7 ms·
So I can off some first hand perspective here. >Do the military "cyberwarriors" even have local admin rights on their machines? We don't, hell I don't even ha
by __john 12y ago
So I can off some first hand perspective here.
>Do the military "cyberwarriors" even have local admin rights on their machines?
We don't, hell I don't even have access to some of the basic tools I need (i.e. version control)
>Hackers don't sign up for active duty military.
They do, I've met the smartest people I know in the military . The hacker types never stay though they either get kicked out because they don't want to put up with the bullshit or separate after their first enlistment and quadruple their salary.
Basically the problem with the military is that they won't (or can't) pay enough to retain any of the talent they have and are unwilling to compensate for the low salary by changing the "culture" they've developed over the last century.
- rdtsc 12y ago> We don't, hell I don't even have access to some of the basic tools I need (i.e. version control) Yap. Dealing with the military as a customer I have definitely have seen red tape that goes beyond reasonable for security and actually downright counter-productive (the steps needed to jump through to "secure" a box, many are wasteful, antiquated, yet some obvious ones are not mentioned. There are things like "tcpdump must not be installed". So debugging is a pain, so then fine, I'll just use a python wrapper around libpcap then. Some of the password policies are odd, don't remember exactly but requiring large passwords made of random gibberish instead of long pass phrases just make people write them posted notes and carrying them in their wallets.
- phaus 12y ago>I'll just use a python wrapper around libpcap then. Must be nice, last government SOC I worked in, we could only script with powershell 1.0 installed. Sadly, that was just a year ago. We had tcpdump and Wireshark, but we weren't allowed to capture anything with it.
- nitrogen 12y agoWe had tcpdump and Wireshark, but we weren't allowed to capture anything with it. So how does anybody know there isn't data exfiltration going on?
- droopybuns 12y agoWe have our top men working on this.
- hueving 12y agoYou usually don't check for exfiltration at the workstation level.
- deleted 12y ago[deleted]
- shubb 12y ago'They have tools to listen to network traffic. But we told them not to. It's fine.' 'So... if they don't intercept network traffic, they were trustworthy and it wouldn't matter. But if they are not trustworthy... they can still sniff the traffic? Are you sure it's fine?' 'Yeah, every modern network is switched so there is nothing to sniff'
- mpyne 12y ago> Basically the problem with the military is that they won't (or can't) pay enough to retain any of the talent they have and are unwilling to compensate for the low salary by changing the "culture" they've developed over the last century. These are all problems that are slowly working their way up the policy chains. E.g. RAND has put out a very good study on all this, http://www.rand.org/pubs/research_reports/RR430.html http://www.rand.org/pubs/research_reports/RR430.html that discusses the challenges with public sector/military hiring (and retention). It may yet have to come down to putting the effort heavily on the Reserves though, because for all the other things the military can change, I don't see culture as being one of them. Even the legendarily free-wheeling communities like submarines and fighter aviation deal with red tape and subsuming egos to the team.
- phaus 12y ago>These are all problems that are slowly working their way up the policy chains. It doesn't matter that the problems are working their way up the policy chains if they are only going to die when they get to the top. You yourself admitted that they are unlikely to change the culture, and we both know they aren't about to pay a competitive wage to the military. Unfortunately, that leaves us with things exactly the way they are now. The military likes to talk about starting to take various issues seriously, yet it is an exceptionally rare occasion when they actually do.
- azernik 12y agoIn larger tech companies there's plenty of red tape, and some of the best software developers I've seen don't care a lot about ego. People I've heard talk about public sector work (never heard any talk about military software security work) complain more about cultures where there are too many incentives to focus on the narrow mission of your own organizational subunit, and little feeling of (or decision-making with a view towards) the overall goals of the broader organization.
- beagle3 12y agoCompany red tape and military culture is nothing alike. The most "conservative" company would have techies that don't meet any customers come in a suit, and those are almost extinct now. In a military, depending on where you are and your rank, you could detention / penalties for not being shaved, not having your shoes shined, having a haircut that's too long by a few centimeters. You often can't take a week (or even a day) off without weeks notice unless it's an emergency. You could go to jail for disobeying a higher up. And most importantly, if you signed up for (say) 3 years, you can't quit before those three years are up. Seriously, if you think corporate red tape is anything remotely like serving in the military - you need to revisit your idea of what the military is.
- thefreeman 12y agoI don't understand how the military cannot afford to compete with the private sector. This is where wars will be won now (or soon). It's pretty important to defend ourselves. And we have trillions of dollars...
- phaus 12y agoPart of it is that the government doesn't want to, the other part of it is that the American people would shit their pants if they found out that a low-ranking Soldier was making 6 figures a year off of taxpayer money. People resent it when government employees make more money than they do. Also, in the Army, you make the same amount of money no matter what your job is. The people they used to have that were only qualified to do laundry 40 hours a week as a full-time job get paid the same amount of money as intelligence analysts and information technology specialists.
- deciplex 12y agoThe base pay is the same, but don't they have all kinds of extra pay they can tack on for various reasons? There is combat pay, but I'm sure there must be more than that.
- __john 12y agoYou can get extra money for all kinds of things. Knowing another language, certain career fields (i.e. special forces and contracting) still have re-enlistment bonuses, etc. etc. None of the "cyber" career fields, in the Air Force at least, get any sort of extra money that I'm aware of.
- phaus 12y agoJohn is correct. There are different types of extra pay, but they don't have anything for tech related jobs. The allowances in the Army are for things like jumping out of a plane, scuba diving, foreign languages, combat pay, etc. The Army still has this attitude that if you aren't outside all day, running around yelling at people, then you must not be doing any work. I'm not sure if that will ever change.
- dm2 12y agoMany hackers / security researchers wouldn't mind working for the military but they don't have the desire to go through basic training and learn the things that will be unnecessary to their main job. If I were to join the military right now wanting to work on computer systems, how long would it take before I'm actually preforming that role, or would they have to "break" me first? Hackers have no desire to do that when they can easily stay in the private sector and earn twice the pay and have a nice cushy office to work out of. There should be some kind of alternate route to joining the military for officer and specialization roles (in my opinion of course, I am certainly interested to here if anyone has objections). Give me a few tests, an interview, a basic physical, a polygraph, and some IT training to get familiar with the systems and let me go to work. High pay isn't really an issue for me personally as long as I enjoy the work and am constantly learning or teaching. Having access to that information is a huge responsibility. There have been spies at all ranks that have done large amounts of harm to the US military. It is absolutely necessary to lock down machines and have strict security checks over each other a logging of everything.
- sliverstorm 12y agoI thought there already sort of was that kind of pathway. Do Air Force Academy pilots go through boot camp, for example?
- dm2 12y agoYes. http://www.military.com/join-armed-forces/air-force-bmt-boot-camp-schedule.html http://www.military.com/join-armed-forces/air-force-bmt-boot... How much of that is really necessary to be in IT security though? I'm sure it makes you a better person, but when you have highly skilled individuals and show them that kind of requirement, the majority of them would rather stay in the private sector. The exception is if you have a specialized degree there is officers school for the branches, but basic training is still required, you will still be marching and be broken in, but after that will be more classrooms than physical activities. Pilots especially must be physically fit. I've heard that leg strength is especially important so that you don't pass out at high g-forces. Drone pilots probably not so much, obviously. The Reserve forces might be slightly less rigorous, but I'm not positive. The cyber warfare stuff is mostly Army and Navy though as far as I know. Agencies like the DHS are the ones that are really struggling to find IT talent. They have a huge amount of responsibility (security all non-military government infrastructure) and have a bad reputation currently (because of airport security staff).