5 ms·
I'm not optimistic about the US Gov's ability to defend and maintain these networks. Yeah they have a lot of money to throw at the problem but eventually you ha
by irateswami 6y ago
I'm not optimistic about the US Gov's ability to defend and maintain these networks. Yeah they have a lot of money to throw at the problem but eventually you have to put the best, most knowledgeable people in front of those computers and do work. They can't hire the best and brightest though, and are otherwise unwilling to make the policy changes necessary to be able to. When security professionals can make 2-3x in the private sector and smoke as much weed as they want (in this case the stereotype has some truth to it; a lot of devs/engineers use marijuana) what incentive is there to work for one of these alphabet-soup government agencies?
Even if the positions paid more and had more modern drug testing policies, I have never, NOT ONCE, met someone who works in software at a government agency or at a company doing government contract work who wasn't a massive fuddy-duddy-boomer.
These breaches will continue to happen until the Gov takes a more pragmatic approach to it's technology and brings it's culture more in line with the private sector.
- ericmcer 6y agoI don't even think many devs are 'stoners' in the sense of using marijuana daily. I don't think you could code at a high level if you were actually smoking weed every day, but it just feels invasive for a job to tell me I can NEVER touch it and they will monitor me to check. I am not a huge fan of alcohol, but if a job told me I could never drink again and they will test me to see if I have been drinking it would feel super invasive and be a huge turn off.
- i_haz_rabies 6y agoI think you'd be surprised. I smoke pretty much every day, at least. That said, only in the evening when I'm done work and I'm not exactly programming control systems for SpaceX or whatever.
- wbronitsky 6y ago> I don’t think you could code at a high level if you were actually smoking weed every day Ah, but on the contrary, I can confirm, based on what I consider a “high level” of coding, that some people cannot code without smoking weed every day. I can also assure you that many, many devs are daily users, quality of code output not withstanding.
- ericmcer 6y agoIt probably affects everyone a little differently, I know if I start smoking every day my brain is noticeably slower. I can still get by but I cannot visualize and store as much code in my mind at one time. Adversely tons of sleep, creatine and coffee seem to expand my context and I can hold a lot more simultaneously. Life is also not about being the best programmer though, so I would definitely trade ability for comfort if weed was offering that.
- March_f6 6y agoA start would be moving the NSA head office out of some rather depressing forest in Maryland and perhaps to say Venice Beach? :)
- 127001brewer 6y agoThere are a lot of things to do outdoors around Maryland: there are a lot really good MTB (or just hiking) places, like Rockburn and Patapsco State Park; beaches are within two hours away; ski / snowboarding places within two hours away; and then there's the Chesapeake Bay. It's not California, but it's nothing either.
- Animats 6y agoCSIA isn't part of NSA. It's part of Homeland Security. That's probably worse for doing anything technical. NSA has a track record of solving hard problems. Homeland Security is a collection of police departments gathered together for political reasons.
- the_only_law 6y agoReminds me of an article that got posted here several months back about the UK government having issues hiring a high level IT worker (I think it was some sort of director). While everyone else was talking about pay, one user pointed out that in such a position they’d be effectively neutered by the bureaucracy and politicians (and others) chasing other interests that would effectively be against the positions missions.
- Veserv 6y agoThere is lots of evidence that the "best and brightest" are also totally incapable of defending and maintaining networks against skilled individuals, let alone skilled organizations, let alone state actors. I can not think of a single commercial organization which would even dare to claim they could protect against state actors or even provide any legally binding, quantitative assessment of their security that should inspire any confidence in their ability to defend against a single competent individual. You can just look to Google Project Zero to see a continuous stream of evidence of singular skilled professionals breaching these systems within mere weeks to months. Hardly comparable to the resources of state actors who can deploy hundreds or thousands of skilled professionals for years. To go from being unable to defend against skilled individuals to being able to defend against state actors would require on the order of a 100,000% improvement in capability by the "best and brightest".
- tmotwu 6y agoYou're oversimplifying the issue to unnecessarily devalue the "best and brightest", whoever you appear to be referring to, and are giving too much credit to state actors. When organizations rely on hundreds to thousands of platforms to operate, and those platforms are under the weight of hundreds and thousands of dependencies, it's not unlikely one could discover and quickly take advantage of randomly sprinkled secrets in some github repository. Humans, weak passwords, and improperly configured ACL are often the common denominator in the majority of recent breaches, not the systems themselves. People get lazy and start overlooking well established protocols that could have prevented these attacks. It's hard to do this right unless you hire red teams to perform monthly audits of every possible leakage or attack vector.
- Veserv 6y agoI do not see how that is disagreeing with my statement. If the security architecture of your IT system can be compromised by stupid mistakes in some selection of hundreds to thousands of dependencies and that selection was not audited then the security architecture can not protect from simple attacks which, almost definitionally, means the security process is largely useless as attackers do not care to attack only where the systems are strong. If auditing dependencies is viewed as "too hard" or "too expensive" I do not see how that has any bearing on the security of the system. It merely demonstrates that improving the security is not worth the cost tradeoff, it does not somehow magically improve the objective security of the system. The objective evaluation of a comprehensive security architecture depends on its holistic effectiveness, not merely the effectiveness of the parts the designers thought about. By that metric, I am not aware of any commercial IT system that even meets the low bar of protecting against an attack with a mere $10M in funding, let alone the billions a state actor has access to. So, a question for you, are you aware of any commercial IT system in the entire world that you think would survive a $10M open bounty let alone $1B? If so, what objective, empirical evidence do you have to justify that claim? Hopefully one day I might get a convincing response to this question.
- TurkishPoptart 6y agoIt seems that Russia's cyber prime directive is to ceaselessly attempt to penetrate USG contractor's systems, which, to a layperson seems like an obvious cybersecurity flaw. How are these systems secured in other Western countries? How do France and the UK, for example, secure their critical infrastructure networks? The U.S. strategy of just contracting out all these essential service is revealing its pressure points. Seems that the USG insists on just cutting checks to these companies like SolarWinds, which are more interested in gaining clients, generating revenue, and marketing than effectively engineering durable solutions. Another factor is probably NIST's questionable practices about password hygiene (requiring them to be changed every 30-60 days).