top | item 5610124

US Navy to pay $1M to make Android more secure

51 points| ariabov | 13 years ago |sbirsource.com

50 comments

order
[+] vabmit|13 years ago|reply
The DoD is committing to Android as a platform in a massive way. Apps 4 Army is a key example. The push is so large and widespread that I think it will force the whole US Gov't along with it. Everyone from political leaders, to soldiers, to doctors at VA hospitals, to employees at defense contractors, will be required to use Android because of government security certifications and custom apps. There's a good chance that Android will become the very dominant winner in the mobile platform space because of this.
[+] dsl|13 years ago|reply
Android is going to be the low cost field deployable random gadget, and this is an investment in bringing a minimum level of security to the platform.

For actual classified applications, the NSA (which provides solutions downstream to DoD and other groups) is already trying to standardize on a highly customized version of Windows CE built by General Dynamics that runs on XScale processors with NSA specific modifications. Some publicly visible applications of this stack are the Sectera Edge (the phone that replaced Obamas Blackberry) and the DTD2000.

Windows CE will become the very dominant winner in the mobile platform space because of this. :)

[+] r00fus|13 years ago|reply
I've heard this before. Remember 15+ years ago when the US Army chose WebObjects because it was so obscure it had no security issues? How is their adoption of Apple server gear since then?
[+] sigzero|13 years ago|reply
Now there is some pie-in-the-sky hope. I don't think it is going to play out that way though.
[+] threeseed|13 years ago|reply
What type of deluded nonsense is this ? Since when did adoption by the US government decide who will win the mobile platform 'war'.

And I was under the impression that Apps 4 Army was built for iOS first. Does that mean iOS will now 'win' ?

[+] shubb|13 years ago|reply
Summary -

The US navy wants to use (near) commercial android devices. These might be used to display confidential reports (as in a normal buisness), but may also be used to control the ship.

The navy already have secure versions of Linux and Windows, and want something similar for android.

This will take the form of additional security layers, similar to the ones the NSA did for Linux[1].

Some of them will be made commercially available, hopefully increasing security to the whole platform. If this included e.g. application sandboxing, you can see that it would be of general interest, particularly to people with similar needs (Android based control terminal for a power station, or sys admin wants to roll out policy to coorp devices).

Android is becoming the default embedded OS for a lot of UI, so it's really nice to see this.

[1]http://en.wikipedia.org/wiki/Security-Enhanced_Linux

[+] jlgreco|13 years ago|reply
Hmm, who actually is the one to usually do this sort of thing?

Clearly it is a good idea, but I don't think it really makes sense for the Navy to do it for themselves. Isn't this more the sort of thing the NSA should be doing on the behalf of everyone else in government?

[+] justincormack|13 years ago|reply
Perhaps even the same. Android is pretty much Linux and converging fast. They can probably reuse a lot.
[+] jedc|13 years ago|reply
I found it interesting that they specifically called out use on Virginia-class submarines. As a former submarine officer myself, there certainly are some applications on board where this would certainly make sense. (Not in the engine room operationally, but in other areas definitely.)
[+] joyeuse6701|13 years ago|reply
yes, that struck me as odd actually. What about those submarines make them a good fit with android technology?
[+] NinjaSudo|13 years ago|reply
The fact that this project is "focused on reducing the impact of short life cycles for commercial mobile devices" excites me as I'm sure many folks dislike how quickly technology grows obsolete and stale when you just bought a new phone and a new one comes out a few weeks later. That being said, security of mobile devices is an increasingly important issue as we become more and more reliant on information connectivity for our daily lives.

I would be curious to hear the results of Phase I and of course look at the framework they use to extend the Android OS.

Why not try to commit the Security extensions into the Android project?

[+] eterm|13 years ago|reply
They didn't say they're lengthening the life cycle, they said they plan on reducing the security impact of such short life cycles.
[+] brucehart|13 years ago|reply
The Navy has an SBIR solicitation out for this topic, but it does not necessarily mean that it is going to put up $1MM. Phase I funding is small (less than $100k per award) and sometimes no Phase II contracts are awarded for a topic. Of course, the Navy could also spend much more than $1MM if they decide to fund multiple Phase IIs (also not uncommon). It really depends on the results they see during Phase I and the importance of the topic compared to other funding opportunities.
[+] cjones99|13 years ago|reply
The average is for them to fund 2-5 Phase 1 awards at $150K and then 1-2 Phase II awards of $1MM each based on the most promising of the Phase I. Given recent changes to the SBIR program, note that Phase I SBIRs can now be for $150K and Phase IIs at $1MM.

It can happen, but is rare, that they would fund nothing on a topic in the solicitation.

And as you say, compelling results out of the SBIR work can lead to follow-on work that is >> $1MM.

The short of it is, the Navy is interested in this topic, and if you have a small tech business with innovative ideas in this space there is a great funding opportunity here for you to advance your tech and grow your business.

[+] jiggy2011|13 years ago|reply
Note: By "less hackable" they mean "more secure" and not "less open".
[+] dublinben|13 years ago|reply
I think the military appreciates the security advantages of open source more than many other organizations. There's really no way to trust national security information to black-box proprietary systems. This concern has even extended to the actual chips running the software, since they're often made in China.
[+] out_of_protocol|13 years ago|reply
Raise of android-based embedded devices is coming. Android already ate ~70% of selling smartphones and now spreading to non-phone areas, like car systems, fridges, cash machines and so on. I really hope android will become even more secure in next few years. Otherwise ... imagine it by ourselves
[+] samspenc|13 years ago|reply
Why doesn't Google apply? :) They get $1 million to improve Android security - and they can just do it and integrate it into the next release for everyone!
[+] jjohnson|13 years ago|reply
Google is far from a small business, these are funding opportunities for companies with less than 500 employees.
[+] cjones99|13 years ago|reply
The SBIR program is the largest Federal source of non-dilutive seed-stage funding available. The program is highly competitive, but this funding is available exclusively to small (e.g., < 500 employees) businesses.

The intent of the program is to drive technology development and new business creation and spur innovation in areas to meet identified national needs (in this case a need by the Navy).

[+] derrida|13 years ago|reply
Can anybody comment on how the Navy restriction to US citizens only developing this plays into the FOSS ecosystem of Android? I assume most of it is GPLv2, so isn't this immaterial? Why would it matter when the code is completely FOSS?
[+] mpyne|13 years ago|reply
Because it's a legal and/or regulatory requirement, which are not required to make sense in the scope of unusual market environments, let alone normal ones. :-/
[+] iam|13 years ago|reply
Seems like a great idea. I expect most of their contributions will make it back to open source via AOSP, and people will be able to run their own secure non-proprietary versions of Android.
[+] rdtsc|13 years ago|reply
The whole device hardware and software needs to be certified. It is hard to make a secure piece of software and prove it so if the hardware or firmware it is running on is compromised.
[+] tptacek|13 years ago|reply
Pfft. Have you ever had a project EALx/Common Criteria certified? The program is a joke. You can certify a ham sandwich if you document what brand of mayo you use.
[+] rdl|13 years ago|reply
Has anyone on hn experimented with the Samsung security stuff yet?
[+] RexRollman|13 years ago|reply
Fucking Navy. First they waste tons of money on NMCI and then tons more on Navy ERP. I'm amazed anything works.
[+] mpyne|13 years ago|reply
NMCI is actually quite successful in meeting most of its design criteria. Unfortunately said criteria don't seem to include rolling releases to recent software, or cost effectiveness (the contract seems optimized to ensure you have to go through the help desk for anything and incur a charge).

I can't speak to ERP but I'd be surprised if it were any worse than our existing menagerie of mainframe-based "corporate data" systems that run batch transactions once a day and require tedious manual correction seemingly all the time.