This is the fourth among the U.S. nuclear weapons institutions that I've read is in trouble, going back several years:
1) Air Force ICBM launch operations: The General in charge had a serious drinking problem (consider that for a moment), to the extent that he went on a bender in Moscow. Among launch officers, there was widespread cheating on qualification tests, disregard for regulations (such as sealing doors to secure rooms), and very low morale.
2) Air Force nuclear bomber operations: At one point, they lost track of a nuclear bomb (or maybe cruise missile), and it was flown to a base in another part of the country before anyone figured it out and could track it down. The Secretary of Defense fired the General in charge.
3) Security at facilities containing highly enriched uranium/plutonium (the essential material to making weapons; the one component that keeps terrorists from making one): At one facility, some peace protestors (not James Bond-level attackers) breached the security and setup a protest next to a building containing the materials. They were there for something like 30 minutes before they were discovered and apprehended.
4) And now this.
This isn't a system that can succeed 99.999% of the time. If one nuclear weapon gets into the hands of someone willing to lose it, millions of people will die and then you can imagine the response - the course of history and civilization will change.
Well, at least they jailed her for 2 years for that terrible act of showing authorities to be grossly incompetent. It certainly must have sent a message to the cadres of spy-nuns waiting in the wings to take over. /s
I wonder how effective jailing a nun is anyway, a convent is not that far from a jail in many ways (I've had family in one and visited many times, and it felt roughly the same as visiting someone in jail).
You can leave a convent. You can't leave a jail. I also don't know too many nuns getting shanked or brewing toilet-merlot in the convent. Also, most go on errands in the city without an armed guard and manacles.
Yes, you can. I did not claim you can't. But even though you can there are quite a few cases of institutionalization in convents. And the convent I visited had nuns that had not been out in society in a long time, quite possibly longer than the jail sentence mentioned.
> I also don't know too many nuns getting shanked or brewing toilet-merlot in the convent.
On the contrary, plenty of convents and abbeys engage in brewing! Trappist beer for one.
> Also, most go on errands in the city without an armed guard and manacles.
No, but back in the day they tended to be chaperoned. Nuns are a dying breed around here, the history I'm recounting is when I was 6, 46 years ago, but still if someone has made their vows and is reconciled to life as a nun I seriously wonder how effective jail would be, I'm pretty sure they would not be too impressed by it (compared to someone not used to solitude at any level).
Agreed. Trappist ale is phenomenal btw. Chimay blue is heavenly. As someone mentioned below, US jails are crowded, unsanitary, loud, and dangerous. But yea, I see the spirit of your point.
Except for the frequent use of solitary confinement. Adam Ruins Everything has a pretty shocking show on U.S. prisons. A prisoner might spend years in solitary going insane.
Hardly. For starters, I don't agree that the risk of nuclear explosion was high, given the electronic precision required to detonate a hydrogen bomb's explosive lenses correctly. And had the W53 warhead exploded at its full nine-megaton potential, Nukemap[1] predicts 3rd-degree burns would not have extended even as far as Conway, and 11000 casualties of which 2500 were fatal (probably much less with a 1980 population).
The state would have faced a greater threat from fallout, but considering the advance warning of a detonation, lack of damage to infrastructure outside the immediate blast zone, and general cold war readiness for the effects of a nuclear explosion, casualties from fallout would have been far below the worst-case scenario. Two days' shelter while fallout radiation fell to 1% of its initial level would be easily achievable.
> given the electronic precision required to detonate a hydrogen bomb's explosive lenses correctly
Please do explain that. As far as I understand, the explosives and the radioactive materials are all there in the warhead, the "precision" only affects the "quality" of the explosion (i.e. the number of "megadeaths" https://en.wikipedia.org/wiki/Megadeath )
Only the first few atom bombs had the missing part of the radioactive matter outside the of the bomb when the bomb was fully unarmed, technically making the explosion impossible, as there isn't enough mass for an explosion without the missing part.
But since the early fifties, all the material needed for the nuclear explosion is always in the warhead.
Note that in the event here discussed (it was an explosion of the fully equipped H-warhead missile in Damascus, Arkansas, US)
The incident you linked to wasn't a nuclear explosion: the rocket the nuke was sitting on exploded. FTA:
"The W53 warhead landed about 100 feet (30 m) from the launch complex's entry gate; its safety features operated correctly and prevented any loss of radioactive material."
(I am not a nuclear engineer)
If you have a ball of fissile material, there are two sizes that are interesting to you. There's the point at which the material goes critical: on average, every neutron emitted causes the emission of more than one neutron. However, there are two types of neutron emission: prompt neutrons (released immediately when an incoming neutron breaks apart an atom), and delayed neutrons, released eventually by the decay of fission products. If you're producing one prompt neutron on average, then you're at prompt criticality.
Nuclear reactors prompt-subcritical but delayed-critical. Because the exponential growth of neutrons in a delayed-critical material is relatively slow, it can be managed by futzing with control rods.
If undisturbed, a supercritcal fissile mass will explode. The question is, how energetically? If it's delayed-critical, not very. The time scale characterizing the exponential growth is large compared to the time required for the explosion to propagate through the mass, so the mass will explode with not much more than the minimal amount of energy required to render it subcritical again. This is messy, but not what you think of when you imagine a nuclear explosion.
If the mass is prompt-critical, then the exponential growth is much faster. Even once the mass has released enough energy to explode, it still takes time for the mass to expand enough to be rendered subcritical. In that time, a prompt-supercritical mass will undergo many more generations, resulting in an actual nuclear explosion.
To get an actual nuclear detonation, then, you need to get your fissile material from subcritical to prompt-supercritical as fast as possible, so it doesn't predetonate unimpressively. This is a tricky task, requiring carefully shaped explosives, and pretty unlikely to happen by chance.
No it wasn't a nuclear explosion, but it certainly could've been and the fallout would have been very bad. You're way oversimplifying it. Did you watch the documentary a few weeks ago? I'm just saying I did and they interviewed the people involved including the guy who dropped the socket. They also go over just how unsafe these facilities were and a couple of other incidents of even worse magnitude.
> This is a tricky task, requiring carefully shaped explosives, and pretty unlikely to happen by chance
It's not "by chance," the warhead is carefully designed to make it and everything needed is already there, there are no missing parts. The "software" maybe doesn't activate the parts optimally or at all if there's luck but nothing is missing inside.
In the given case, "only" the rocket body exploded (with the fully functional warhead on it) even if it's not designed to do so, and only because of one single fallen small piece of metal (a single socket).
Yes, there were two bombs as the plane broke. One bomb, from its internal perspective, had a "fully normal drop": there was the switch that was triggered only once the bomb actually leaves the plane through the expected door -- it was activated as the plane broke exactly in a way that from the bomb perspective it simply wasn't an accident but "do it." On that bomb, the only switch that wasn't "on" was the one which a crew member was supposed to pull prior to the drop.
On the another bomb, from which point of view the dropping sequence was less "normal" (the breakup of the plane made less clear-cut case from the perspective of that one, so some internal components didn't activate) the same switch was discovered in the "on" position.
So it was really, really close call.
(A "small" curiosity: These bombs are two-stage bombs, one weaker nuclear explosion forces the next, one stronger. The "weaker one" part of one of the bombs, with its radioactive content that has enough material for a nuclear explosion is still there(!) deep in the ground.)
I think at some level there is a problem of mission and purpose. A military unit needs to believe what they are doing is important, like they are saving the country, protecting its citizens and so on.
After the Cold War, I'd imagine, the strategic nuclear forces probably ended up losing some of that "mission" and "purpose" and at least informally became more irrelevant. That has to take an emotional toll on everyone involved.
You go to work deep down in a bunker, follow a 1000 little rules and procedures, deal with lots of red tape, outdated technology and so on, but you don't really believe your actions today are protecting or saving anyone.
I think there is probably a parallel there with software maintenance. There are a lot of developers keeping alive and maintaining old code. Most written in languages which are not cool anymore. Nobody on HN is boasting making cool apps with them, others make fun of it. And there you are having to write patches and manage updates and so on it. The software is keeping the business alive and you are getting paid, but it is hard to feel proud and boast about your "cool project you are working on" during meetups or conferences. I would imagine that takes some toll as well on a person.
>> If one nuclear weapon gets into the hands of someone willing to lose it, millions of people will die.
That's just not true. There are a host of technologies designed to prevent a captured bomb ever being used, and I presume an entire department at the DoE dedicated to them. The very structure of a modern bomb makes use by thieves impractical. (Misuse by US forces is a different matter.)
(1) Bombs do not have hollywood-style timers. You cannot just cross a few wires. Getting a modern fusion device to properly explode requires the participation of a great many systems. For example, a warhead meant for a missile has safety triggers looking for flight path and altitude. Faking something like 200 seconds of zero-G flight while in vacuum isn't easy. Bypassing the sensors isn't easy. Detonating the explosives yourself, bypassing the electronics altogether, will not create a nuclear explosion. You have to know how to time everything very precisely. Doing that without the bomb's willing participation is practically impossible. The necessary equipment to launch the device in a manner that will result in a nuclear explosion doesn't travel with the bomb anywhere except while deployed.
(2) There isn't much nuclear material in a modern fusion bomb. This isn't a blob of enriched uranium like seen in WWII bombs. This is a very thin and hollow sphere of uranium packed with hydrogen and other harmless elements. You could grind up that sphere to make a "dirty" bomb but even then there is very little material. You won't be killing millions. For the effort, a terror group could do far more damage with weapons bought legally at any wallmart.
(3) Bombs in transit (ie off-base) are packed in tech meant to prevent misuse. Just cracking open the crate will probably trigger a device to blank the circuitry’s internal memory, making proper detonation impossible. (I've read about such system on non-nuclear missile systems and presume they are also used with nukes).
I agree that you can't simply capture a bomb then detonate it; there are many ways to prevent that from happening.
I assume the threat model people are worried about is the plot of Tom Clancy's 'The Sum of All Fears' [1] wherein a damaged nuclear bomb is captured by terrorists who can't enrich uranium themselves, but can replace the firing mechanisms once they have the fissile material.
And of course, a group that might be able to replace the firing mechanism would be able to engage in nuclear blackmail even if their replacement didn't work so long as nobody called their bluff.
But even in tom clancy's senario it took the efforts of russian weapons experts. And they were working with an oldschool core. Modern weapons use hollow/layered cores and so require better timing to achieve critical mass than those of the past.
"The bomb weighs approximately 1,100 kilograms (2,400 lb)"
"the greater part of the total mass is contained in the nuclear explosive. It has a variable yield: the destructive power is adjustable from somewhere in the low kiloton range up to a maximum of 1.2 megatons"
1.2 MT is 60 times stronger yield than the Nagasaki bomb which had only "6.19 kilograms (13.6 lb) of plutonium."
> packed with hydrogen and other harmless elements
They are never "hydrogen and other harmless elements."
It's radioactive, produced only in the nuclear reactors, and specifically for the colloquially called H-bomb part of the current designs.
It's the computerized part that controls the desired yield and we know that
a) the computers can't be made to be bug free and 100% secure
b) the mechanical parts controlled by the computer have all the necessary material for the full yield.
The argument "but it's more secure because the built-in computer controls it" should be laughable for the HN readers. Hiding behind the "it's complex that's why it's safer" works better only for those without the technical background.
The people who know how that stuff works are typically the most worried. There are enough worries when countries acquire even enough raw material which can be used to produce the bomb, here we talk about the fully built bombs with enough material for the full yield.
You conflate terms. Explosive warhead includes conventional explosives and the "physics package" with nuclear material. Modern bombs have proportionally more explosive and less fission material than historic weapons. By weight they are mostly all conventional explosives. And tritium is harmless. ... too many similar issues to address here on mobile.
> There isn't much nuclear material in a modern fusion bomb. This isn't a blob of enriched uranium like seen in WWII bombs. This is a very thin and hollow sphere of uranium packed with hydrogen and other harmless elements.
Primary and secondary in todays devices arent as different as they once were in "spark plug" configs. These are boosted weapons. A hollow sphere of fission material is collapsed into a point. Hydrogen is inside to add fusion reactions, increasing the efficiency of the fission reaction without the need of a formal secondary.
As a counterpoint, zero defect policies could be be harmful. If everyone must take a test and score 100% or otherwise end their career, shenanigans happen.
> As a counterpoint, zero defect policies could be be harmful. If everyone must take a test and score 100% or otherwise end their career, shenanigans happen.
It's not a counterpoint, it's a consideration when designing the system. Taking this into account, the system must still function 100% of the time. If what you describe did happen, than the cause of failure would shift somewhat from the officers to the designers, but the system still failed (however, one must question the judgment and character of anyone who cheats on a nuclear weapons launch qualification test, no matter how hard it is).
If your system requires 100% perfection from all of its subcomponents, it is a shitty, fragile system. Robust systems can be made of parts with known failure rates.
This this this. I really see this as the core of my job, career even. Build reliable systems out of unreliable parts. Hardware fails, software has bugs, people have bad days. Yet we still make insanely reliable stuff.
Until you actually launch the missile, it should be ok to do nothing.
People will invariably fuck up. The system needs affordences to handle those inevitablys. Ideally a drunk commander shouldn't matter, matter much anyway.
Accidentally launching a missile is pretty hard and I'm confident that we have enough safeguards against that. I'm not so sure we have enough safeguards against terrorists stealing nuclear weapons (or the essential components for making one). You only need somebody with motive and motivation, and a mistake by pair of truck drivers. It's fairly hard to make a reliable system out of that failure mode.
A friend worked with that kind of transportation in the 80s. At the time it wasn't 2 truck drivers. Perhaps 30 people with lead and follow cars. Iirc, most were us martials, everyone was armed. the trailer was a rolling fortress. Security was probably much better in the Cold War. My friend had a story about a truck hitting some ice, and tipping over. They had prepared for many contingencys and had it handled in a few hours. The only person who noticed something was up was another truck driver who stopped to help. He was confused that the trailer didn't tear itself apart, but didn't make a bid deal out of it.
Not cheap. But likely pretty reliable.
Perhaps without the Russian villains the system has atrophied. Stories like that make me think it can work, but perhaps require a bit more wherewithal to maintain it.
The Wiki entry[0] for the secure trucks reads like some kind of Tom Clancy fiction. They allegedly have automated weapons systems that will kill attackers even after all defenders become casualties.
My friend likely worked with the prior generation. They were unwilling to go into any sort of detail. they did say, you don't want to be any where near one if the operators think you shouldn't be there. Their phrase was something like "There are extensive anti personnel defenses".
You have to assume that such a truck is constantly "phoning home" and hopefully has some kind of asset tasked to watch it constantly. Maybe the process to get in involves authorization from "home base" in the form of that private key?
While I doubt that anything could stop a truly determined and well equipped adversary, I would frankly not be shocked if the whole thing was basically packed in claymores facing out, just for starters. You won't care in that extreme about compromising the physics package; you'll already be scrambling every resource including NEST to the site. You just want to buy time, and there are a lot of ways you could do that.
Hell, maybe they include an EPFCG... that would be really clever.
It's such a complex network of systems and people and policies; all of which is constantly in flux. All of which has to yield a perfect result, every time. You can argue about robust systems, but the reality is that these systems are far from robust.
Look at what happened when the USSR collapsed for god's sake! We're still cleaning that up.
Very much this: A system should be designed with the mindframe that the user won't be at 100%. Especially this, weirdly - because in a time of crisis, folks might not be at 100% even though they should be.
Its why some things just won't work unless put together just right - to account for people's mistakes. It'd make sense for a submarine to refuse to dive if the seals aren't sealed, for example. I'd think there would be something that could be applied even for this.
That sounds very good, but now here are your real-world constraints.
You have a network of detection systems which you give you (optimistically) 15-40 minutes of warning before everything and everyone you've ever known and cared about ends. In that time you have to make the decision to launch a counter-attack. Your decision needs to be something which can be rapidly acted upon, but also needs to be something that absolutely cannot be interfered with by any adversary launching the first strike. If you delay, your ability to counterattack will be forever lost. If you're wrong, you'll be setting off Armageddon.
Perimetr, the Russian system, is one solution. The USSR decided not to go for launch on warning. Their plan is that, when things get tense, they activate Perimeter. This is sometimes called "The Dead Hand". If the system was enabled, detected nuclear explosions, and there was no way to communicate with higher authority, it would automatically release weapons control to some lower level of authority. Even then, it's not auto launch; there are people in bunkers somewhere who have to make that decision.
Part of the rationale is that this didn't give the leadership of the USSR direct launch authority. They could enable the system, but that didn't cause a launch. It took H-bombs on Moscow plus an enabled system to do that. This provided a safeguard against the leadership going nuts.
In theory sure, but point me to the long-term practice of making it actually work. In practice, nuclear weapons have been subject to obvious and critical fuck-ups.
You also have a problem with precision. A test with a 100% pass threshold is a really poor estimator of an underlying failure rate; at best it can bound it, but you really do care about the precise underlying odds of failure.
Given that list, and given the facts, the two broad options seem to be:
A visionary leader who can make these issues clear to people (haha)
The course of history and civilization will change.
Now, when you look back on our history, how often do we as a species anticipate and prevent the .001% calamity, and how often do we need to be neck deep in it before we realize that there's some trouble?
The only thing that's changed here- and it isn't us as people- is that once we're in it with nuclear weapons, there is no coming back, but so what? That hasn't changed people at all.
This is why we should all become more knowledgeable about nuclear weapons. Right now there is no political pressure to make things more safe because the electorate is largely uneducated.
Which has really pulled back the curtain on nuclear thinking. There's also a private members slack if you support them on Patreon, which is endlessly useful. And really, if you're going to support a podcast on Patreon, I can't think of a better case than the ACW Podcast:
"This is why we should all become more knowledgeable about [ANYTHING]. Right now there is no political pressure to make things more [ANYTHING] because the electorate is largely uneducated."
We can't get people on the same page with their health insurance... nuclear disarmament might be a big ask in that context.
2) 6x Nuclear cruse missiles, W80 variable yield (150kt). I find the public story hard to believe, there's a window that is mandatory to check to see if the warhead is real. On the positive side people actually got fired.
It depends on how "terrorist state" is defined, but North Korea might count.
A state is different; they have something to protect and are subject to deterrence through threatened retaliation. Groups like al-Qaeda are more dangerous in this regard.
> It depends on how "terrorist state" is defined, but North Korea might count.
Who is NK terrorizing? Their entire (Korean) story from top to bottom seems to be based on factual invasions throughout the Korean history from near and far flung people, and their party line is insistence to remain independent and free. Isn't NK also in multiple crosshairs? Have they no right to have a military? Only certain nations can make threats and others must be meek or else be called "terrorist"?
1) Air Force ICBM launch operations: The General in charge had a serious drinking problem (consider that for a moment), to the extent that he went on a bender in Moscow. Among launch officers, there was widespread cheating on qualification tests, disregard for regulations (such as sealing doors to secure rooms), and very low morale.
2) Air Force nuclear bomber operations: At one point, they lost track of a nuclear bomb (or maybe cruise missile), and it was flown to a base in another part of the country before anyone figured it out and could track it down. The Secretary of Defense fired the General in charge.
3) Security at facilities containing highly enriched uranium/plutonium (the essential material to making weapons; the one component that keeps terrorists from making one): At one facility, some peace protestors (not James Bond-level attackers) breached the security and setup a protest next to a building containing the materials. They were there for something like 30 minutes before they were discovered and apprehended.
4) And now this.
This isn't a system that can succeed 99.999% of the time. If one nuclear weapon gets into the hands of someone willing to lose it, millions of people will die and then you can imagine the response - the course of history and civilization will change.