8 ms·
“The Department’s most consequential strategic competitor and the pacing challenge for the Department, the People’s Republic of China,3 as well as other state-s
by asynchronous 4y ago
“The Department’s most consequential strategic competitor and the pacing challenge for the Department, the People’s Republic of China,3 as well as other state-sponsored adversaries and individual malicious actors often breach the Department’s defensive perimeter and roam freely within our information systems.”
This statement from the actual PDF really is telling for how far the DoD has dropped the ball on protection- maybe spend less time fleshing out offensive capabilities and more time on defense of your citizens?
- edgyquant 4y ago>maybe spend less time fleshing out offensive capabilities and more time on defense of your citizens With our budget the two are not mutually exclusive
- prvit 4y agoAnd they’re often the same. Take cyber “offensive” capabilities for example. Why do those exist? To provide intelligence for defense.
- Godel_unicode 4y agoNot really? Cyber threat intelligence is an incredibly overblown industry, remarkably similar to the xkcd about crypto. Offensive capabilities are for Natanz. Everyone seems to think they need super ninja threat intel to protect them from elite nation state hackers, meanwhile they’re being randomware’d with metasploit modules from 8 months ago. Run A/V and patch, that’ll be $1.7million, thanks.
- prvit 4y agoNothing in my comment has anything to do with “cyber threat intelligence”. Did you reply to the wrong comment?
- Godel_unicode 4y ago> To provide intelligence for defense. Did you forget what you wrote?
- prvit 4y agoI didn’t forget what I wrote, I just exist in the real world where missiles are a bigger threat than hackers.
- Thorrez 4y agoThat quote is from this PDF: https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTStrategy.pdf https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-Z...
- prvit 4y ago> maybe spend less time fleshing out offensive capabilities and more time on defense of your citizens? What do you mean? The US should invest in cyber defenses instead of fighter jets?
- Enginerrrd 4y agoNo it's just that the NSA used to work to make American companies more secure. Now they instead they find zero-days to then secretly exploit for as long as possible. It's gotten so bad, that their recommendations for crypto are regarded with a significant degree of skepticism because of past history of deliberately undermining crypto systems which is a Terrible state of things.
- lazide 4y agoThey do both, but right now the technology makes real defense (when you have real users) pretty much impossible. And not because of the NSA.
- _jal 4y agoThey do both, but it has been the case for a while that the NSA prioritizes offense. You can agree with that stance or not, but it is there, criticism on this point goes back at least a decade. I agree that the security environment is awful, but that doesn't excuse NSA making it worse.
- prvit 4y agoOf course NSA prioritises offense when it provides a vastly greater RoI.
- lazide 4y agoAlso, outside of SCIF environments (which do get prioritized), there isn’t a whole lot that is feasible for DOD or other gov’t agencies to do while still using civilian technology or working habits, which they don’t really have an option on right now. The whole industry and economy needs to be upleveled software wise in a lot of ways for meaningfully better security to be economically possible. Typically that requires a serious crisis and/or war. Hopefully not the case here.
- CKMo 4y agoI was reading it and going "Are...are you allowed to publicly admit this?" It's a wild time, I'm telling you
- imwillofficial 4y agoAs an insider, I’ll say it’s a selective reading of the facts on the verge of hyperbole.
- ynbkc 4y agoIf this is true, why now?
- recuter 4y agoBudget.
- asynchronous 4y agoI could see that being the case, drumming up the situation so they get more funding to fix the problem. At least I hope that is the case, over the alternative.
- Godel_unicode 4y agoThat is absolutely not the case.
- imwillofficial 4y agoIt is absolutely the case. I worked network defense for Network Warfare Command. There is literally nobody on earth more qualified than me than me to make the statement I did.
- Godel_unicode 4y agoYou’re aware that the DoD is more than just the navy, yes? Also, the defender’s having missed a bunch of intrusions is literally exactly what this report is saying. Sorry to be the one to tell you.
- nonameiguess 4y agoThey are. The entire purpose of the zero trust push is that it is nearly impossible to completely prevent perimeter breaches, so instead design in such a way that an actor inside your perimeter is not automatically trusted.
- PLG88 4y agoYou can almost entirely prevent perimeter breaches (from untrusted attacks) by implementing authenticate-before-connect with strong identity incl. closing all inbound ports at source and destination.