News: 1729539013

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

(2024/10/21)


Interview This month, presidential hopeful Donald Trump got a tool in his arsenal, some allegedly "unhackable" communications kit, and The Register has talked to the man behind the operating system, who also ran for the US Senate on a campaign to get self-driving Teslas off the road and is on something of a crusade about the matter.

Dan O'Dowd, founder of Green Hills Software, is a curious character - a little-known billionaire who has earned his spurs writing very secure code sold to the government and military, which he claims is "unhackable." This hasn't gone down well with some in the security community.

"Anyone who claims that an OS is "unhackable" shouldn't be trusted, simply based on the ludicrousness of the claim," cryptography expert Bruce Schneier told The Register . "No respectable security professional would ever say something like that."

[1]

O'Dowd is a 1976 Caltech graduate who developed a passion for extreme security, and in 1982, set up a firm to develop the most secure operating system possible. The result was over a billion-dollar payoff and allowed him to develop a personal style that - given the money involved - could be described as eccentric.

[2]

[3]

He has a Tyrannosaurus Rex skull in his office (with the other 57 percent of the skeleton in storage) and owns one of the world's most valuable coin collections. But when it comes to security he's an absolute nerd. He claims that the Integrity-178B operating system [4]used by Trump , the FBI, the US military, and others, is effectively unhackable, and it has paid off.

"This is the result of 40 years of technology. The goal was to build an operating system that could be used in the highest security, highest reliability applications, because there wasn't one. It is a completely original design, unlike anything else, unlike Windows or Linux," he said.

[5]

"It is designed with a simple principle that everything must be secure before there is no feature that goes in until we figure out how to make it secure. Completely secure. None of the other operating systems that you will have did that. They put the features in, and then they thought about later, how do we make them secure? Well, it's already too late."

[6]

O'Dowd's on a mission for security on and off the road - Click to enlarge

To date, the Integrity-178B operating system has been certified to the international [7]Evaluation Assurance Level 6. Level 7 tends to be rarely pursued due to the complexity.

The key, he argued, was simplicity. The operating system has around 10,000 lines of code, compared to the millions in commercial software. Each line of code is scrutinized by a separate and larger coding team, who are financially incentivized to find flaws.

"We had to get the source code to the NSA to have them evaluated. They did a full evaluation and checked we have proof of security in the underlying software, and they had the source code," he said. "They said we don't just want the binary to see if we can find a way through it. You have to give us the source code."

But there is another factor in this - security by obscurity. Integrity-178B and has a very small attack window - it's used mainly in military and government circles and the exposure to common-or-garden hackers is very small.

[8]

The OS is used in very restricted circumstances on military and law enforcement systems, and the US military is [9]pretty stingy on bug bounty payouts, despite the best efforts of Katie Moussouris and others to improve that situation. Putting the OS in the hands of skilled white-hat hackers might lead to flaws being found, however.

O'Dowd made over a billion dollars selling his OS and is now looking to expand operations for high-value targets, like Trump. There's no word from the Harris campaign to see if it would like to try it.

But what about Tesla

O'Dowd also has a bee in his bonnet about Tesla and its claims to offer self-driving cars, and he set up the Dawn Project, which puts out frequent missives about poor performance in the vehicles' software.

"My best analogy for Tesla is that Elon Musk is trying to win the Tour de France on a tricycle," he told us.

Some facets of self-driving have been in Tesla vehicles for years now and Elon Musk keeps promising full self-driving capabilities will be coming soon. Last week he held a gala "We, Robot" launch for his promised Cybercab, a fully autonomous car, a planned autonomous bus dubbed Robovan, and Optimus robots, which reportedly have been controlled by human operators during the [10]event .

O'Dowd's not especially anti-Tesla himself - he owns three of the original Roadsters. But the self-driving software is useless, he says, the company uses cheaper but less effective parts, and the FSD just isn't fit for purpose.

[11]Trump campaign arms up with 'unhackable' phones after Iranian intrusion

[12]Tesla's big reveal: Steering-wheel-free Robotaxi will charge wirelessly

[13]San Francisco fog defeats pack of Waymo robo-taxis

[14]Elon Musk's disaster relief promises: Should we believe the hype?

"Over 40 people who have died in Tesla self-driving cars and it keeps going up. It doesn't work. It shouldn't be on the road. People shouldn't be allowed to buy it. It is the most dangerous, stupid product I've ever seen on the market," O'Dowd argues.

"We already have workable self-driving cars from Waymo," he added, and they succeed because the cars are fully equipped with sensors, LiDAR, and a custom operating system built primarily for autonomous transport. They're now common in San Francisco, Los Angeles, and Phoenix, and services for Austin have been announced.

There are plenty who criticize Tesla for its FSD failings, but O'Dowd has taken things further for that. In 2022 he ran for the Senate purely on the single issue of getting unsafe autonomous vehicles off the road, with the slogan "Make Computers Safe for Humanity."

He [15]didn't get elected, but did garner over 74,000 votes, helped by spending a reported $650,000 buying advertising time. He has also booked full-page adverts in the New York Times on the matter - blessed are the poor but it must be nice to be rich.

[16]Youtube Video

In 2023, and again this year, O'Dowd's Dawn Project bought advertising space for the last two Superbowls, with stark footage of Tesla FSD systems failing and calling for a boycott. This earned the organization a personal cease-and-desist letter from Tesla, which O'Dowd promptly [17]mocked online.

The Dawn Project will continue, he said, and it had had some effectiveness in terms of getting politicians on his side. Whether or not it'll work is another matter.

Tesla had no comment at the time of publication. ®

Get our [18]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZxbPBgrroCZoV3csRxcheAAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZxbPBgrroCZoV3csRxcheAAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZxbPBgrroCZoV3csRxcheAAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2024/10/14/trump_unhackable_phones/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZxbPBgrroCZoV3csRxcheAAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://regmedia.co.uk/2024/10/18/odowd.jpg

[7] https://en.wikipedia.org/wiki/Evaluation_Assurance_Level

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZxbPBgrroCZoV3csRxcheAAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/09/29/pentagon_bug_bounty/

[10] https://www.theregister.com/2024/10/11/tesla_robotaxi_robovan_arrive/

[11] https://www.theregister.com/2024/10/14/trump_unhackable_phones/

[12] https://www.theregister.com/2024/10/11/tesla_robotaxi_robovan_arrive/

[13] https://www.theregister.com/2023/04/12/waymo_san_francisco_fog_traffic/

[14] https://www.theregister.com/2024/10/17/opinion_column_elon_musk/

[15] https://ballotpedia.org/Dan_O%27Dowd

[16] https://www.youtube.com/watch?v=Ly6Juveo-7Y

[17] https://dawnproject.com/dan-odowds-response-to-teslas-cease-and-desist-letter/

[18] https://whitepapers.theregister.com/



Tom Chiverton 1

Big deal. NSA got the Windows source too.

Publish your source, or a bootable image, or GTFO.

10k lines of code?

EricM

Even if we go back to the simple times of a C64 or ZX81, 10k LOC won't buy you much functionality.

On a (modern) phone, initializing the hardware, radio, GPS, etc. will already take more than that.

So I'd like to see what definition of "OS" is being used here.

Is the actual functionality located then in "applications" that interact with the hardware, so in case of a security problem you can claim your OS is secure, because the problem was in one of the many applications needed to actually work with a device?

Overall I'd suspect this claim to be true only under a very specific set of circumstances.

Re: 10k lines of code?

Tom Chiverton 1

I assume he's talking about a microkernel, so nothing more than a message bus, and everything else lives in user space, including the device drivers and application software. Which of course aren't "OS" and so don't count when they have the inevitable exploit in PNG parsing or hard coded credentials in the provisioning app.

Re: 10k lines of code?

Roland6

The first release of the Linux kernel was a little over 10,000 lines of code…

Looking at BSD (*), I suspect they are being very precise on what constitutes the “OS”.and what is add-ons.

(*) https://docs.freebsd.org/en/books/design-44bsd/

"the result of 40 years of technology"

munnoch

40 years ago you didn't really have an OS as we know them now. All you had was a program loader and majority of machines weren't connected to anything other than a power outlet.

Its taken us the intervening 40 years to build a Hydra-like nightmare with all the unintended consequences for security. All the billionaire had to do was stand still...

Re: "the result of 40 years of technology"

Hugh McIntyre

(More than) 40 years ago, we had Unix, VMS, and various other operating systems including networking and email. Definitely more than a program loader and power outlet ...

mark l 2

It sounds like this phone with 10000 lines of code is only going to be able to do basic stuff so calls and perhaps email/messaging. So when the orange one wants to post on Truth social, or watch videos of himself on Fox news etc he will no doubt revert back to a regular phone and therefore be using insecure devices for most of the time.

MachDiamond

"It sounds like this phone with 10000 lines of code is only going to be able to do basic stuff so calls and perhaps email/messaging. So when the orange one wants to post on Truth social, or watch videos of himself on Fox news etc he will no doubt revert back to a regular phone and therefore be using insecure devices for most of the time."

It's the voice calls and texts that will be the most sensitive. If he also has a tablet for Social Media, it can be shorn of voice and text capability so there aren't any slips.

All is fear in love and war.