The integration of conventional and nuclear systems creates significant risks of inadvertent nuclear escalation, as cyber attacks on dual-use infrastructure can blur the lines between conventional and nuclear threats, making it difficult to distinguish espionage from prelude to attack; this fundamental tension between rapidly changing threat environments and maintaining robust cybersecurity posture requires strategic choices that balance operational effectiveness with security, recognizing that complexity is inherently antagonistic to security and that best practices demand fixing identified vulnerabilities rather than accepting them as acceptable risks.
Cyber Threats and Nuclear Weapons: Risks, Scenarios, and Policy
Added:my name is raj ewing i'm a co-director at csac and it's a pleasure today to introduce one of our own herb lynn as the speaker for our seminar herb's a senior research scholar for cyber policy and security at csac and the hank holland fellow at the hoover institute he has his doctorate in physics from mit what's most striking about herb's work is how much demand he's in uh he has roles with the aspen institute the nato center for cooperative defense the salzman institute for war and peace studies he serves on the science and security board of the bulletin of atomic scientists and for the national academy of sciences he serves on the committee on international security and arms control to name just a few he's just published a book cyber threats and nuclear weapons you should all have a copy on yourself and this is something most of you will know but for those who don't he's also made his daughter's cat very famous by writing an op-ed for the los angeles times entitled what a house cat can teach us about cyber security and so herb and his daughter's cat will okay it's all yours so i i was thinking as i as i came in here for uh you know half an hour before the seminar was about to start uh i wanted to test the technology right to make sure it worked you've all had this experience of coming in and technology doesn't work and then you realize that this is the same technology that controls our nuclear weapons okay so that that you will i worry about that and at least those kinds of worries are part of what motivated this uh this study uh there's a book talk there's a flyer going around uh which will give you a 20 discount if you want to get it um here's the one slide version of the uh of the talk okay this is really the policy implications and everything that i'm going to say here basically is driving to these uh five uh five bullet points okay uh the first is is that the the entanglement of conventional and nuclear systems that is systems that have that serve both conventional warfighting and nuclear uh purposes uh raises the risk of inadvertent nuclear escalation and that to me is one of the most important uh aspects of this book and it's something that is underappreciated in the uh in the policy community second is the observation that the legacy that is what we have now the nuclear command and control system has not yet failed catastrophically right we're all still here uh and and there have been near misses and there have been corrections and and uh uh corrective actions and fixes and and so on these slides will make available to anybody by the way send me a note or you know i'll send them out to anybody um and they've been corrected fixes uh deployed um and you know by definition any modernized system won't have had that history of operation and being shaken out uh the third point is that there's a fundamental tension between chain or rapidly changing threat environment and changing your system to meet the requirements of that threat environment and maintaining adequately and adequately robust secure and secure cyber security posture you can't resolve that tension that that that's always going to be there and you have to make trade-offs this last thing about doing the best practices that is there are cyber security problems if you find a problem fix it okay that may seem obvious to you but that is often not followed in in practice and the the last point is that strategic choices can compensate for additional cyber risk to some extent not completely but to some extent and i'll i'll i will address that okay so here's the outline of the talk there's the book okay uh on cyber threats this is just a brief recap just you know three minutes on you know two two minutes on this offensive cycle capabilities but you're due to the bad guy with cyber in cyberspace they can compromise they can steal information that's the country indentiality they can change the information that's a threat to integrity uh they can make it unavailable uh to the other guy to to do something bad to the other guy you need to need to do two things you need to penetrate to the system and once you're inside you have to do something to the system those are two separate things and this that ambiguity sorry that that that that fact drives a lot of the the problem with cyber attacks and their their ambiguity so because once you penetrate you can spy which doesn't change their system at all or you can destroy stuff which does change their system and if you're the bad guy and you're watching something happening to you and you're seeing a computer intrusion on in your systems you don't know why it's there there's no way of knowing yeah offensive it mean is a reference only to the nature of the effect it has nothing to do with purpose right it doesn't have anything to do with the purpose it's a good question okay in general in pre-war scenarios offense dominates defense that is the bad guy you know the attacker can always get in given enough time before the war starts okay you have to have good intelligence that is you have to know a lot about the other guy system and if the other guy has installed yesterday's you know the yesterday's microsoft patch your your attack won't work whereas the day before the installed apache attack would have worked an attribution you're never sure immediately who's attacking you but there are some there are ways that you get some indication over the long run so prompt attribution is hard over the long term uh attribution is easier although not always guaranteed on strategy we know that it's impossible to deter low level attacks all of you who are on computers right now are being attacked right now but all of your protective devices are shielding you but it may be possible for a high-level attack that's an interesting question which we'll get to later the logic of cyber attack suggests that if you use cyber attacks early on and that you should be using cyberdecks early on in the conflict and that can lead to have that can lead to significant escalation in practice nobody really wants to secure it i hate security gets in my way it gets in your way too you have to do it but it's a pain in the ass to do and it doesn't help you do your job anymore except it makes your system available when you walk and it's a it's a holistic emergent problem what that means in in short is that it's not stay close to the mic okay um and what that means in practice uh is that it's not just a technical issue cyber series is much more than just technology i'm going to talk about the entire nuclear enterprise from the design and production and stewardship of nuclear weapons all the way down to nuclear operations every aspect of it to the extent that there's anything new in this book it's mostly about the integration of many different aspects of of the problem cyber aspects of the problem because cyber affects all of these elements command control the delivery systems um the planning aspects of it the operational aspects of and of course there's an extensive nuclear modernization program happening right now okay here's some of the cyber risks and by cyber risks here i'm talking about deliberate cyber risk that is a bad guy is seeking to intrude into your system and you are into our into u.s systems the deliberate choice to compromise our systems in some way either by stealing information or by destroying programs and and so on so could affect the design and production process for example we use the nuclear simul their simulation codes that simulate the explosion of nuclear weapons if those codes are changed somehow how it's a different question but if they could be on change in an unauthorized manner you you know you you louse up your simulation results you may have you may screw up the data you may alter data that's used to verify nuclear codes okay all those things would be bad you have many nuclear delivery systems they can be compromised right the f-35 has 10 million lines of code in it okay all of all that code is cyber vulnerability nuclear command and control there are many different aspects of it um there you can have glitches in early warning that signal a false attack um maybe it signals a uh maybe it fails to warn you when there's a real attack coming in nuclear planning nuclear planning relies on a lot of databases you can corrupt those databases nuclear decision making maybe you confuse a conventional attack and attack on conventional forces with an attack on nuclear forces that starts to get accidental you know more accidental-ish in nature okay more inadvertent in in nature maybe you can corrupt the decision-making processes of the adversary by using uh information operations against them feeding them bad information through twitter at strategic command we see on their big board a twitter feed at the bottom of it along with cnn um cyber attacks could cause a disconnect of our command authorities with our nuclear forces and by the way you also want to be able to communicate in crisis with your adversaries right in a nuclear environment you really want to be able to connect with your adversaries right how else are you going to stop a war right and the idea of being able to communi that our president is going to connect is going to talk to the russian president in the middle of a nuclear war in a nuclear environment that's highly problematic and no one really knows how to deal with that problem because the hotline of course is in the pentagon and the pentagon is located with i mean it's ground zero right there's ground zero cafe there's a restaurant right in the middle of you know in the center of the pentagon in the courtyard there it's called ground zero cafe okay and the you know the the hotline ends there okay that's not a good idea okay okay so this is gives you a sense you know obviously a fictional weapon system but there are many places where where you could get access to the uh to it okay there's a radar receiver that takes in electronic signals over the air there's a radio receiver there's a wire there wireless communications links that that eat information the operator brings along a cell phone in his pocket okay the pilot there's a usb port in the in the hull for maintenance okay um there are components in the whole thing that are uh supplied through a a law an extensive supply chain all of these are opportunities to tamper with a weapon system other points of vulnerability the maintenance system's there there's a life support systems there there's the flight control software uh collision avoidance um targeting systems uh industrial control systems that control the flaps and and the thrust and so on all these places are things that you could compromise and all these systems are supposed to be networked they operate in a big network uh so you know through dod networks and they communicate to themselves among themselves but they also communicate to the outside world they communicate to the business systems at the pentagon business systems they order things like oil and fuel and toilet paper and food okay they're all unclassified as well as ammunition uh require orders and stuff like that they're commanding control centers back at the pentagon and then all this stuff is connected is connected to the public internet okay in some indirect way in fact the secret network the one for secret information and below at the pentagon the classified network runs on top of the public network the public internet and all it is essentially is a virtual private network but it runs on the same hardware and those are all potential points of vulnerability what dod penetration testers could do with simple tools this is what gao found they could take control of a system uh in one day they could gain initial access in an hour okay security measures prevented access by remote users but not by insiders they were able to take control of the operator's terminals one of the most interesting things was this last one here they caused a pop-up message to appear on user terminal say insert two quarters before proceeding okay okay they're able to change and delete system data okay the use default password to access open source and to access open source tools okay sometimes testers these penetrations uh were detected but no action was taken they reconv they were able to reboot systems in operation all of these vulnerabilities are a fraction of the total vulnerabilities they didn't test everything tests don't reflect the full range of threats sometimes they couldn't do a review because the software was proprietary and sometimes they complain the cybersecurity testing would interfere with operations okay nevertheless program officials often said systems were secure and they discounted tests as being unrealistic i want to talk about the site and by the way some of those systems that that were identified in the report from this from which this was drawn the gao report described there they included some nuclear systems as well okay on the nuclear connection here so information technology is the lifeblood of military organization and power projection nuclear enterprise is not an exception to that right nuclear command control relies on computers for every aspect of operation every aspect of it and you know you could make the argument the subway security and resilience of u.s nuclear forces especially nuclear command control is of comparable importance to the reliability and performance of the weapons themselves this is not my conclusion this is a conclusion of defense science board of 2017. i agree with it just a little review on the uh basic principles of nuclear command and control you should never ever ever ever use nuclear weapons without proper orders but you always have to be able to use them when they are properly ordered note this tension between always and never right there's a fundamental inherent unresolvable that you can only manage that tension the military emphasizes the always we have to execute our orders when we give it all we want to be able so we always want to be able to do this when we're ordered to do so the civilian is mostly peace time they say no we i focus on the never and you can see a tension there if you're going to attack the always requirement that you would be trying to prevent or interfere with a properly authorized order that means you want to inhibit the u.s nuclear u.s nuclear action so you might see communications a cyber attack by several communications it might get in the way of authenticating the individuals who are giving orders they may compromise the orders change the orders and uh change the orders um you may be able to trick insiders into operating foolishly like not doing what they're supposed to do but contrast an attack on the never requirement enables the improper insurer the improper issuance of a launch order of a valid launch order okay and here for example it's more it's more like being able to pretend that you're the president of the united states um and taking over a wireless link to the icbms to enable it to launch under circumstances under certain circumstances um and here the the uh cyber attacks are are uh likely to to focus on compromises on trickery of people who are in the uh who are in the launch command chain you might corrupt or interfere with the ability of people to uh of decision makers to plan and coordinate with each other um confidentiality here is particularly important if you're conferring with allies you don't want the you know that that transcript to get out to the new york times these are some of the people you might be trying to confer with vulnerabilities and nuclear planning again as i said they you you gather information from many different assets uh sorry from many different databases and you have to coordinate them for example tankers the flight schedule of tankers has to be coordinated with the flight paths of bombers and if the bomber arrives at a certain point in space and the tanker isn't there you're going to have an awfully pissed off bomber pilot um corruption in the databases may not be detected for a long time especially if it's a rarely used database right if you corrupt something slowly you don't know necessarily that it's been corrupted and so you're still your backups become corrupted too over time the result of all of this is that operational plans don't get executed optimally how do you communicate with adversarial leadership this is not usually something that's considered to be part of nuclear command and control i think it should be but it isn't for reasons which i don't quite understand but you have to have communications with the adversary to affect conflict termination and you want to be able to negotiate the terms of a ceasefire okay and you have to be able to do this in a nuclear environment with leaders who want to stay hidden and all of whose ground stations are already you have to assume are known have already been targeted and destroyed so he has to have wireless communications and if you have wire if you have wireless communications that means you're emitting and somebody can home in on those emissions that's not going to make you feel very secure if even if you're flying around so and you're going to have systems on one side and on another side and they have to interoperate right a russian system and a us system have to be designed to interoperate with each other that takes a certain degree of coordination it's even hard to get microsoft top products interoperate with each other and thereby the same company right imagine trying to get a russian system and an american system or even the most cooperative environment possible some of the cyber security lessons for nuclear modernization our appetite for information technology functionality is unlimited we always want our computer systems to do more the computers that you have now that you work with on a day-to-day basis are the same sorry are better than computer systems you had five years ago they're faster they do more things they did more applications whatever okay but fundamentally the point here is that as you increase your demands on it the systems get more and more complex they get bigger and bigger and every cyber security person will tell you that the enemy of security is complexity complexity is the enemy of security more complex systems more insecurity more functionality more complexity less security so until you can get a handle on your appetite for more functionality you're going to be having systems that are more insecure and so the the the i wish i could take credit for this but there are you can choose between a system that is so simple that obviously has no errors or a system that is so complex that it has no obvious errors okay number two is a better way to design a system and design nc3 okay and that's why i fear that that we're going down bigger systems larger attack surface and just as an example consider the difference between a system that you need to support nuclear and conventional integration of warfighting efforts versus one that's primarily oriented just to just nuclear i submit to you the second one is much simpler than the first how do you build a complex system when the requirements change rapidly well you see various statements for various senior people saying we just have to do this we have to adopt ways of building systems that are fast we want to go faster faster faster we understand the sentiment here but cyber security is inherently a drag on deployment because it doesn't add any functionality for the end user you can't do anything differently really security just gets in your way okay and so it's always going to be cheaper to develop and faster to develop a less secure system always and so how are you going to build how are you going to manage that tension and you silicon valley techniques for doing software development don't change that it doesn't change that fundamental trade-off okay silicon valley says well let's do stuff we we do stuff we we put out stuff rapidly sure they do they they do a great job of putting out software that changes to user requirements very rapidly get closer to the podium all right okay um yes so silicon valley wants you to uh what wants to produce software that is responsive to users and that's fine but the who the user is in the in a nuclear command and control system is not clear right is it the commanders is it the operators it's the national command authority they all have conflicting requirements in silicon valley when they prove produce software their goal is to provide value for the user the user is king and they know who the user is that's the person who gives them money no such metric in in for nuclear command and control there's this trade-off between getting work done and having better security the success of the commander of norad actually pre-norad what turned into norad says that if possible to have convenience if you were willing to tolerate insecurity but if you want security you have to be prepared for inconvenience these words are chiseled in granite at norad um and you know day-to-day incentives drive people to ignore security requirements for example every one of you has seen the door that says do not prop this door open and it's propped open with a brick every one of you has seen that okay um military is more aligned with the always you with the always function i remember i i said that they have more incentives to compromise security functions because security makes it get in the way in the 1970s the minuteman permissive action links the things the the things that you needed special codes for to enable a nuclear weapon to go off they were set to all zeroes an eight-digit code was set to all zeros so that the operators of missiles could always fire their missiles the intent was good you wanted to prevent an off on the right side that came from the civilians no no one authorized launches the military circumvented that by making them all zeros they obeyed the orders but they were all zeros i want to talk a little bit about some selected about cyber risk and selected scenarios um there are certain irreducible uncertainties and ambiguities and this is just a sampling of when you think about uh operational scenarios okay there's uncertainty in interpreting and signaling images a lot of political theory is devoted to what does it mean to signal an adversary you may intend to show restraint but they'll see your provocation and how do you get that clear that's very hard if you're actually not talking to each other what do your actions say the other guy doesn't know we talked about ambiguity in the intent okay we made the comment that our offensive activities are in effect but they can be done for different purposes is an attack is a cyber intrusion an attack or is it espionage or is it operational preparation of the battlefield that enables you to attack later you can't tell you don't know the answer and there's no way of knowing the answer in advance there's uncertainty about the nature of a target is a target that you're hitting nuclear non-nuclear or both and if it's both which aspect of it is most concerning to you if you're the attacker you might say i just want to deal with the conventional stuff if you're the defender you may say oh but he's going after my nuclear and you're both right is it a military target or a non-military target it's an electric power plant a military or non-military target unclear and are you worrying about direct effects on the system that's being attacked or on something that it's connected to and there's something that's connected to that and you and you never know what the what the intended attack what the target the in the mind of the attacker is you know in advance okay and then you have these difficulties of prompt attribution you don't know who is it who it is that's attacking you right now and of course you may know that over the long run that doesn't help you very much because you have to know now scenario one basically this is a scenario in in which let's say china announces an attack a an exercise in which it's going to do stuff with its mobile missiles it's going to flush the mobile missiles from the garrison okay we need to know whether they're preparing for an attack so we say well the best way to get do that is to penetrate the nuclear conventional system and listen to their orders okay so we do that this is for perfectly benign purposes but the chinese see us in there and say hey wait a minute these guys are in our system now this is a dangerous situation right because the chinese now think that we are there for purposes that could be interpreted as disabling their nuclear command control system so we're there for benign purposes they are they worry that we're not there for benign purposes you can see how it might escalate attacks on dual purpose systems the early warning satellites we have or or the adversaries you have early warning satellites that are supposed to detect strategic missile launches and so they're part of the nuclear warning system but if those systems are used in a conventional war to see to improve the effectiveness of your ballistic missile defense in tactical situations in regional conflicts the other guy may try to attack your early warning satellites to disable your missile defenses but then we'll say no no they're going after our early warning satellites or strategic satellites and they're both right both sides are right and so the person whose satellites are being attacked they're going to interpret this in the worst case and be very concerned about an impending nuclear fact where the intent was really only to go after the conventional assets and imagine a situation a third scenario in which um the adversary conducts a cyber attack uh through a supply chain through the supply chain and selectively disables a couple of nuclear systems and then announces to the you know by a tell secure telephone um that uh we've done this and then you know we have to prove it you know here's some evidence that we did it and the other guy said and and you know and then he proves he can do it and now we're in a situation where potentially all of our forces have been compromised that whatever that situation is is not good for stability does it increase the likelihood that we'll do something does it decrease the likelihood it's not clear but putting doubts into our mind about what to do is not necessarily a good idea okay some of the policy implications just want to unpack a little bit of what i discussed in in in in the book here so uh this question about this is the first slide okay that i'm now unpacking for further okay the entanglement of conventional nuclear systems raises the risk of inadvertent uh conflict nuclear conflict my claim is that operational advantages in warfighting have to be weighed against an increased escalatory risk and that's a trade-off that you have to the that decision makers have to have to make um it's desirable to minimize the possibility that nuclear attack that cyber attacks on conventional assets will be seen as a tax on nuclear and i propose a number of ways of doing that but with what i call impact statements in procurement and as part of war planning to moderate the appetite of the designers of nuclear command and control and weapon software to make everything all singing all dancing you don't want software that does all of that you want to as simple as possible i think that stratcom should have acquisition authority over nuclear command and control not just be able to set the requirements but actually have good authority decision makers ought to have an independent that ought to have an independent backup system for bare functions of nuclear command control for the minimum what used to be called the minimum essential communications network and you should find a way of assuring communications channels between adversaries even during war talked about legacy nc3 not failing catastrophically the implication of that is you want to keep the old stuff and new stuff work work in operation at the same time and test the new stuff against the old stuff there's going to be a lot of resistance to that because it's going to cost money um trade-off between changing threat environment maintaining adequate cyber security you have to make trade-offs between between that and there's no way around that you have to be willing to give something up or unless you're going to have bad cyber security do best practices that means actually fix the problems you find that's harder than it sounds okay many many of you in this room may have patched security patches that you should have installed on your windows system that you haven't yet or on your mac that you haven't yet installed um and and and it's hard and this last point about strategic choices being able to to compensate for uh additional cyber risk to some extent is the following there is the question you know we have this question about you want to eliminate the launch on warning risk okay launch and warning risk is you you risk launching an attack by mistake because you have incoming warheads that are going to destroy your system your your icbms and what do you do about that and if you want to take that you if you take that off the table then you have a lot more time to figure out what's going on and my i will assert that as the probability of an attack on the icbms decreases the risk of cyber failure relatively goes up it's it's a relative position and therefore uh if i'm more worried about if i start to become more worried about cyber i want to start thinking about that now it is my also my claim that reconfiguration of nuclear forces can also buy down some of the cyber risks associated with short warning times we've talked about different different basing modes one of the ways of doing is just of course getting rid of the icbms but if you really want to keep the icbms there are other ways of basing them and so on that are less vulnerable that take away from the launch on warning uh the need for doing launch on warning so as a closing thoughts senior management at dod does understand the importance of cyber and the people on the ground who are actually at the keyboards they understand it it's the guys in the middle that don't understand they're in my experience they're the most deliberate they're the ones who think everything is fine yes we've gotten the orders from above i've issued orders down below the guys down below are doing the right thing and i don't have to think about it and they're raw as the gao found someone once asked me what's the difference between cyber threats and against nuclear versus cyber threats and conventional and there's a good question um there's two observations one is that the cyber threats against uh nuclear forces uh is likely if it's a deliberate attack is likely to be rip better and more more well-resourced you're going to get your best hackers to go after the nuclear bomb to go after the nuclear more resources and so on and sophisticated nation states are in a position to deploy a lot to throw a lot at that problem and the second is just yeah i'm going to say that i think it's obvious the stakes are higher because nuclear weapons pose an existential risk that conventional weapons don't and so i'll close on that and and open it up for some discussion thanks all right so uh the paper is open for discussion let me remind those who are zooming into uh this seminar to use the uh q a on zoom as a place to put your questions and toward the end of the hour we'll try to get to as many of those questions as as possible i we'll begin with uh our tradition of allowing the fellows students to pose first questions so yeah please and say who you are yeah i heard great talk my name is steve bowen i'm a second year fellow here at csac um my question deals with automation so i'll preface the question by saying that your talk reminded me so much of dr strangelove except it wasn't funny um and what i experienced or what i was worried about when i first saw the movie was that all it would take was one intervention in the decision making process to set off a chain of events that was more or less automatic the rest of the way through and even in the era of bombers when there were several steps they were all automated and all you would need is that one intervention to what extent does automation uh in the decision-making and the technical processes factor into your account of uh cyber security threats because it was mentioned with the lows that that was something that would just trigger i wonder to what extent that this is something that people in the national security community are concerned about or discuss at all people people who worry about launch on the the risk of launch and warning are very aware of this um i i want to emphasize that the the the way the nuclear command and control system works is not it is not you press a button and then electronic signals go out and then missiles get launched that's not how it works there are human beings actively involved in at many points uh to authenticate to confirm etc that that these orders are valid and then they press the right switch and and so on now you might say that those that those people are acting as essentially you know flesh computers okay and there's a sense in which the um the military likes to to say that that that's what we mean by personnel reliability they'll follow orders and so on but in fact they're only allowed they're they're only supposed to follow valid orders okay legal legally valid orders and there you know then there are interesting questions there and about what constitutes a legally you know a legal order um people think about this a lot the tension the fundamental underlying tension that you raise has never been resolved because the orders from the president are presumptively valid and yet you know we've seen cases in in which people say well maybe not you know i mean certainly that happened in the russian case there was one russian watch officer who who violated orders uh to to save the world now you know would if he had let the orders go through you know let the warning go through what would have happened nobody knows i'm glad we didn't find out but i mean you know maybe nothing bad would have still happened under those circumstances um but he's certainly violated towards nobody nobody doubts that so additional questions from the fellows all yeah right please identify yourself thank you in your research scholar so why would you know with regard to the last bullet that's on your screen there why would an adversary want to try to compromise an entire nuclear weapons infrastructure knowing that they might fail you know with even one or two or three weapons so you know the question is they'd have to be somebody who was trying to compromise your the whole infrastructure would have to be very sure that their compromise was going to work compromise intended to do what but to disable it you mean to make it less likely to function yes okay and so what do you and so what do you say well so you know presumably you you do that because then you would attack with conventional forces and be safe from a nuclear attack or maybe attack with nuclear forces and and and follow up with conventional ones but why i'm just not understanding what the the the concept of of disabling a adversary's force nuclear force you know why would they for the same reason that they believe in doing um dam counter force strikes of any sort a cyber attack a russian cyber attack on the united states for example for on our nuclear forces would serve the same function as sending over you know the ss-29 or whatever the back in my day it was ss-18 um nuclear wars to disable our our our minutemen you know to kill our minutemen okay so the idea is that you want to inhibit a u.s nuclear response and you know they can do that by trying to sync our ballistic missile submarines to get the bombers in you know on the ground and get the silo get you know destroy the missiles in the silos cyber is another way of trying to do that so that that's a possible rationale i'm not saying i would recommend that to them but but that's you know that that's a rationale for for why they might want to do it does that have i answered your question yeah i think okay what's the risk that if a bad guy gets into the u.s uh possible effects that the bad guy may not be trying to achieve and does that then maybe deter the bad guy from doing that in the first place ah okay so there are two separate questions there well the first question is what's the risk that the bad guy uh mucking around in the system that he doesn't really understand will have some what will do something that he didn't intend to do um that might cause some inadvertent effect i think the likelihood of that is high personally okay um i probably shouldn't say this when i'm on zoom but you know when when you're in it when you're in a system and you don't know what you're doing on it the likelihood of making a mistake is is much higher okay that that i know that from personal experience okay um and so yes i worry about that and you can certainly imagine cases in that you know something happens so for example they're attacking a uh an asset and it serves both nuclear and conventional and then they're trying to just go after the conventional but they are unable to do that and something leads over into the nuclear okay so that's that's an example of something that could happen okay so i think the likelihood of that sort of thing is high well it will deter them from doing that that's a much that's a psychological question okay and depends on the persuasiveness of the hackers over there that says no no i have this under control i can do this so this is part of why i want when i teach my students i want my students to be skeptical of technology to not believe the assurances that there's that their technical especially to give them when their high confidence oh yes we can we know we can do this you know i i really don't want my students to trust technology um and and this is this is this is part of it i i want my i want decision makers to be skeptical of the reassurances that the technologists know always know what they're doing and they're always in full control because more often than not they are not in full control and so that that part of it terrifies me quite a follow-up question from dale gates sorry nail gates on this issue of probability the question is how likely do you think the major cyber security disaster that affects nuclear systems is today was in the past and will be 10 years from now uh was in the past not very high today a little bit higher but not much and in the future much higher that's those those those are my those are my answers and i don't like those answers but i think that that's in effect uh where we're headed um i don't i mean i i i see much of what i've done here i mean i i've been able to get some of this briefing to the nuclear posture review whether they're gonna pay any attention to this sort of stuff you know dominance and high technology you know high tech is the way to is the wave of the future and and so on and it says more and more complex systems and i just don't you know i just don't i fundamentally question that underlying premise and that makes me very unpopular um so i think i think that i think cyber risk is is growing and it's because of this demand for more and more functionality hi i'm i'm julia steinberg i'm an undergraduate um earlier you're talking about the systems of technology that come out of silicon valley which obviously surrounds us and how consumer demands eg more complexity drives the products they make given that the united states military is a very big spender you just said that they really like to be technologically innovative have the highest degree of technology if they realize that it's such a big security threat as i'm sure they do why don't they partner with companies like microsoft or other weapons or weapons manufacturers to make sure that there are safer products being used that are on the simpler side mostly the stuff that they're using as far as i can tell is custom made i mean there's there's very little you know demand for you know commercial demand for nuclear command and control systems and and so you you don't you know you the the architects are are are not you know you don't have the architects working in the civilian sector i mean there's a you know it's a very specialized niche application um and and and so that that's very hard they you know the only people they know with any experience are the traditional prime contractors and boeings and and lockheeds and and so on um you say they know you say they know uh they they know about this trade-off between functionality and security actually they don't um what i mean by what i mean by that is here here's the way i'm gonna characterize i'm gonna capture it and in fact i have a quote in the in the book on this they will say we have a bunch of requirements functional requirements okay and they throw it over the transom and say make this as secure as you can okay that's what that's a way to that is a way to do it but notice in that model there's no room for the security guy to push back and say no you have to change this requirement because it makes it too insecure they don't have that conversation the person in the room the people in the room who are depre who are determining the performance requirements the functional requirements don't put security as a function i mean it's it's a constraint and that's that's that's very different the current strat common commander has said cyber security or security cyber security has to be an additive requirement he wants to say he he says that it has to be in addition to performance and inversion to speed you know and all this other stuff that's better than it was before because when it when it never was but he's not saying i am sometimes willing to trade off lower functionality for better security he has not said that and until he's willing to say that i think we're hosed that's that's the issue and i don't think that i don't think that's happened thank you aren't you go ahead uh i guess uh hi my name's uh ethan i'm a undergraduate and i'm taking professor hollins one of professor lin's classes uh this quarter but i guess my my question is about um the ambiguity you were talking about between cyber espionage and um cyber attacks in nc3 networks um i guess specifically and you kind of said that it's inherently ambiguous but i guess are there is it is it possible or is it practical to build um build these sort like worms or uh i don't know the technical term so cyber intrusions would only have a surveillance function like as a confidence building measure would that be possible or feasible or would that inherently limit uh the uh the available like um attack vectors or attack surface that that uh that the offense could use um uh to uh to gain access to the system i think what you're saying is is it possible to design an intrusion where the purpose is unambiguously one or the other yes from as far as i can tell i don't i can't give you a rigorous proof of this but as far as i can tell with the current architecture of digital computers which is a vulnerable architecture in which essentially data and programs are indistinguishable they're all ones and zeros you can't do it as far as i know i i i if there's somebody who can give me either a refutation of that claim or a defensive or more rigorous defense of that claim i'd like to to hear from you but i i i think that it's it's inherent in the neumann architecture that you can that you can't distinguish but because you can't disagree with programs they you can't do the kind of thing that you're talking about uh dan green postdoc at csac um i was wondering what kinds of interventions or experiences do you think have the potential to cause mid-level managers of the nuclear command and control system to care more deeply about cyber security um when some of them start getting fired i mean in in the end that there have to be consequences for for this sort of stuff a navy commander that runs the ship aground doesn't matter whether or not it was his fault whether he was asleep in his cabin at the time or whatever that commander is is almost always relieved of you know reliefs of command and in the navy they take seriously you know running a ship of ground i mean that's a big deal um and people lose their commands over it i've never ever ever ever heard of anybody losing a command or rank or something like that because of presiding over a cyber security breach never the usual proposals out there now in the arms control control realm is to get all sides to agree that cyber attacks on nca are banned can you foresee any technical means of verifying such a ban no um unfortunately especially because you have national leaders i i i know how santa claus through twitter being somebody reasonable he displays a photograph that comes over twitter and now your phone is effective i can imagine that happening so i i i i can't i i can't see it if there's anybody out there who would like to contest me on that again i would like to i'd like to hear from hear from them but uh i have i've looked at these things as very as carefully as i can i can't i can't see that happening hello my name is deborah chance i am an undergrad here i'm curious so obviously even within not just in the dod but also within stanford's own international security program we have classes like hacking for defense that are very popular that are focused on this let's push forward let's innovate as fast as possible i'm wondering if you think that there's any way to sort of divide the mindset of pushing forward and innovating in conventional and then separating that from restraining on the nuclear side is that possible or do you think that with such a big bureaucracy you kind of have to stick with one or the other i mean it strikes me that the yeah so let me how do i say this agile devops which is a buzzword that people use for the silicon valley as a shorthand for silicon valley ways of developing software is perfectly good for some things it's absolutely the right thing to do on even on many things okay but it's not always the right thing to do it's absolutely the right thing to do for example if i know who the user is if you're a pilot and i'm and you want to know the best configuration of displays and and and colors on the screen and you know and so on you want to pay attention to what that user says and you that that's great environment for for for for devops i do not want a devops environment to drive command and control uh system requirements when there's a pilot who wants to drop a nuclear weapon on a target of opportunity and who gets who's frustrated that he has to get higher authority sign off on it to me the getting in his way of getting you know the president to sign off i want that impediment there okay and that's not a tension that's ever going to go away so in that kind of a in that kind of an environment i i can't see uh quote devops giving the user what he wants because it's not clear who the user the user is um so that's it that's it so i think the answer is you do you you do you know you you do devops in some situations but not in all situations and the wisdom isn't trying to figure out which is which right the last question is from david elliot who says right now the strategic stability dialogue is underway between the u.s and russia as a follow-up to the biden putin need to your knowledge are the vulnerabilities that you have laid out in any part of those discussions not in track one uh i'm involved in track two with the russians uh through the national academy of sciences they're they're csac and we meet with the russians you know track two russians all the time about this and and we we talked about this um but they they're they're frustrated about it too so right i reported brings us to the end of the hour okay thank you very much thank you thanks for that [Applause] and i'm willing to answer any questions if anyone wants to send me email or anything so thanks and my apologies to those who send in questions that we didn't get to but we're out of time send email
Up Next

The Hidden Economics of War: Understanding Petrodollar Hegemony
@jaketran
1.6M views•2021-09-17

The Kashmir Conflict: Why It Risks Nuclear War Between India and Pakistan
@RealLifeLore
1.5M views•2025-05-16

Rebel to Party Transformation: FMLN Insurgent Paths to Power
@CISACatStanford
111 views•2024-04-26

Explaining the Saudi-Iranian Proxy Conflict in the Middle East
@Vox
18.2M views•2017-07-17
Related Study Plans & Knowledge Roadmaps
Structured learning paths in Political Science










![[이춘근의 국제정치 367회] 트럼프의 골든 돔(Golden Dome)에 의해 폭망한 중국몽과 북한핵](https://i.ytimg.com/vi/XggXvxBuzcM/maxresdefault.jpg)









![[CB18]Nuclear Weapons and Cyber Risks by Julia Franziska Berghofer](https://i.ytimg.com/vi/n1s8Dt1cYJc/maxresdefault.jpg)

![[CB19] Keynote:Hacking the Bomb - Cyber Threats and Nuclear Weapons by Andrew Futter](https://i.ytimg.com/vi_webp/LyQBAd1sK7s/maxresdefault.webp)














![[제7차 세종국방포럼] 억제와 위기 안정성: 진화하는 북핵 독트린과 한미의 이중과제](https://i.ytimg.com/vi/C1JgWahlmpw/hqdefault.jpg)
