Howard and Longstaff's Blueprint for Sanitizing Nuclear Breaches

By Eleanor Voss ·

While the FBI tracked hackers attacking the Air Force in 1998, Sandia researchers built a system to scrub the gore from security failures, keeping the true scale of nuclear vulnerability in the dark.

When the systems guarding the American nuclear arsenal glitch or buckle, the people in the blast zones of the Midwest and the corridors of the Pentagon are the ones who pay the price for the silence that follows. For years, the gap between a technical 'incident' and a national security catastrophe was bridged by a vocabulary designed to hide the blood on the floor.

I am working from an archival description of a specific record—a summary of its contents rather than the original pages—and that summary reveals a calculated effort to standardize the language of failure. The record is an unclassified paper titled "A Common Language for Computer Security Incidents," written in October 1999 by John D. Howard and Thomas A. Longstaff of Sandia National Laboratories. According to the record, the paper "addresses the need for a common language by proposing a set of terms and structures that can be used to classify and understand computer security incident information."

On the surface, this is a dry exercise in taxonomy. But in the world of nuclear security, a dictionary is often a shroud.

A Lexicon for Failures

Sandia National Laboratories, a facility owned by the federal government but operated by Honeywell International, is the entity responsible for the non-nuclear components of the U.S. nuclear weapons stockpile. It is the place where the triggers, the casings, and the safety systems are engineered. When Howard and Longstaff sat down to write this paper, they were not acting as academics; they were researchers for the National Nuclear Security Administration, the agency tasked with ensuring the warheads actually work when called upon and stay silent when they aren't.

John D. Howard, who would later move into the world of high finance at Irving Place Capital—a New York private equity firm formerly known as Bear Stearns Merchant Banking—understands the value of a precise ledger. His partner in this effort, Thomas A. Longstaff, a man whose earlier life as an English medical doctor and Himalayan mountaineer involved scaling the peaks of Trisul, brought a different kind of precision to the table. Together, they proposed a way to "classify and understand" security breaches.

But the record does not say who they were classifying, or what specific failures prompted the need for this new language. It only provides the framework for the description. The desk's reading is that this paper serves as a sanitized Rosetta Stone for a classified ledger of actual intrusions that the authors were unable to disclose. By creating a "common language," Sandia didn't just help researchers talk to each other; they created a way to translate a terrifying reality into a manageable report.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

The Secret Timing of 1998

To understand why Sandia needed a new language in 1999, you have to look at what was happening in the shadows a year earlier. The public record shows a government in a state of quiet panic. In September and October of 1998, the Government Accountability Office—the congressional watchdog—issued a series of blistering reports warning that "serious weaknesses place critical federal operations and assets at risk." The GAO wasn't talking about theoretical risks; it was flagging systemic rot in the way the United States protected its most sensitive data.

While the GAO was sounding the alarm on the surface, the FBI was operating in the depths. A Secret memo dated July 31, 1998, records the FBI granting authority for the use of consensual monitoring equipment to track a "hacking attack" targeting the USAF Institute of Technology. The Air Force was being probed, and the FBI was using informants and surveillance to find out who was pulling the strings.

The line between these events is where the story lives. You have the GAO reporting systemic weakness, the FBI hunting hackers in a Secret operation, and then, almost immediately, the researchers at the nuclear labs proposing a way to standardize how "incidents" are described. The pattern suggests the 'common language' was a response to a specific, systemic failure in inter-agency communication during a real-world security event. If the FBI knows who is attacking and Sandia knows what is being broken, but they lack a shared vocabulary, the result is a blind spot large enough to fly a missile through.

Scrubbing the Intelligence

There is a profound irony in the fact that the Howard and Longstaff paper is unclassified. It describes how to handle information that is, by its very nature, some of the most sensitive data in the government. The record focuses entirely on the "what"—the classification of the incident—while remaining completely silent on the "who."

In a nuclear security environment, the identity of the adversary is the only thing that truly matters. If a glitch is caused by a faulty server, it is a maintenance issue. If it is caused by a state actor in Moscow or Beijing, it is an act of war. By stripping away the attribution metrics and focusing on a "common language" of technical structures, the authors created a mechanism to move data across clearance boundaries.

If this file is shaped the way it looks, it was designed to enable the movement of incident data by stripping away specific intelligence identifiers. It allows a researcher to report a "Type 2 Intrusion" to a supervisor without having to admit that the intruder spent four hours inside the schematics for a trigger mechanism. It transforms a breach of national security into a data point in a technical taxonomy.

The Architecture of Silence

This is not about efficiency; it is about the management of panic. When the GAO warned that federal assets were "at risk," the response from the laboratories was not to simply harden the walls, but to refine the way they described the holes in those walls.

The desk's reading is that this framework was a defensive measure to standardize the reporting of 'glitches' versus 'attacks' to avoid premature escalation to political leadership. By formalizing the definitions, the NNSA could decide which failures were "incidents" and which were "anomalies," effectively deciding what reached the President's desk and what stayed in the basement of a New Mexico lab.

What a full release of the 1998 and 1999 Sandia files would show is the list of actual breaches that the "common language" was designed to mask. The still-withheld pages are protecting the names of the systems that failed and the countries that exploited them. The pattern established here is one of translation as a form of concealment: the more standardized the language becomes, the easier it is to hide the specific, jagged edges of a disaster.

This is how the nuclear state survives its own incompetence. It doesn't fix every leak; it just invents a new word for the flood, ensuring that those who paid for the security—the taxpayers and the people living under the shadow of the stockpile—never know exactly how close the water came to the wiring.

Sources

  1. John D. Howard, Thomas A. Longstaff, Sandia National Laboratories, “A Common Language for Computer Security Incidents”, October 1999. Unclassified. — National Security Archive (GWU)
  2. Document PDF (John D. Howard, Thomas A. Longstaff, Sandia National Laboratories, “A Common Language for Computer Security Incidents”, October 1999. Unclassified.)
  3. Background: Sandia National Laboratories — Wikipedia