server 2003, it'd be grey) However it's in 'classic theme' mode. As it's on the lock screen, then that's a 'system wide' setting, which infers that the themes service is disabled. If they've disabled the themes service, then it's safe to assume that lots of other parts have been disabled or locked down also. This doesn't make XP safe, but it does at least a) mitigate the risk somewhat, and b) indicate that steps have been taken to secure the OS.
This whole thing has gone wrong before: https://www.wired.com/1998/07/sunk-by-windows-nt/
In this case, quite literally so.
This is a multi-billion project, in the defence sector, for a major US ally.
So for one thing, it seems very likely that someone involved in the carrier project does have access to all the relevant Windows source and build infrastructure, one way or another. Relevant Microsoft staff have probably been checked as well.
In any case, obviously you can't install some OSS and then just "hire some programmers" to fix bugs in this environment.
Using Windows on naval vessels is not unprecedented. The US Navy "Windows for Warships" situation showed that it is already done, and sometimes problems are then found in trials, and those problems do then have to be fixed.
That might work for changing the text on a web site running Drupal 6 ten years later, but thinking that this sentence makes any sense when you're talking about a huge distributed system ported from probably some commercial Unix-like or even bare-metal Ada or whatever to NT then that's just a very naive sentiment.
The Royal Navy has the budget and bargaining power to sign a multi-decade support contract from the likes of IBM, HP, and Oracle. The latter already offers 24 years of support for the latest series of Solaris; maybe they can add another dozen years on top of that if you throw enough money in their general direction. By contrast, no version of Windows has been supported for more than 13 years (though they might also offer special long-term contracts), and most flavors of Linux only get 5-10 years.
Microsoft essentially does develop a custom version of Windows for mission critical state-backed infrastructure, which is most certainly not the "off the shelf" version.
Why not build the capability within the military itself to build and maintain specialized *nix-based OS's for precisely this situation? Then you have indefinite support and on-site capabilities.
It's all outsourced to contractors making such an effort much more difficult.
Systems like this have the same "we proved it worked correctly once, do you really want to screw with it?" factor as the space shuttle. Proper functionality has been verified with those systems using XP. That goes out the window if you do a major upgrade. All the layers of security you need to implement elsewhere because the OS is fundamentally outdated and insecure is still easier than upgrading the OS. Finally, if an attacker can manipulate those systems then you've already lost. Defense in depth is important but serious defense at these levels is like a "no trespassing, police take notice" sign on the inside of your bank vault above a pile of gold bars.
I agree they probably should have been based on a unix system from the beginning but a lot of these hardware/software system passed the point of no return for the OS portion of their design a decade or more ago when XP wasn't an insane choice. The industry is slowly coming around.
edit: There are a lot of people in here who need to realize that you know very little about the hardware, performance and software requirements of the system. Just because you can write code in the trendy language of the day and use docker to cover up systemic reliability issues that would cripple a LAMP stack does not make you qualified to armchair engineer a software stack that people's lives depend on. This article should make you wonder what set of constraints resulted in them running XP. They did it for a reason. Nobody runs an OS that old without a really good reason.
It supported multiple browsers, including IE7 in as late as summer 2014, because end-users in the U.S. Navy had machines that only had IE7. Countless man-hours (and U.S. taxpayer dollars) were spent to ensure all features worked in IE7, including drag-and-drop and responsive UI.
That project was the single biggest driver for me to get the hell out of the government contracting world and into the "truly" private sector. At least at a startup I can say more or less "if it works in Chrome, it works."
And by God doesn't it irk me to hear mentions of ’cyber’ as if it were an object.
[NB I meant to watch as HMSQNLZ sailed down the Forth last night - but was later than I was expecting. The MarineTraffic app currently has her doing circuits out in the North Sea past the mouth of the Forth]
[1] See https://en.wikipedia.org/wiki/USS_Yorktown_(CG-48) where a divide-by-zero error brought down the ships propulsion for almost 3 hours.
As systems become more sophisticated, manual intervention becomes that much more difficult and vulnerable systems create that much more weak spots. So screw up a system to sink a ship may one day become a reality.
Something similar to the stuxnet approach (sprinkle infected USB drives around employees hoping they'll bring it into the facility) or spearphishing will easily work on sailors whenever they bring "reading material" from shore to the ship; and from there it's just a matter of some sloppiness (which is likely to happen) and the malware will spread from the personal devices to the ship's systems.
In fact I'd be surprised if $large_nation_states aren't doing this already.
No, you most likely want a targeted attack - manufacture such USB keys, distribute them only where you want them to be, and implement various triggers for the malware to delete itself (expiry date, IP ranges, regional settings) so that it doesn't spread worldwide beyond where you want it. Infecting millions of non-target systems is undesirable, that's how Stuxnet got discovered.
Just like the rest of the world, eaten by software.
The UK's Defence Ministry later gave assurances, through questions in the UK parliament, that this is a low risk use of Microsoft Windows. However, some other suppliers have taken a different path.
The console for the new Sonar 2076 supplied by Thales Underwater Systems for the Astute class submarines, and which may be retro-fitted to other classes, are built as PCs running Linux rather than Windows.''
There was an MOD denial some years ago but the phrase 'when the ship becomes operational' was used. So possibly 'Windows for warships' during trials.
Possible there's a lot of custom software used across the navy which is only support on Windows XP. Maybe too costly to rewrite than for another system and have it interoperate with other ships etc. on the old (current) system.
https://mspoweruser.com/uks-nuclear-submarines-runs-windows-...
http://www.popularmechanics.com/military/weapons/a19061/brit...
Well then everything is fine I guess...
“The MoD can confirm that Windows XP will not be used by any onboard system when the [HMS Queen Elizabeth] becomes operational,” the spokesman added. “This also applies to HMS Prince of Wales.”
https://www.theregister.co.uk/2015/12/18/windows_for_warship...
https://ukdefencejournal.org.uk/no-our-new-aircraft-carriers...
If a mirky shot of a login screen is the only thing informing this article, it's poor journalism IMO.
The Royal Navy have a specialisd version of Windows, and I'm happy to believe they didn't spend a lot of time tarting up the login screen.
If you use a specialised, highly adapted version of an OS, why not base it on Linux? Wouldn't that be easier than paying Microsoft to be able to change the kernel of XP?
Why not something that isn't made of "swiss cheese"? With an old Linux system you have exactly the same problems as with an old Windows, probably even more.
Sticking "Linux" and "Open Source will save this" into it does not tangibly improve the situation.
(There are operating systems with a very good maintenance, stability and security track record that could be used for some of these cases, but seemingly aren't)
https://governmenttechnology.blog.gov.uk/2015/05/22/update-o...
I don't think it work out as a cost effective saving of course, as the NHS was badly hit by WannaCry as we all know.
It will have been security validated to the extreme and to assume it is anything like the commerical version is wrong
It got progressively worse with every SP pack installed but the original system was very well engineered.
I hope these computers are air gapped and USB ports are removed / disabled though.
That's damning with faint praise...
> It got progressively worse with every SP pack installed
Well, SP2 removed craptons of exploitable scenarios. Anything before that was a security nightmare, and that includes my beloved Windows 2000.
> I hope these computers are air gapped and USB ports are removed
That's optimistic. At some level, there will be some sort of port for servicing requirements anyway. Chances are that it will be an USB.
Well, I wouldn't mind if it only patched security issues. The problem was original Windows XP was very performant. I was running it on computer with 64MB RAM and it was very fast and snappy. After installing SP packs it became sluggish and I needed to upgrade my computer to be able to work.
Also, after XP my second favorite would be Windows Server 2003. Also a very solid system.
These days I only use Apple computers for work. It was Vista which annoyed me so much that I switched from MS to Apple.
> That's optimistic. At some level, there will be some sort of port for servicing requirements anyway. Chances are that it will be an USB.
Yes. I wouldn't be surprised if this was the case.
I probably would have gone with Linux anyway but if you have to do a "neutral" vendor assessment Windows doesn't look that bad. You can't just put "Windows sucks" into your report.
EDIT: I wonder why this is being downvoted.
Please don't do this. It breaks the HN guidelines (https://news.ycombinator.com/newsguidelines.html) and mars your otherwise fine comment.