The US nuclear forces’ messaging system finally got rid of its floppy disks
c4isrnet.com
c4isrnet.com
* Their maintenance is well understood - every fault that is likely to happen has happened and has been recovered/repaired from. It's very unlikely there will be new surprised down the road.
* Their degradation is well understood - it's been around long enough that parts have failed and have been repaired.
* Isn't easily communicated with through modern tech - no USB ports, no network access - people aren't picking up floppy disks in the car park and plugging them in.
* Robustness to electromagnetic interference - the bits are so big that a few electrons being knocked out of the way won't cause an issue.
* Software well understood and tested over time - the only way to _really_ trust software is by having it work without failure.
* Simple implementation - because there's no computational space or power, it only does the minimal it needs to. It's not rendering a GUI, it's not running some complicated neural network.
Old hardware isn't sexy, but it does work. I still use an oscilloscope with a phosphor display and a programmable power supply with instructions on a floppy disk. Floppy disks occasionally fail, but there's no substitute for making good backups over several mediums/locations.
Actually, I'm not even thinking about floppy disks vs X. Rather about qualitative changes as a whole.
Then again, armies are known to prepare for the previous war. In WW-1 they used trenches and then came the machine-gun and the gas. In WW-2 all soldiers were prepared against gas, the French dug the Maginot line and the Germans just skipped around. Now we have amazing tanks but the next war is online...
() I have to correct myself: NASA was looking for 8086 chips in 2001 - not 286 chips a few years ago. https://www.geek.com/chips/nasa-needs-8086-chips-549867/
But then I think of all the amazing people (that are on youtube) who restore old technology, and build replicas, etc, and I feel okay again about human knowledge.
But I think it is possible that as time goes on, knowledge about these systems can get lost, even if they're simpler to understand.
As long as there's engineers, there will be hope ;)
Old equipment is actually interesting to work on -- difficult, but interesting. It's also very valuable for understanding modern hardware at a deep level that isn't often taught anymore.
How many people do you know who have actually replaced and aligned the heads on a UYH-3 or run end to end tests on serial data channels that traverse thousands of feet and multiple switchboards from a UYK-43?
I think that's interesting and valuable on its own from an academic/research/nostalgia perspective, but not when we're talking about maintaining systems critical to the functioning of a nuclear weapons arsenal.
Read my comment in context and it will become quite clear.
You're also less likely to be able to find people willing to train in something they know is obsolete and will have no utility outside the job at hand, which means you have to spend more money to find and train these people.
I guess all this is less of a problem in the military, where you do as you're told, but still.
The difficulty in finding people experienced with floppies is a choice made, a burden taken on due to a lack of willingness to use more-current technology.
Not saying bleeding-edge whiz-bang tech is a great idea for nuclear weapons control and comms systems, but when it's hard to source parts, and hiring new people usually requires extensive training on technology they've never seen before and will never see again, that's a problem.
Given the possibility of hardware bugs; eg FOOF, Intel dev bug, outdated hardware is well tested hardware, and as such, is arguably safer than newer, less-well tested hardware.
On the other hand. Based on the article, it sounds like maintaining the nuclear launch system frequently involves working with soldering irons and microscopes, manually replacing individual wires, and it takes years of training to reach an acceptable skill level. That has the potential to be nearly as dangerous as unreliable code.
I know I'm being pedantic, but no such system exists. The best you can do is reduce the probability of failure to an acceptable limit.
Especially since this was a military system, some team, somewhere, estimated the Mean Time To Failure for this system and was satisfied with the answer.
I suspect here you're thinking about mainstream OSes, like Linux, one of the BSDs, etc.
But there are quite a few very small, well-tested (RT)OSes that are actively maintained and suitable for the "absolutely must not fail ever"[0] use case.
[0] Which is, of course, impossible, but you'll get a lot closer with a modern realtime OS written to purpose vs. a Linux-type deal.
I am not so sure I want “Rapid Agile” development for something that literally controls nuclear missiles.
Yet it definitely is designed for that.
I wonder if they ever feels frustrated.
No one will be changing the Nuclear launch systems often where never ending iteration is a threat.
One thing that agile solves that introduces the most instability into a project is the ability to constantly alter scope. It takes a lot of good management to make sure that changes in scope don't have secondary or tertiary order effects, that would be my focus for a high reliability agile process.
I work in safety critical software, my biggest problem with agile (and other popular development methodologies) has always been that there is too much equivocation and other semantic games by their advocates to turn into something useful to me.
When we have a development tool vendor on site they often ask if we're "waterfall or agile?" I hate this question because the real answer is "neither, but sorta both, and can we just move on because it's not going to fit into your simplistic model of the world?"
`git commit -m “Fuck fuck fuck, forgot to replace the launch API endpoint with a mock one.”`
Scrum master: “Let’s implement the stuff with the highest customer value first.”
Developer A: “I guess that means being able to launch the nukes.”
Developer B: “Yeah. Auth can come later.”
Developer C: “Nobody answered us about how they want the abort sequence to work. I guess we’ll defer it to the next sprint.”
https://en.wikipedia.org/wiki/Permissive_Action_Link#Develop...
Hunter/Gatherer , hunter12, Get IT.
lol and ROL. my gentlemen. women. polar bears, whatever.
I approve. Just making a joke.
I mean (man), this is totally RAD.
They're making Star Wars and Star Trek references, so 'rad' is cool too, right?
Or it's an early/late 1st April story.
https://media.defense.gov/2018/Oct/09/2002049591/-1/-1/0/DIB...
The final release of that paper along with other SWAP study publications can be found here[2].
Is it even possible to fully secure the supply chain?
Introducing any outside code or hardware is a liability. Unless there is a really urgent problem, I think they should just freeze their entire computer platform, that way they can eliminate any chance of any new threats.
I can not possibly imagine any cost justification for doing so. I have no problem with taxpayer money being spent to keep ancient computers running forever. Keeping our nuclear missiles secure is priceless.
What new features do they even need that they don't have now?
The thought of some ux monkey using npm anywhere near our ICBMs makes my physically ill.
That's not the question you should be asking. The question you should be asking is, what features would the Commander in Chief want?
Almost spilled my coffee reading this one.
FYSA[1], would it surprise you if that figure was precisely zero?
I am quite certain that there are no Chinese back doors in hardware that was put in the ground in the early 1980s.
Security wise, we can only go downhill from there.
They do make a fairly substantial effort.
This was the system used to pass early warning to the Patriot anti-missile (Scud) batteries during the first Gulf War.
Internetworking the Air Force system to an Army system was considered revolutionary in 1991. Today, it would be equivalent to "stone knives and bearskins".
not that the base computer for personnel and other records was much more modern, cards were still used till 89 for many applications; this was on a Sperry 1100/70 ? I remember my first turbo pascal program was used to replace a Sperry program used to upload card images to the system; we still had paper cards for some departments.
Well that sounds like a disaster waiting to happen.
After a tour any one of them could be a VP of Engineering at a FAANG or Unicorn, and they generally choose to remain in the public sector because money isn't the most important thing in their lives.
...or perhaps it's a much more simple risk probability v. consequence severity decision?
That's a very risky assumption to make. There are many attack vectors besides TCP/IP: social engineering, side-channel attacks, EM pulse, backdoors in ICs...
The claim is: "No IP address == unhackable."
So, for a second stop assuming we are in a nuclear bunker. There are many unconnected systems that are still hackable. For example, the Stuxnet worm was able to infiltrate an unconnected SCADA system using USB exploits. Many systems radiate data in EM and ultrasonic (side-channel). And obviously, there are known and unknown backdoors in PCBs, ECs, and ICs. All of these do not require an IP address.
I would even argue that having an IP address can improve security by increasing monitoring, improving continuous security updates and decreasing a false sense of security. This was the original goal of DARPA all along.
So not just any thumb drive, an expensive thumb drive.
Most have replaced the unit with a floppy simulator that takes an SD card (or USB key?).
The load takes just as long. But it doesn’t fail (forcing you to get an undamaged disk and start over).
I wonder if that’s why they say they got rid of the floppy disk. Maybe they maintained the underlying tech.
MAM-A/Mitsui has tested their Gold reflective layer CD-Rs with their Mitsui dye, to withstand
the full spectrum of light, same as the sun, for 100 continuous hours without damage.
Using data from tests like these, industry standard guidelines predict that MAM Gold CD-R
will last greater than 100 years! (In fact, if you extend the data, MAM-A predicts a lifetime of
up to 300 years before failing at the Orange Book limit of 220 CPS)Floppies are really just tape in a disc format, and use heads to read high and low signals and deduce the 1s and 0s.
It stands to reason they should last quite a long time considering audio/video/data tapes can last over 50 years.
I wonder what the capacity of VHS tape is, given the restrictions of the NTSC modulation? I believe, back in the 80’s, someone made a ISA card for PC backup to VHS.
NTSC video signals offer a lot of bandwidth but very very few promises about the quality of the reproduction of the stored waveform
5,25" floppies (especially lower density variants like the ones you mention) are quite reliable indeed, but the most recently common 1.44 MB 3,5" floppy is terrible.
However, after most people had moved on, when I did use more recently-manufactured ones, they were indeed terrible.
My theory is that, when Zip disks and CD-Rs took over and people stopped using 1.44MB floppies, the manufacturing of them changed, and both the disks and the drives became much crappier than they used to be. The drive manufacturing moved from Japan to Thailand, for instance, for some of the drives I looked at, and the components were noticeably crappier (drive motors much smaller, for instance). These were the days when every PC had a 1.44MB drive just for Windows XP drivers, and no one ever used the drive for anything else because it was just too small, so the OEMs really cut back on the quality since the drives weren't expected to be used much.
But back in the early 90s, it wasn't like that; those disks were totally bulletproof, just like all the other floppies.
Even the Windows support of CDs has gone to shit. Windows 10 usually can't figure out if the burned CD was already ejected and inserted with a fresh one, and randomly retains files from the previous burn.
Ripping audio CDs is slower than it used to be as the drives seem to become unbalanced.
You are right that at some point they started making (much) worse quality 1.44MB floppies (and drives, probably, though I have had nothing but good experiences with mid-2000's floppy drives so far), but I still say they're much less reliable overall than most 5,25" formats.
I say this partly because I have a retro-computing hobby and when acquiring random floppies from various places my experience is that 360K floppies from the mid-80's almost invariably still work fine while DD and HD 3,5" floppies from the late 80's to mid 90's are about 50-75% unreadable garbage at this point. They just don't survive. I also remember having to throw out a lot of 3,5" floppies (name-brand, too; Sony, Verbatim, etc...) due to them becoming unreadable in just a few years in the late 90's.
I mean, it's not surprising. Each bit is simply much physically larger on a 5,25" floppy.
So be thankful they didn't reinvent those, only using plastic instead of paper based card. Though plastic punched cards would last a very long time and also be imune to EMP, water...many things that other forms of media fall foul of.
Just don't get the storage capaicty there and if they are using systems that fit data on a floppy. Well, a CD based media would perhaps be overkill.
As for CD quality, that can vary a lot with some lasting since day one, others - rusting away (literally I have old CD's from the early days, some fine, others have rust holes due to impurities in manufacture).
But like most things, you don't appreciate the quality of the product until time has past and it still just works.
Don't forget, CDs have been out since 82, and they were not the first optical disc format around, either.
Tapes however, can last 50+ years. It's a much better medium than most think it is, for analog or digital storage. Heck, a reel to reel tape unit offers the best analog sound quality you can get.
Tape has done well, however when you look at how it was used and how it is used today. The density of data is much tighter today than the 80's era. So tolerance of errors was greater and more forgiving as data would be stored in a larger area, so a few atoms going adrift won't stand out, when you get into density when a few atoms is your data, errors are statistically more prone to happen.
I fully concede it’s security by obscurity, though. A technician possessing any experience with that hardware is probably going to make short work of its security measures.
From what I understand, military personnel generally "operate" equipment and technologies that are built and designed by private industry. I can only imagine the idiotic buzz-word sales pitch that some whiz-kid fast-talking slime-ball in a suit from a fancy looking tech company made to some meat-head, decorated military general with no understanding of what a digital threat model is and barley knows how to check his email on a windows 7 machine on IE, all for quick federal contract. I hate it.
Secondly, how does one replace a 8 inch drive (most likely MFM interfaces) with a solid state disk?
Probably something like that.
https://www.pbs.org/video/american-experience-command-and-co...
Is this article a troll, or is the Air Force just trying to be 'cool'.
Why wouldn’t the Air Force be full of geeks?
In other words, the Air Force (and other branches) can, indeed, be "cool."
Did SuperMicro make the board?
Suppose for the moment that they did. Surely you're not going to stake your reputation on an unconfirmed rumor from Bloomberg for which no single shred of hard evidence (or evidence at all, frankly) was ever offered, because that would just be silly. So what's your point?