4 ms·
Of course NSA prioritises offense when it provides a vastly greater RoI.
by prvit 4y ago
Of course NSA prioritises offense when it provides a vastly greater RoI.
- lazide 4y agoAlso, outside of SCIF environments (which do get prioritized), there isn’t a whole lot that is feasible for DOD or other gov’t agencies to do while still using civilian technology or working habits, which they don’t really have an option on right now. The whole industry and economy needs to be upleveled software wise in a lot of ways for meaningfully better security to be economically possible. Typically that requires a serious crisis and/or war. Hopefully not the case here.
- _jal 4y ago> provides a vastly greater RoI Of course it does. Thinking about it in terms of ROI doesn't consider externalities. When the OPM gets hacked, nobody at the NSA worries about their budget. Reason #7893 "run government like a business" is a self-describing category error.
- lazide 4y agoeveryone uses ROI calculations somewhere (just not necessarily using cash as the return metric) or they are flying blind. The underlying issue is that large organizations have low trust (some worse than others!), and therefore large organizations tend to coarse numeric metrics, and game those metrics to look better, which makes even more low trust (and hence backstabbing, empire building, etc.) between divisions. As a reaction, leadership also tends to err towards coarse, harder to game metrics (like ‘reduce breaches by xx%’ rather than relying on judgement and trust like ‘ensure we don’t have an unreasonable number of breaches, and work to reduce them in the ecosystem’. Which of course provides strong incentives for chasing the number by throwing all the babies out with the bathwater, and often making the real problem worse. It’s a size of the organization problem. Changing metrics/mission will shuffle up the specific babies being thrown out, and what is considered the bath water, but the underlying problem remains. Solid, consistent leadership makes the problem better. That tends to be expensive and not want to deal with the political BS common in Gov’t, at least in the US.
- deleted 4y ago[deleted]
- _jal 4y agoFormer employee, or contractor?
- lazide 4y agoThankfully No, but I know a few. If you think tech workers have office BS to complain about, gov’t workers are at least 10x higher on the scale.
- Godel_unicode 4y agoThe government does a ton of pure research, including in computer science and security, which is explicitly not about ROI but rather about advancing our understanding of basic science.
- lazide 4y agoWhich always has a grant proposal laying out hoped for results in areas being investigated, at least most of the time correct? Someone looks at it and goes ‘yeah, that might pay off’ or round files it somewhere. Researchers who never end up finding anything notable also don’t tend to have long careers, correct?
- Godel_unicode 4y agoNone of that is what I’m talking about, no. I know many researchers who are quite proud of the fact that their research is never going to make money but is super interesting from a scientific perspective. The crazy amount of skepticism this always draws is simultaneously very funny and very saddening.
- lazide 4y agoThat a percentage of total funds is put into stuff like that isn't surprising, to avoid too much hyperfocus on what we know. What percentage of the overall budget do you think it is?