US nuclear weapon bunker security secrets spill from online flashcards since 2013
- Reference: 1622227887
- News link: https://www.theregister.co.uk/2021/05/28/flashcards_military_nuclear/
- Source link:
The astonishing security blunder was revealed by investigative journalism website Bellingcat, which described what it found after “simply searching online for terms publicly known to be associated with nuclear weapons.”
The flashcards “detail intricate security details and protocols such as the positions of cameras, the frequency of patrols around the vaults, secret duress words that signal when a guard is being threatened and the unique identifiers that a restricted area badge needs to have,” Bellingcat [1]reported .
[2]
[3]
[4]
Merely googling “PAS” (protective aircraft shelter), “WS3” (weapons storage and security systems) and “vault” (the US military term for nuclear weapons bunkers) together with the names of US Air Force stations in Europe came back with flashcards used in training and hosted on websites Chegg, Quizlet, and Cram.
Materials found by Bellingcat suggested the protocols had been in use as recently as April, though the oldest dated back to 2013. The flashcards themselves have since been deleted, with the US Air Force telling Bellingcat it was “investigating the suitability of information shared via study flashcards.”
[5]Exercise-tracking app Strava to give away data sweated out after four billion runs, rides and rambles
[6]US Pentagon scrambles after Strava base leaks. Here's a summary of the new rules: 'Secure that s***, Hudson!'
[7]When humanity perishes in nuclear fire, the University of Essex's radiation-resistant robots will inherit the Earth
[8]Orford Ness: Military secrets and unique wildlife on the remote Suffolk coast
Some flashcards included the locations and sightlines of surveillance cameras pointed at key entrances, and the locations of modems networking the vaults’ systems with the wider base. Precisely which vaults were being used to store nuclear warheads was detailed in some cards.
The investigative website’s findings are similar to the open-source intelligence it found when [9]looking at beer-rating app Untappd last year. Using Bellingcat’s techniques, The Register was able to easily identify key government personnel working in militarily sensitive establishments.
Online OPSEC is important: subscribing to ebooks website Scribd and searching for certain terms can reveal all manner of confidential manuals and handbooks, and slide-deck website Prezi occasionally contains internal slideshows the content of which probably wasn't intended to be published to the wider world.
[10]
Think of it this way: if you’re uploading sensitive data to a website that isn’t operated by or contracted to your company (or the government in this case), you probably shouldn’t do it. Particularly if you're guarding nuclear weapons. ®
Get our [11]Tech Resources
[1] https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YLFn@Q@Rxis@cRX4dP7pLQAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLFn@Q@Rxis@cRX4dP7pLQAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YLFn@Q@Rxis@cRX4dP7pLQAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2020/09/28/strava_free_data/
[6] https://www.theregister.com/2018/01/29/us_pentagon_strava_tracking/
[7] https://www.theregister.com/2021/05/21/uni_of_essex_radiation_robots_600k/
[8] https://www.theregister.com/2019/09/24/geeks_guide_to_orford_ness/
[9] https://www.theregister.com/2020/05/19/bellingcat_beer_app_osint/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLFn@Q@Rxis@cRX4dP7pLQAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re: Ah, siteguard
That’s called an own-goal, no? And as for being tired…. “Exhausting” I think is the correct term…
Oops
Need I say more?
Flashcards ?
Why do I have a picture of little camo-clad heroes sitting cross legged in a circle around a sergeant, while he holds up a flash card and says
"Now children who can tell me what kind of bomb this is ?"
Re: Flashcards ?
Similarly, I first thought that somehow the nucular secrets had been stegano- or otherwise encoded into a flashcard deck used by elementary school teachers or home-schooling parents.
Staffing these sensitive sites with young people is also an invitation for fun
Bellingcat link: https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/
Those young men (and some women) enjoy social media more than most.
Bellingcat has taken good advantage of the carelessness of military and intelligence personnel as well as using openly available databases of private information.
Re: Staffing these sensitive sites with young people is also an invitation for fun
Great discussion of "inert nuclear bombs” in the link. Those are my all time favourite kind!
Ah, siteguard
The memories of SiteGuard in BAOR during th 1980's. A week of being very tired, and very bored.
And astounded as the average US serviceman's inept weapon handling, as characterised by the individual who followed the QRF out with a 66mm AT to the first response position; a narrow sanbagged area just wide enough to squeeze down whilst in CEFO, with a wall behind it....