3 ms·
It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting
by thingexplainer 10y ago
It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.
- gnarbarian 10y agoI contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucracy required of federal employees. For instance if I was directly employed by one of my clients i would be severely limited in the toolchain that I use and I wouldn't even be allowed admin access on my development machine (despite having it on multiple servers which are orders of magnitude more sensitive). If I was their employee, every time I needed to install a java update I'd have to call up IT sit on hold and explain to them exactly why I need to install this update etc.. I've had it literally take a week of futzing around with bizarre errors (from the crazy policy settings and restrictions on the laptop) on hold with some poor schmuck at a national level helpdesk four time zones away who has zero experience with programming trying to get a dev-enviornment set up on a government laptop which would have taken literally an hour on a computer I have local admin access on. I would rather be waterboarded than do that again. Contracting and having our own rules saves literally unending amounts of pointless bullshit. Many things would probably never get completed internally because of situations like this. Of course those contractor advantages cut both ways when considering security. In OP's situation I'm not sure him being a contractor makes any difference. Either kind of employee can take a usb stick home and transfer stuff to a compromised PC. A contractor or employee may have gotten their clearance a long time ago and unless they have some kind of regular unannounced random inspection of their home you'd never know if they were a hoarder. And if they never caused or were involved in a security incident in the past there would probably be very little desire to bother shaking them down. I'd say problems in this category may be worse internally. I've met many husks of people in government positions who have been there for decades and are completely unemployable. What's worse is they can't be fired easily like a contractor so as long as they show up sober 9-5 they never leave. Not saying it's a good situation. The contractor knowingly and clearly broke laws, policies, and rules. I annually have to take record keeping and security courses and quizzes to maintain access to the network. I am sure the contractor implicated here had much more stringent requirements than I have due to his clearance level. Thus this guy's screwed, his company is screwed too. legally too. Lord knows this guy can't pull strings at the DoJ to save his ass like some people from recent memory.
- thingexplainer 10y agoAs an outsider looking in, it seems like there have been a lot of DLEs due to contractors though. Theres the obvious example of Snowden, but also the QinetiQ breach (https://www.bloomberg.com/news/articles/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets https://www.bloomberg.com/news/articles/2013-05-01/china-cyb...). Moonlit Maze might be a counterexample.
- gnarbarian 10y agoI think that's because most of the people doing the work are contractors. Not because of some notion of contractors being less secure/loyal/honest/organized than gov employees. For one federal organization I work for literally everyone I work with and talk to at all levels seems to be a contractor except for a couple people. the ratio is at least 20:1 contractors to federal employees. As for why this is, it's mostly related to the reasons I mentioned in my wall of text
- thingexplainer 10y agoI agree, I never meant to imply that I thought contractors were less loyal. I appreciate the depth of your responses and hope I haven't given offense. There are just so many of them that it projects the attack surface of the DoD out; now you can attack contractors which aren't as tightly regulated, and they might hire people to, say, build their website that aren't even cleared. So now I can steal some web dev's credentials and pivot towards classified networks.
- gnarbarian 10y agoNo offense taken. And yes external contractors can pose additional security vulnerabilities since they are not always under the same security policies on their own machines. I know that some departments are changing things so all work must be performed on government equipment with government source control on internal networks. If my client does this I will definitely quit. I am already pretty burned out on the work (their policy is all internal projects must be in cold fusion)
- dsl 10y agoThe government has all sorts of pay guidelines on what people can make, which makes it near impossible for them to retain talent. Most of the NSA guys I know put in 18 or so months, then go to Booz Allen and get contracted right back to the department they left at 4x the pay (one guy even got his same desk back). Every time someone points out the "why'd they give a clearance to X person" argument, I point out that there are close to a million people with security clearances. No screening system is perfect, but for something being ran by the government it is pretty damn good.
- w8rbt 10y agoIt's roughly 5 million people. The number fluctuates, but way more than 1 million people have US government issued security clearances. http://www.defenseone.com/business/2015/04/number-security-clearance-holders-drops-12-percent/111268/ http://www.defenseone.com/business/2015/04/number-security-c...
- nommm-nommm 10y agocollecting things that interest you in a compulsory manner vs marijuana use The key difference to the government is hording can be perfectly legal while marijuana use requires you to participate in the black market.
- thingexplainer 10y agoWhich is a pretty flimsy reason to believe an adversary might find leverage against you. But hoarding is a force multiplier in the adversary's favor.
- nommm-nommm 10y agoI think it's more about willingness to participate in black market activities makes you untrustworthy in the government's eyes.