4 ms·
I interned at Lawrence Livermore for three summers and a fall circa 2010, first building internal web apps for IT and then building open source websites for the
by glacials 4y ago
I interned at Lawrence Livermore for three summers and a fall circa 2010, first building internal web apps for IT and then building open source websites for the climate group. As someone who needs a large amount of autonomy, I wouldn’t do it again.
My experience was that 80% of the folks are lifers, for better or worse. Work-life balance was great because everyone’s got kids and soccer games and traffic to beat home, but it was still very much a “butt in chair” system, not a “get work done” one. People regularly do “10-40” (10-hour days M-Th) or “9-80” (9-hour days M-Th, every other Friday off) schedules.
Compared with startup life and even FAANG, everything moves slowly. It’s a combination of real security, security theater, and the red tape that comes with being funded by taxpayer money. That plus the extra rules from just being near the nuclear stuff (can’t drink at lunch, guests need a background check, relationships with foreign nationals must be disclosed) made it a slog.
The most hilarious example, heard only through stories: there are two internal networks, the normal one everyone uses and the high-security one that has no internet access. They are physically separate—no cables crossed, no SSH tunnels, no bridges, nothing. But you have to transfer data between them sometimes, so you would remotely load your data onto a tape drive, and there was a tech you would ping who would eject the tape, run it over to the other network, and insert it in.
As with anything rote, the process was soon automated with a shell script. The script would take a couple of minutes to execute, and your data would be transferred. Entire workflows were built on this script. And around noon every day the latency would skyrocket, because the tape runner was on lunch.
- gateorade 4y agoThe story about how data had to be manually transferred between the unclassified and classified networks might seem odd to people not used to how this world works, but it's extremely common to this day and absolutely necessary in certain scenarios. If you have a network that must be absolutely secure, both to data extraction and the injection of malicious software, airgapping the network and tightly controlling writable media is the only option. See STUXNET [1]. These days there are some solutions where the high-side and low-side networks are only pseudo airgapped with things like data-diodes or cross-domain guards [2] but these are really only implemented in scenarios where the frequency of high-side to low-side transfers (and vice versa) necessitates it and/or in relatively low-security (but still classified) networks. 1. https://en.wikipedia.org/wiki/Stuxnet https://en.wikipedia.org/wiki/Stuxnet 2. https://en.wikipedia.org/wiki/Cross-domain_solution https://en.wikipedia.org/wiki/Cross-domain_solution