25 ms·
Defense is the critical problem. There is very little in the way of serious cyber security defensive minded assessment before projects are on-boarded. Technical
by thewildginger 4y ago
Defense is the critical problem. There is very little in the way of serious cyber security defensive minded assessment before projects are on-boarded. Technical vulnerability assessment, reverse engineering, security-by-design, all of that doesn't really exist and isn't thought of as a NECESSITY. Contractors pitch toys to different commanders, they say hell yeah, then security is this after thought and not part of development from an engineering perspective, just like almost every business working in technology. All the money goes to attacking bad guys, not to protecting what's there. Most people think it's no big deal until you realize it means the enemy can destroy expensive tools and possibly injure personnel without any physical involvement.
Legislation on security-centered development is a possible solution, but the political will from congressional sub-comittees just is not there. It could be if it was pitched as a way of enriching the states those reps are from with high paying white-collar jobs that would make states like Mississippi, Ohio and other struggling but MIC centered states at the center of a growing and important field, but alas, the contractors doing the hiring probably won't want to balance the budget on their current money printing machines for that.
This is something worth talking to your member of Congress about. Budgets might be bigger, but it helps some destitute states, improves national defense (defense defense, not war in the name of defense), and makes politicians re-electable.