Showing posts with label nuclear safety. Show all posts
Showing posts with label nuclear safety. Show all posts

Monday, June 18, 2018

Hacking Nuclear Weapons


Until I saw the title of Andrew Futter’s Hacking the Bomb:  Cyber Threats and Nuclear Weapons in the new-books shelf of my university library, I had never given any thought to what the new threat of cyber warfare means to the old threat of nuclear war.  Quite a lot, it turns out. 

Futter is associate professor of history at the University of Leicester in the UK, and has gathered whatever public-domain information he could find on what the world’s major nuclear players—chiefly Russia, China, and the U. S.—are doing both to modernize their nuclear command and control systems to bring them into the cyber era, and to keep both state and non-state actors (e. g. terrorists) from doing what his title mentions—namely, hacking a nuclear weapon, as well as other meddlesome things that could affect a nuclear nation’s ability to respond to threats. 

The problem is a complicated one.  The worst-case scenario would be for a hacker to launch a live nuclear missile.  This almost happened in the 1983 film WarGames, back when cyberattacks were primitive attempts by hobbyists using phone-line modems.  Since then, of course, cyber warfare has matured.  Probably the most well-known case is the  Stuxnet attack on Iranian nuclear-material facilities (probably carried out by a U. S -Israeli team) discovered in 2010, and Russia’s 2015 crippling of Ukraine’s power grid by cyberweapons.  While there are no known instances in which a hacker has gained direct control of a nuclear weapon, that is only one side of the hacker coin—what Futter calls the enabling side.  Just as potentially dangerous from a strategic point of view is the disabling side:  the potential to interfere with a nation’s ability to launch a nuclear strike if needed.  Either kind of hacking could raise the possibility of nuclear war to unacceptable levels.

At the end of his book, Futter recommends three principles to guide those charged with maintaining control of nuclear weapons.  The problem is that two of the three principles he calls for run counter to the tendencies of modern computer networks and systems.  His three principles are (1) simplicity, (2) security, and (3) separation from conventional weapons systems. 

Security is perhaps the most important principle, and so far, judging by the fact that we have not seen an accidental detonation of a nuclear weapon up to now, those in charge of such weapons have done at least an adequate job of keeping that sort of accident from happening.  But anyone who has dealt with computer systems today, which means virtually everyone, knows that simplicity went out the window decades ago.  Time and again, Futter emphasizes that while the old weapons-control systems were basically hard-wired pieces of hardware that the average technician could understand and repair, any modern computer replacement will probably involve many levels of complexity in both hardware and software.  Nobody will have the same kind of synoptic grasp of the entire system that was possible with 1960s-type hardware, and Futter is concerned that what we can’t fully understand, we can’t fully control.

Everyone outside the military organizations charged with control of nuclear weapons is at the disadvantage of having to guess at what those organizations are doing along these lines.  One hopes that they are keeping the newer computer-control systems as simple as possible, consistent with modernization.  What is more likely to be followed than simplicity is the principle of separation—keeping a clear boundary between control systems for conventional weapons and systems controlling nuclear weapons.

Almost certainly, the nuclear-weapons control networks are “air-gapped,” meaning that there is no physical or intentional electromagnetic connection between the nuclear system and the outside world of the Internet.  This was true of the control system that Iran built for its uranium centrifuges, but despite their air-gap precaution, the developers of Stuxnet were able to bridge the gap, evidently through the carelessness of someone who brought in a USB flash drive containing the Stuxnet virus and inserted it into a machine connected to the centrifuges. 

Such air-gap breaches could still occur today.  And this is where the disabling part of the problem comes in. 

One problem with live nuclear weapons is that you never get to test the entire system from initiating the command to seeing the mushroom cloud form over the target.  So we never really know from direct experience if the entire system is going to work as planned in the highly undesirable event that the decision is made to use nuclear weapons. 

The entire edifice of nuclear strategy thus relies on faith that each major player’s system will work as intended.  Anything that undermines that faith—a message, say, from a hacker asking for money or a diplomatic favor, or else we will disable all your nuclear weapons in a way you can’t figure out—well, such an action would be highly destabilizing for the permanent standoff that exists among nuclear powers. 

Though it’s easy to ignore it, Russia and the U. S. are like two gunslingers out in front of a saloon, each covering the other with a loaded pistol.  Neither one will fire unless he is sure the other one is about to fire.  But if one gunman thought that in a few seconds, somebody was going to snatch his gun out of his hands, he might be tempted to fire first.  That’s how the threat of an effective disabling hack might lead to unacceptable chances of nuclear war. 

These rather dismal speculations may not rise to the top of your worry list for the day, but it’s good that someone has at least asked the questions, and has found that the adults in the room, namely the few military brass who are willing to talk on the public record, are trying to do something about them.  Still, it would be a shame if after all these decades of successfully avoiding nuclear war, we wound up fighting one because of a software error.

Sources:  Andrew Futter’s Hacking the Bomb:  Cyber Threats and Nuclear Weapons by Andrew Futter was published by Georgetown University Press in 2018.  I also referred to the Wikipedia article on Stuxnet.

Monday, October 06, 2014

Playing with Nuclear Fire


The safety of nuclear weapons is the theme of Eric Schlosser's 2013 book Command and Control:  Nuclear Weapons, the Damascus Accident, and the Illusion of Safety.  After reading the book, my own reaction is mirrored in a quote Schlosser cites from General George Butler, who became head of the U. S. Strategic Air Command shortly before the Soviet Union came to an end in 1991.  After familiarizing himself with the secret plans for nuclear war, Butler later remarked that "we escaped the Cold War without a nuclear holocaust by some combination of skill, luck, and divine intervention, and I suspect the latter in greatest proportion."

Did you know, for example, that on March 11, 1958, a nuclear bomb landed on a playhouse belonging to the Gregg family of Mars Bluff, South Carolina?  The impact was strong enough to set off the high explosives in the bomb, destroying the playhouse, a nearby automobile, and injuring six family members.  Fortunately, the nuclear core was not inserted in the bomb.  It remained behind in a B-52 aircraft three miles above, where the navigator had entered the bomb bay to check on the status of a locking pin.  As he crawled awkwardly around the device, he grabbed the nearest object at hand for support, which happened to be the manual bomb-release lever.  The bomb fell onto the bay doors and forced them open, and the navigator narrowly avoided following it to the ground by hanging on for dear life. 

That same manual bomb-release lever was responsible for at least one other accidental loss of a nuclear bomb.  The most hair-raising accident involving nuclear weapons happened to a Titan II nuclear missile in a silo near Damascus, Arkansas, on September 18, 1980.  The Titan II was the same multistage rocket that boosted the Gemini manned spacecraft into orbit in the 1960s.  It used highly hazardous nitrogen tetroxide liquid oxidizer and an equally dangerous rocket fuel, which would explode on contact with the oxidizer.  You can imagine the challenges involved at underground missile silos all over the U. S., as Air Force personnel struggled to keep dozens of these hundred-foot-tall rockets fueled and ready for launch in minutes during the many years of the Cold War. 

Inevitably, something would go wrong.  On that fateful day in 1980, during a routine pressure check on the missile in Launch Complex 374-7, a technician dropped a heavy socket-wrench socket.  It bounced off a projection inside the underground silo, hit the thin aluminum skin of the rocket, and punctured it, allowing fuel to escape into the silo.  Over the next nine hours, things got steadily worse.  I won't give away the ending of this particular story, which reads like a Tom Clancy thriller in spots, but today the silo is filled in and the land has been returned to its previous owner.

The  Damascus accident advances in fits and starts over the entire length of the book as Schlosser digresses into the history of nuclear weapons, the evolution of nuclear-weapons policy in international relations, and attempts to make nuclear weapons safe as well as reliable.  This structure mostly works, although at times I found myself wishing for less political and military infighting and more Cold War stories about bomb accidents.  But there is plenty of both, for policy wonks interested in the finer points of Henry Kissinger's diplomatic skills and for techies wanting to know exactly how a thermonuclear weapon's electronic system functions.

The more time passes, the harder it is to believe that two of the most advanced industrial countries of the world—the U. S. A. and the Soviet Union—routinely played chicken with nuclear weapons, not just once, but dozens of times.  And most of these games were played in an era when the most advanced communications systems were either submarine cables installed as long ago as the 1860s, or shortwave radios that were essentially amateur radio sets on steroids.  During the Cuban missile crisis of 1962, generally recognized by historians as the time that the world edged closest to the nuclear brink, whenever the Soviet ambassador in Washington wanted to send urgent messages to his superiors back in the USSR, he had to call Western Union, which sent a messenger to the embassy on a bicycle and carried a piece of paper back to the telegraph office by hand.  

Because few civilians ever saw or dealt with nuclear weapons, the whole Cold War threat had an unreal quality to it, but it was frighteningly real.  Schlosser shows us that everyone living in the U. S. and the USSR, not to mention other nations with nuclear capabilities, had numerous escapes from a fiery or lingering death by nuclear holocaust during the Cold War, though most of us were unaware of them.  And of course, that threat still exists today, though now the most dangerous nations with nuclear weapons are places like North Korea and Pakistan.  As I write this, North Korea's nominal leader Kim Jong Un has not been seen in public for more than a month, so we don't really know who's in charge there.

Toward the end of the book, Schlosser quotes Langdon Winner's comment that "artifacts have politics."  That is to say, the very nature of some technologies compels the formation of certain types of political structures to deal with them.  The only way to deal with nuclear weapons, Winner concluded, is to form a secret, authoritarian system of control.  The ultimate in hazardous technology demands the ultimate in control and safety precautions.  Although nuclear-weapons powers have done pretty well at controlling the intentional use of such devices, the horror-story list of accidents that Schlosser has compiled in Command and Control leaves one with the impression that it is only a matter of time until we see an entire city or region vaporized, not because someone decided to start a war on purpose, but because some technician screwed up.  For the sake of everyone who might be endangered by it, I hope that such an accident never happens.  But unless those who decide to build nuclear weapons value safety as highly as they do reliability, the chances are that sooner or later, it will.

Sources:  Eric Schlosser's Command and Control:  Nuclear Weapons, the Damascus Accident, and the Illusion of Safety was published in 2013 by the Penguin Press.  I also referred to Wikipedia articles on Mars Bluff, SC, the Mark 6 nuclear bomb, Titan II, Langdon Winner, and the 1980 Damascus, Arkansas incident.  As of today (Oct. 6, 2014), CNN reports that Kim Jong Un has not made a public appearance since Sept. 4.

Monday, October 01, 2012

Fukushima Revisited: Lessons Learned


On Mar. 11, 2011, a huge earthquake and tsunami struck Japan, killing thousands of people outright and flooding large areas of the northeastern coastline of the country.  But perhaps the most significant legacy of the disaster will arise from what happened at the Fukushima nuclear plant, which was situated in the direct path of the tsunami.

As we mentioned in a blog two days after the disaster, no nuclear plant in history had been subjected to an 8.9-magnitude earthquake before.  But all of the six reactors at the plant may have sustained the shock without serious initial damage.  As the earthquake struck, automatic shutdown procedures were followed and after the earthquake, the operating reactors were still under control.  The problems came with the tsunami, which flooded the lowest level of the plant.

At this point, we turn to the conclusions of two special commissions charged with investigating the accident.  Both issued their conclusions just this last July of 2012.  One commission was the first of its kind in the entire sixty-six-year history of Japan’s constitutional government.  After interviewing hundreds of witnesses and conducting over a thousand hours of interviews, the commissions had harsh words to say about Tokyo Electric Power Company (TEPCO), government officials, and the sadly lacking state of emergency preparedness showed by those charged with the safety of nuclear power generally in Japan.

One problem that could have been avoided concerned the location of the emergency generators that kept cooling pumps operating during cooldown.  Turning off a large nuclear reactor is not like just flipping a switch.  They operate by heating large volumes of water, metal, and fuel to many hundreds of degrees, and even if the nuclear reaction is stopped almost instantly by some means such as the insertion of neutron-absorbing control rods, the laws of physics say that all that heat has to go somewhere.  And the usual place it goes is into the cooling fluid that is circulated through the reactor to remove the heat to boilers to generate electricity.

In the case of a shutdown, the heat can be simply dissipated in cooling towers or other rapid means, but first it has to be extracted by the cooling fluid flowing through the reactor.  In an emergency, this fluid has to be pumped even faster than normal, and only mechanical pumps will do the job in the type of reactor used at Fukushima.  With the loss of electric power from outside due to the earthquake and from the plant’s own generators due to the shutdown, the pumps had to be powered by emergency generators that were operating from diesel engines.  The big problem was, all these emergency generators were in the basement—where the floodwaters rose and stopped them cold.

From that point on, the situation just got worse.  With no cooling fluid flowing, the three reactors operating at the time of the earthquake overheated and produced hydrogen from the reaction of water with hot metal inside, and eventually the hydrogen exploded.  This was a chemical, not a nuclear, explosion, but it broke open the plant’s housing enough to release a lot of radioactive trash from the wrecked reactors inside—about a tenth of what was released during the much more serious accident at Chernobyl, Ukraine in 1986.  But enough radioactive material was released at Fukushima to affect the lives of those who lived near the plant for many years.

The fact that the emergency generators were in a vulnerable position where floodwaters could stop them is only one of a number of design flaws that contributed to the magnitude of the disaster.  Higher dikes around the plant site could have conceivably prevented flooding in the first place.  Following a call for increased safety measures at nuclear plants in 2006, TEPCO apparently did little or nothing.  According to the National Diet report, the firm relied on its close connections with Japanese regulators to avoid taking any substantial actions to improve safety.  The reports also faulted government officials for not planning for evacuations of the scale that turned out to be needed.  The Fukushima disaster has also given ammunition for groups agitating for the end of nuclear power altogether, and several countries such as Germany have either slowed or stopped their plans for future nuclear plants.

Admittedly, the earthquake and tsunami that led to the Fukushima disaster were at the outer limits of what any reasonable design would take into account.  But clearly, some fairly simple measures that might have made routine operations a little less convenient would have reduced or eliminated altogether the tragic events that led to the death or injury of numerous plant workers, the release of radiation that contaminated land for miles around the plant, the bad publicity that nuclear power received, and the total loss of billions of dollars’ worth of machinery and equipment.

One hopes that every nuclear engineer, in school and out, will make a special study of Fukushima in order to use the lessons learned from what went wrong there.  With the release of the disaster reports (and, hopefully, their translation into other languages including English), the nuclear industry has been presented with a treasure trove of mostly bad examples of how not to do it.  As engineer and writer Henry Petroski likes to point out, engineers often learn more from failure than from success, and Fukushima has presented us with an abundance of learning opportunities.  In view of concerns over climate change, the availability of fossil fuels, and the promise of conservation technologies such as smart-grid approaches to power distribution, it would be a shame if we back away from a form of energy that could provide non-fossil power for many decades to come.

Sources:  I relied upon the Wikipedia summaries of the commission reports under the headings of “Fukushima Daiichi nuclear disaster” and “National Diet of Japan Fukushima Nuclear Accident Independent Investigation Commission.”