FYI: That Hawaii missile alert was no UI blunder. Someone really thought the islands were toast
False text probe reveals screw up after screw up
The individual who sent an emergency text to everyone in Hawaii warning them of an imminent missile attack did not hit the wrong button as first claimed – and was actually convinced a real attack was happening.
That's according to a report published Tuesday by America's comms watchdog, the Federal Communications Commission (FCC). Written by the regulator's cybersecurity advisor James Wiley, the dossier notes that the individual in question refused to talk to Wiley, but that he or she did write down their recollection of events shortly after they occurred on January 13, and Wiley was given a copy of that statement.
Previous to the report, the assumption was that the alert had been sent in error, and focus turned on the Hawaii Emergency Management Agency's terrible user interface on its computer systems.
It was claimed an official clicked on the wrong item in a drop-down menu. Rather than perform a test of the software without warning citizens, the agency worker accidentally selected the option to emit a real missile alert.
Hawaiian fake nukes alert caused by fat-fingered fumble of garbage GUIREAD MORE
Now it turns out there was no accidental user-interface blunder. Now we're told confusion arose when conflicting messages were sent in a test of the system during a shift change. The person at the controls thought Hawaii really was going to be wiped off the map.
"At 8.05am, the midnight shift supervisor initiated the drill by placing a call to the day shift warning officers, pretending to be US Pacific Command," the report notes. "The supervisor played a recorded message over the phone. The recording began by saying 'exercise, exercise, exercise,' language that is consistent with the beginning of the script for the drill.
"After that, however, the recording did not follow the Hawaii Emergency Management Agency’s standard operating procedures for this drill. Instead, the recording included language scripted for use in an Emergency Alert System message for an actual live ballistic missile alert. It thus included the sentence 'this is not a drill.' The recording ended by saying again, 'exercise, exercise, exercise.' Three on-duty warning officers in the agency’s watch center received this message, simulating a call from US Pacific Command on speakerphone."
As the report digs deeper, screw-up after screw-up is revealed.
One more thing...
For one, there was no system in place for dealing with a false alarm. Which seems pretty shortsighted considering the enormous importance of a ballistic warning system.
There was also a critical miscommunication between supervisors when they took over from one another at 8am on that fateful day. The leaving supervisor told the incoming day-shift supervisor that he intended to carry out a preparedness drill, but the incoming supervisor assumed he meant for those ending their shift, not the new people starting their shift that he was overseeing.
As a result, the day shift supervisor "was not in the proper location to supervise the day shift warning officers when the ballistic missile defense drill was initiated" – which is probably code for he was sat on the toilet.
Also noteworthy is the fact that the organization's policy and related checklist for the alert system had only be finalized one week earlier, on January 5.
Not only was the system new but managers decided to push it to its limits – simulating a live ballistic missile defense drill, with no notice, specifically as the shift changed at 8am. It was a worst-case scenario test – and it failed, resulting in over a million people believing that they would shortly be hit by a nuke.
It took 38 minutes for another alert to be sent telling Hawaiians it was a false alarm.
The critical error, according to the person who hit send – the day shift warning officer – was that he or she heard the phrase "this is not a drill," but did not hear "exercise, exercise, exercise." As such, the staffer thought it was a real event.
On their computer, they selected the template for a live alert – which offers a drop-down menu that includes the option for both a live alert and a test alert; a design that people have been quick to point out is less than optimal. The official chose live test and then when prompted with the message "Are you sure that you want to send this alert?" – which is also the exact same message and prompt that appears during a test – clicked yes. And out the alert went.
Is that right?
However, it is also possible that this version of events is also untrue, and the warning officer simply screwed up first by choosing the wrong option, and then refused to pause when given the warning prompt. He or she could simply be protecting their job and reputation.
The report goes with the official version – of a misunderstanding – although it inserts a few skeptical notes. "Because we've not been able to interview the day shift warning officer who transmitted the false alert, we're not in a position to fully evaluate the credibility of their assertion that they believed there was an actual missile threat," it notes, adding: "But it is worth noting that they accurately recalled after the event that the announcement did say 'This is not a drill.'"
As for the long delay in announcing it was a false alarm, that is another series of cockups. The warning officers realized almost instantly that they had wrongly sent a real message telling Hawaiians they were about to be bombed.
The drill was started at 8.05am with the call pretending to be from US Pacific Command. The alert was sent just two minutes later, at 8.07am. And then, just sixty seconds later, the mobile phone of the warning officer went off – "distinct audible tones that announce a wireless emergency alert."
That was when the rest of the team realized a live alert has actually gone out beyond their internal network. The rest of the team said they knew it was a drill so it's safe to say it was a brown-pants-moment for pretty much everyone.
The first thing they did – within the next 60 seconds – was call the governor of Hawaii to tell him it was a false alert. As we now know, he tried to send out a tweet telling people not to panic but he didn't know his Twitter password.
Then, at 8.10am, they called Pacific Command and the Honolulu police to tell them there was no missile launch. At 8.12am a cancellation is run through the system but that isn't able to recall messages or warn people that the original message was false, and by then everything is already in meltdown – the Emergency Management Agency (EMA) starts calling TV and radio stations to get the message out but its phone lines become clogged as the public try to find out what is going on.
Sponsored: Becoming a Pragmatic Security Leader