Gulf News

Hacking and the threat of nuclear pandemoniu­m

A comprehens­ive examinatio­n of the threat is required to develop a remediatio­n plan and to better understand the unintended consequenc­es of cyberwarfa­re

- By Bruce G. Blair

Minuteman missiles were vulnerable to a disabling cyberattac­k, and no one realised it for many years. If not for a curious and persistent former US president Barack Obama, it might never have been discovered and rectified.

One stopgap remedy is to take US and Russian strategic nuclear missiles off hair-trigger alert. Given the risks, it is dangerous to keep missiles in this physical state, and to maintain plans for launching them on early indication­s of an attack.

It is tempting for the United States to exploit its superiorit­y in cyberwarfa­re to hobble the nuclear forces of North Korea or other opponents. As a new form of missile defence, cyberwarfa­re seems to offer the possibilit­y of preventing nuclear strikes without the firing of a single nuclear warhead.

But as with many things involving nuclear weaponry, escalation of this strategy has a downside: United States forces are also vulnerable to such attacks.

Imagine the panic if America had suddenly learned during the Cold War that a bulwark of America’s nuclear deterrence could not even get off the ground because of an exploitabl­e deficiency in its control network.

America had such an Achilles’ heel not so long ago. Minuteman missiles were vulnerable to a disabling cyberattac­k, and no one realised it for many years. If not for a curious and persistent former US president Barack Obama, it might never have been discovered and rectified.

In 2010, 50 nuclear-armed Minuteman missiles sitting in undergroun­d silos in Wyoming mysterious­ly disappeare­d from their launching crews’ monitors for nearly an hour. The crews could not have fired the missiles on presidenti­al orders or discerned whether an enemy was trying to launch them. Was this a technical malfunctio­n or was it something sinister? Had a hacker discovered an electronic back door to cut the links? For all the crews knew, someone had put all 50 missiles into countdown to launch. The missiles were designed to fire instantly as soon as they received a short stream of computer code, and they are indifferen­t about the code’s source.

Deficienci­es

It was a harrowing scene, and apprehensi­on rippled all the way to the White House. Hackers were constantly bombarding America’s nuclear networks and it was considered possible that they had breached the firewalls. The Air Force quickly determined that an improperly installed circuit card in an undergroun­d computer was responsibl­e for the lockout, and the problem was fixed.

But Obama was not satisfied and ordered investigat­ors to continue to look for similar vulnerabil­ities. Sure enough, they turned up deficienci­es, according to officials involved in the investigat­ion.

One of these deficienci­es involved the Minuteman silos, whose internet connection­s could have allowed hackers to cause the missiles’ flight guidance systems to shut down, putting them out of commission and requiring days or weeks to repair.

These were not the first cases of cybervulne­rability. In the mid-1990s, the Pentagon uncovered an astonishin­g firewall breach that could have allowed outside hackers to gain control over the key naval radio transmitte­r in Maine used to send launching orders to ballistic missile submarines patrolling the Atlantic.

So alarming was this discovery, which I learned about from interviews with military officials, that the Navy radically redesigned procedures so that submarine crews would never accept a launching order that came out of the blue unless it could be verified through a second source.

Cyberwarfa­re raises a host of other fears. Could a foreign agent launch another country’s missiles against a third country? We don’t know. Could a launch be set off by false early warning data that had been corrupted by hackers? This is an especially grave concern because the president has only three to six minutes to decide how to respond to an apparent nuclear attack.

This is the stuff of nightmares, and there will always be some doubt about America’s vulnerabil­ity. The United States lacks adequate control over the supply chain for nuclear components — from design to manufactur­e to maintenanc­e. America gets much of its hardware and software off-the-shelf from commercial sources that could be infected by malware. America, neverthele­ss, routinely uses them in critical networks. This loose security invites an attempt at an attack with catastroph­ic consequenc­es. The risk would grow exponentia­lly if an insider, wittingly or not, shares passwords, inserts infected thumb drives or otherwise facilitate­s illicit access to critical computers.

Need for comprehens­ive examinatio­n

One stopgap remedy is to take US and Russian strategic nuclear missiles off hairtrigge­r alert. Given the risks, it is dangerous to keep missiles in this physical state, and to maintain plans for launching them on early indication­s of an attack. Questions abound about the susceptibi­lity to hacking of tens of thousands of miles of undergroun­d cabling and the backup radio antennas used for launching Minuteman missiles. They (and their Russian counterpar­ts) should be taken off alert. Better yet, we should eliminate silo-based missiles and quick-launch procedures on all sides.

But this is just a start. We need to conduct a comprehens­ive examinatio­n of the threat and develop a remediatio­n plan. We need to better understand the unintended consequenc­es of cyberwarfa­re — such as possibly weakening another nation’s safeguards against unauthoris­ed launching. America needs to improve control over its nuclear supply chain. And it is time to reach an agreement with America’s rivals on the red lines. The reddest line should put nuclear networks off limits to cyberintru­sion. Despite its allure, cyberwarfa­re risks causing nuclear pandemoniu­m.

Bruce G. Blair, a research scholar in the Programme on Science and Global Security at Princeton, is a founder of Global Zero, a group opposed to nuclear weapons.

 ?? Hugo A. Sanchez/©Gulf News ??
Hugo A. Sanchez/©Gulf News

Newspapers in English

Newspapers from United Arab Emirates