https://www.theregister.com/2021/09/03/usaf_chief_software_officer_quits_angry_post/ [user] [user] Sign in The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem All On-PremServersStorageNetworksHPCPersonal Tech (X) Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice All Vendor VoiceAdobeAmazon Web Services (AWS)Amazon Web Services (AWS) MigrationGoogle CloudGoogle Cloud's ApigeeGoogle Workspace NutanixRapid7Red hatSophosVeeamVirtru (X) Resources * Whitepapers * Webinars * Newsletters Situation Publishing * The Next Platform * Devclass * Blocks and Files Get our Weekly newsletter [front] Software US Air Force chief software officer quits after launching Hellfire missile of a LinkedIn post at his former bosses Too many inexperienced project managers and not enough DevSecOps Gareth Corfield Fri 3 Sep 2021 // 18:14 UTC 17 comment bubble on white --------------------------------------------------------------------- 17 comment bubble on white # reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy The US Air Force's first ever chief software officer has quit the job after branding it "probably the most challenging and infuriating of my entire career" in a remarkably candid blog post. Nicolas Chaillan's impressively blunt leaving note, which he posted to his LinkedIn profile, castigated USAF senior hierarchy for failing to prioritise basic IT issues, saying: "A lack of response and alignment is certainly a contributor to my accelerated exit." Chaillan took on his chief software officer role in May 2019, having previously worked at the US Department of Defense rolling out DevSecOps practices to the American military. Before that he founded two companies. [front] In his missive, Chaillan also singled out a part of military culture that features in both the US and the UK: the practice of appointing mid-ranking generalist officers to run specialist projects. [front] [front] "Please," he implored, "stop putting a Major or Lt Col (despite their devotion, exceptional attitude, and culture) in charge of ICAM, Zero Trust or Cloud for 1 to 4 million users when they have no previous experience in that field - we are setting up critical infrastructure to fail." The former chief software officer continued: We would not put a pilot in the cockpit without extensive flight training; why would we expect someone with no IT experience to be close to successful? They do not know what to execute on or what to prioritize which leads to endless risk reduction efforts and diluted focus. IT is a highly skilled and trained job; staff it as such. In the British armed forces mid-ranking officers are posted, regardless of qualifications or professional experience, to manage equipment-purchasing projects for the Ministry of Defence. These postings are of fixed length and last for two years, meaning any project that takes more than two years has the potential to end up turning into a hugely expensive and unproductive mess. The origin of this policy was a 1980s corruption scandal where a civil servant overseeing a long-term MoD contract was caught accepting bribes; to prevent it happening again, senior personnel decided to implement the two-year-posting policy. Chaillan went on to complain that while he had managed to roll out DevSecOps practices within his corner of US DoD, his ability to achieve larger scale projects was being hampered by institutional inertia. [front] "I told my leadership that I could have fixed Enterprise IT in 6 months if empowered," he wrote. Among the USAF's sins-according-to-Chaillan? The service is still using "outdated water-agile-fall acquisition principles to procure services and talent", while he lamented the failure of the Joint All-Domain Command and Control (JADC2) to secure its required $20m funding in the USAF's FY22 budget. * US Navy starts an earthquake to see how its newest carrier withstands combat conditions * US Air Force announces plan to assassinate molluscs with hypersonic missile * Chuck Yeager, sound barrier pioneer pilot, dies at 97 * Talk about a control plane... US Air Force says upcoming B-21 stealth bomber will use Kubernetes He was also quite scathing about the USAF's adoption - or lack thereof - of DevSecOps, the trendy name for efforts to make developers include security-related decisions at the same time as product-related decisions when writing new software. It appears the service wasn't quite as open-minded as its overseers in the wider DoD. "There is absolutely no valid reason not to use and mandate DevSecOps in 2021 for custom software," wrote Chaillan. "It is borderline criminal not to do so. It is effectively guaranteeing a tremendous waste of taxpayer money and creates massive cybersecurity threats but also prevents us from delivering capabilities at the pace of relevance, putting lives at risk, and potentially preventing capabilities to be made available when needed whenever world events demand, many times overnight." Doubtless his full post will chime with anyone else in a senior post at a tech company who eventually becomes fed-up enough not only to quit but also to tell the wider world exactly why. [front] So far the USAF hasn't publicly responded to its former chief software officer. (r) Get our Tech Resources #Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy 17 Comments Corrections Send us news --------------------------------------------------------------------- [front] Other stories you might like * Lenovo pops up tips on its tablets. And by tips, Lenovo means: Unacceptable ads Amid customer fury, PC maker says it has 'no plans to add any further push notifications' to its stealth adware Tim Richardson Fri 3 Sep 2021 // 22:32 UTC 5 comment bubble on white Lenovo has come under fire for the Tips application on its tablets, which has been likened to indelible adware that forces folks to view ads. One customer took to the manufacturer's support forum late last month to say they were somewhat miffed to see an ad suddenly appear on screen to join Amazon Music on their Android-powered Lenovo Tab P11. The advertisement was generated as a push notification by the bundled Tips app. "There is no option to dismiss," the fondleslab fondler sighed. "You have to click to find out more. Further, these notifications cannot be disabled, nor can the Lenovo 'Tips' app be disabled." Continue reading * Alpha adds to tally of exploding rockets, takes out space sail prototype with it Firefly Aerospace rounds out a wobbly week for rocket fanciers Richard Speed and Katyanna Quach Fri 3 Sep 2021 // 21:34 UTC 1 comment bubble on white Video The sudden and explosive end of Firefly Aerospace's first test flight of its Alpha rocket rounded out a hat-trick of woe for rocket fans this week. The Alpha, which Firefly has pitched as being able to loft 1,000kg to low earth orbit (LEO), finally left its pad at California's Vandenberg Space Force Base at 01:59 UTC on 3 September, only to tumble and explode around two-and-a-half minutes into the flight of the booster. Observers of the launch were treated to the sight of the rocket lurching perilously before exploding as the trip was terminated. You can watch the full thing below: Continue reading * Apple stalls CSAM auto-scan on devices after 'feedback' from everyone on Earth Critics celebrate reconsideration of 'spyPhone' regime Thomas Claburn in San Francisco Fri 3 Sep 2021 // 20:48 UTC 13 comment bubble on white Apple on Friday said it intends to delay the introduction of its plan to commandeer customers' own devices to scan their iCloud-bound photos for illegal child exploitation imagery, a concession to the broad backlash that followed from the initiative. "Previously we announced plans for features intended to help protect children from predators who use communication tools to recruit and exploit them and to help limit the spread of Child Sexual Abuse Material," the company said in a statement posted to its child safety webpage. "Based on feedback from customers, advocacy groups, researchers and others, we have decided to take additional time over the coming months to collect input and make improvements before releasing these critically important child safety features." Continue reading * Apple engineers complain of hostile work environment to US labor watchdog Harassment, bans on discussing pay, responsibilities slashed, and more alleged Tim Richardson Fri 3 Sep 2021 // 19:14 UTC 3 comment bubble on white The US National Labor Relations Board (NLRB) - which investigates complaints against employers - is to examine claims made by two Apple employees, including allegations of unfair changes to working conditions, harassment, and muzzling pay equity discussions. Ashley Gjovik, a senior engineering program manager at Apple who filed her complaint on August 26, told Reuters she experienced at the very least "harassment by a manager, reduction of responsibilities, and increases in unfavorable work." According to the FT, Gjovik was placed on indefinite paid administrative leave last month while Apple investigated her claims of a hostile work environment. Continue reading * Don't like the new Windows 11 Start or Taskbar? Don't worry - Microsoft's got your back Insiders, they don't like it. Bork the Taskbar, bork the Taskbar Richard Speed Fri 3 Sep 2021 // 17:06 UTC 13 comment bubble on white Microsoft's efforts to shed as much glory as possible with its Windows 11 release have continued with the sudden breakage of the Start Menu and Taskbar for its happy band of Insiders. The cock-up happened in the latest preview build of Windows 11, 22000.176 for Beta Channel users and build 22449 for those lucky enough to still be in the Dev Channel. The Beta Channel release is supposedly the more stable of the pair. Affected Insiders found, according to Microsoft, "that Start and Taskbar were unresponsive and Settings and other areas of the OS wouldn't load." The result was a hurried update requiring those impacted to do a bit of Registry tinkering in order to get things back to normal. Continue reading * Component shortages: HPE pushes up some hardware prices and as if by magic, reports 'record' gross margin in Q3 Average unit prices climbed mid-to-high single digits, confirms chief beanie Paul Kunert Fri 3 Sep 2021 // 16:00 UTC 4 comment bubble on white Hewlett Packard says it filed record gross margins for its latest financial quarter after increasing prices for hardware including servers and networking kit in response to industry-wide component shortages. The biz last night reported sales of $6.897bn for its Q3 ended 31 July versus $6.816bn a year ago - representing a rise of one per cent. This was still down on the $7.217bn HPE achieved in the same quarter of pre-pandemic 2019. The largest division remained Compute, which recorded turnover of $3.104bn, down 9 per cent year-on-year. CFO Tarek Robbiati said this reflected normal seasonality "despite previously anticipated supply chain tightness". Continue reading * Rapid7 says Computer Misuse Act should include 'good faith' infosec research exemption Security biz publishes plans for law reforms Gareth Corfield Fri 3 Sep 2021 // 15:16 UTC 6 comment bubble on white Infosec firm Rapid7 has joined the chorus of voices urging reform to the UK's Computer Misuse Act, publishing its detailed proposals intended to change the cobwebby old law for the better. The cloud-based SIEM company specifically highlighted section 3A of the CMA, saying this potentially "imperils dual-use open-source security testing tools and the sharing of proof-of-concept code". It also echoed other industry concerns about criminalising general security research through section 1 of the act, which prohibits accessing a computer without the owner's permission. Continue reading * Big data means big money for the UK government as PS2bn tender mooted Central procurement team tickles the market with tantalising offer... but what for? Lindsay Clark Fri 3 Sep 2021 // 14:10 UTC 10 comment bubble on white The UK government is putting the feelers out for a bundle of big data products and services in a move that could kick off PS2bn in tendering. Cabinet Office-run Crown Commercial Service (CCS), which sets up procurement on behalf of central government ministries and other public sector organisations, has published an early market engagement to test the suppliers' interest in a framework for so-called big data and analytics systems. According to the prior information notice: "Big data and analytics is an emerging and evolving capability, with its prominence heightened by COVID. It is fast becoming recognised as business critical and a core business function, with many government departments now including chief data officers. The National Data Strategy and implementation of its missions reinforce the requirement to access and interrogate Government data more effectively to improve public services." Continue reading * New Zealand internet outage blamed on DDoS attack on nation's third largest internet provider Here in the UK, Sky broadband users back online Tim Richardson Fri 3 Sep 2021 // 13:13 UTC 4 comment bubble on white Parts of New Zealand were cut off from the digital world today after a major local ISP was hit by an aggressive DDoS attack. Vocus - the country's third-largest internet operator which is behind brands including Orcon, Slingshot and Stuff Fibre - confirmed the cyberattack originated at one of its customers. According to a network status update, the company said: "This afternoon a Vocus customer was under DDoS attack... A DDoS mitigation rule was updated to our Arbor DDoS platform to block the attack for the end customer." Continue reading * Give us a CLU: Object Oriented Programming pioneer arrives on GitHub No, not the 1980s TV show where Lionel Blair attempted to mime data abstraction to Una Stubbs Richard Speed Fri 3 Sep 2021 // 12:18 UTC 9 comment bubble on white Retro fans, rejoice! A bit of digital archaeology has turned up a working early version of the CLU programming language and the files needed to create it uploaded to GitHub. Unearthed by Lars Brinkhof, the implementation (with files mostly from 1976-1978) is an intriguing insight into the Object Oriented Programming concepts and other ideas that found favour in later programming languages. In a history of the language [FTP PostScript file] its creator, Turing award winner and MIT professor Barbara Liskov, noted it was "the first implemented programming language to provide direct linguistic support for data abstraction." Continue reading * Crypto-coin startup said its bot could generate huge profits from your Bitcoin. It was a scam, says SEC Founder and promoter accused of running 'Ponzi-like scheme' Katyanna Quach Fri 3 Sep 2021 // 11:27 UTC 24 comment bubble on white Cryptocurrency startup BitConnect and two men have been sued by America's financial watchdog, which claims the now-defunct biz swindled investors out of billions by lying to them about an automated trading bot that could reap huge profits. BitConnect founder Satish Kumbhani, 35, and promoter Glenn Arcaro, 44, are accused of breaking US fraud laws in a civil lawsuit brought this week by the SEC in New York City. The regulator alleges the pair touted a "volatility software trading bot," and promised investors the automated system could generate returns as much as 40 per cent per month. "We allege that these defendants stole billions of dollars from retail investors around the world by exploiting their interest in digital assets," said Lara Shalov Mehraban, associate regional director of SEC's New York office. "We will aggressively pursue and hold accountable those who engage in misconduct in the digital asset space." Continue reading ABOUT US* * Who we are * Under the hood * Contact us * Advertise with us * Seeking client-side dev MORE CONTENT* * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING* * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2021 Do not sell my personal information Cookies Privacy Ts&Cs