[HN Gopher] CISA broke into a US federal agency, and no one noti...
       ___________________________________________________________________
        
       CISA broke into a US federal agency, and no one noticed for a full
       5 months
        
       Author : rntn
       Score  : 110 points
       Date   : 2024-07-12 18:19 UTC (4 hours ago)
        
 (HTM) web link (www.theregister.com)
 (TXT) w3m dump (www.theregister.com)
        
       | sybercecurity wrote:
       | The only reason they noticed is because they were told, so it
       | really it should have been "..and no one noticed."
        
       | jmclnx wrote:
       | Nice they are doing their job and glad they exist.
       | 
       | But how to fix ? Most US Gov agencies are underfunded, it is
       | either beef up security or provide services. Really a tough
       | choice, and the outlook looks like they may lose even more
       | funding.
        
         | akira2501 wrote:
         | Lesson learned: The assessed organization had insufficient
         | controls to prevent and detect malicious activity.
         | 
         | Lesson learned: The organization did not effectively or
         | efficiently collect, retain, and analyze logs.
         | 
         | Lesson learned: Bureaucratic processes and decentralized teams
         | hindered the organization's network defenders.
         | 
         | Lesson learned: A "known-bad" detection approach hampered
         | detection of alternate TTPs.
         | 
         | https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
        
           | doe_eyes wrote:
           | The problem with such "lessons learned" is that they are
           | usually not lessons learned - I bet there were numerous
           | people within the organization who knew about these issues
           | before the test.
           | 
           | The actual issue is probably that these people are (a)
           | ineffectual at communicating and prioritizing concerns
           | clearly; or (b) good at communicating, but are not being
           | listened to; or (c) they are listened to, but the
           | organization has no practical means to fix this - no money,
           | unable to recruit talent, etc.
           | 
           | Most techies often assume (b), but (a) is at least as common.
           | The last issue - (c) - might be superficially true, although
           | it's usually not correct in a deeper sense: there is plenty
           | of discretionary and wasteful spending in any sufficiently
           | large bureaucracy. Central resource allocation is just a hard
           | problem.
           | 
           | Anyway, my point is that the problems that need fixing are
           | almost never just technical. Recommendations such as
           | "implement sufficient controls to detect malicious activity"
           | seldom get to the root cause. They are still useful in
           | temporarily overcoming organizational obstacles, but it
           | usually doesn't last.
        
         | Rinzler89 wrote:
         | _> Most US Gov agencies are underfunded_
         | 
         | Doesn't the US outspend in terms of dollars almost every single
         | developed country on the planet at absolutely everything, even
         | in per capita statistics, from military, police to education
         | and healthcare? How could it be underfunded?
        
           | lazide wrote:
           | The first thing you learn in government is that _you're_
           | always underfunded.
           | 
           | If you aren't, your budget will go to someone who is.
        
           | throwway120385 wrote:
           | The US is really really big. People way underestimate how
           | huge it is in terms of land area. You could fit Europe inside
           | the US. So the reason Germany or France underspend the US has
           | more to do with the area they have to cover and the number of
           | people they have in their borders.
        
             | dmix wrote:
             | > even in per capita statistics
        
               | tossandthrow wrote:
               | The argument is density. Things tend to be cheaper per
               | capita, when density is high.
               | 
               | I don't buy it thought. I think the reason why the spend
               | is less in Europe is due to higher salary equality - good
               | people take job in government because the salary is
               | _only_ 50% higher in private sector (for tech, even less
               | for other areas).
        
               | vidarh wrote:
               | There are only a couple of US states less dense than e.g.
               | Norway, and even in those states the vast majority of the
               | population live in small, higher density areas.
               | 
               | The areas where the vast majority of Americans actually
               | live are fairly high density.
               | 
               |  _Some_ cost might come down to density, but not much.
        
               | tossandthrow wrote:
               | Agreed, only trying to make the comment justice - not
               | agreeing.
               | 
               | Arguable, Denmark has a super low density also if you
               | count in Greenland.
               | 
               | As also written, I don't buy that argument. I think the
               | core is inequality.
        
             | coldtea wrote:
             | > _You could fit Europe inside the US._
             | 
             | If we're considering contiguous US, then no.
             | 
             | Europe is 3.93 million square miles.
             | 
             | Contiguous US is 3.15 million square miles.
        
               | saalweachter wrote:
               | I'm guessing the poster was thinking of "Europe" as more
               | like "the EU" or "Europe minus Russia"; 1.1 million of
               | Russia's 6.6 million square miles are part of Europe's
               | 3.93; take it away, and "Europe" drops to more like 2.8
               | million square miles, a smidge less than the contiguous
               | US.
        
           | Jtsummers wrote:
           | In total the US executive is very well funded, but individual
           | agencies aren't always well-funded and often lack the
           | specific skillset to properly utilize funding even if they
           | have it, especially wrt IT systems when that's outside their
           | main field of expertise.
        
             | dmix wrote:
             | Yes the should try having less of them. There's 438 total,
             | it'd probably take CISA years to red team all of them.
        
               | oneplane wrote:
               | So your solution to a problem that exists because there
               | isn't enough capacity to go around is to compound that
               | problem by having even less capacity?
        
               | nradov wrote:
               | The federal government does too much. We could simply
               | eliminate many of those agencies and save money for
               | taxpayers, or redirect those resources to more important
               | functions. There is excess capacity, it's just in the
               | wrong places.
               | 
               | As for IT functions, all of that should be centralized
               | under the GSA with proper security controls. There's no
               | benefit to having every agency maintain its own IT
               | infrastructure. Most of those staff are redundant and
               | could be laid off.
        
               | notaustinpowers wrote:
               | I worry for having a centralized IT infrastructure as
               | that now puts every single agency at risk from a single
               | attack. No one would call a neighborhood "secure" if
               | every home used the same key.
        
               | acdha wrote:
               | > As for IT functions, all of that should be centralized
               | under the GSA with proper security controls. There's no
               | benefit to having every agency maintain its own IT
               | infrastructure. Most of those staff are redundant and
               | could be laid off.
               | 
               | This works for email. Would you work at a company where
               | you had to build and deploy apps on infrastructure
               | controlled by someone in a different department and
               | location, whose boss gave them the mandate to standardize
               | as much as possible to reduce costs? (Hope you like
               | Oracle...)
        
               | Uvix wrote:
               | That was your fairly typical on-premise corporate
               | hosting. Things have gotten _better_ with the cloud but
               | it 's still hardly a free-for-all, use-whatever-you-want-
               | with-no-oversight situation.
        
               | acdha wrote:
               | Cloud environments helped, but the kind of massively
               | centralized environment they're talking about in the
               | cloud work still tends to mean "get 4 levels of approvals
               | and you can get a t3.medium using our AMI with Java 6".
               | My point is just that successful IT needs people who
               | understand the mission and share your incentives - you
               | can outsource email and other generic services but most
               | people here work on things which aren't one-size fits
               | all.
        
               | LamaOfRuin wrote:
               | Everyone agrees the government does too much of some
               | stuff and not enough of other stuff. No one agrees on
               | what belongs in which category.
        
               | fleabagmange wrote:
               | Omar a minimum we need to deduplicate insane degrees of
               | replication. Why does virtually every government agency
               | have dedicated law enforcement? Narrow it down,
               | reallocate budget, eliminate the wasteful overhead.
               | 
               | It's not all or nothing here. We spend too much and get
               | too little out of it.
        
               | redserk wrote:
               | Law enforcement is incredibly difficult, especially with
               | the number and types of laws on the books. You want
               | multiple different law enforcement agencies so they can
               | specialize based on the field of law they are in.
               | 
               | Currency counterfeiting is a different set of laws than
               | interstate financial fraud, which is a different set of
               | laws than throwing a Snickers wrapper on the ground in
               | Yosemite.
        
               | coldtea wrote:
               | > _Currency counterfeiting is a different set of laws
               | than interstate financial fraud_
               | 
               | Which is somewhat irrevant. Teams dealing with each can
               | still share headquarters, IT resources, support stuff,
               | cafeterias, and lots of other things.
        
           | mrguyorama wrote:
           | The US government is broadly disallowed, for political
           | reasons, from doing anything. So they have to buy services on
           | the open market, where they get charged through the nose.
           | 
           | Our state legislature recently voted down adding a new Data
           | Analyst position to one of their departments. That department
           | cannot function without that position, so instead it has to
           | use it's funding to buy that same position from a 3rd party
           | contractor for 3x the price or more.
           | 
           | The result is that we pay more than anyone else for basically
           | everything we do.
        
             | iisan7 wrote:
             | I generally agree that the government often hamstrings
             | itself. But consider also that you can't terminate state
             | employees easily, and their benefits packages often cost
             | more than 100% of their salary. The salary itself and the
             | working conditions often don't attract the best talent.
             | Thus it's not always so cut and dry in terms of what's the
             | best outcome for the public interest.
        
               | Jtsummers wrote:
               | It's getting centralized anyways, just not inside any
               | federal agency. Instead they're outsourcing it to
               | companies like MS and Google who provide hosted services.
               | This gives the agency cover so long as they do their part
               | (like making use of MFA, using encryption on email). Then
               | they can offer a claim of making their best-effort and
               | going with industry "standards" (standard as in common,
               | not as in ISO, ANSI, or others).
        
           | ndriscoll wrote:
           | My understanding is that regardless of funding, the US
           | federal government has standardized pay scales that top out
           | way below what private industry pays, so even well funded
           | agencies can only possibly get junior developers/IT or people
           | that are willing to take a significant (50-80%) pay
           | reduction. The very most you can possibly make as a GS15 in
           | 2024 is 191,900, and they have locality-adjusted pay with
           | most localities being below that.
           | 
           | They might also generally still drug test? I don't even do
           | drugs, but I'm not going to pee in a cup for someone to
           | effectively do charity lol. Good luck recruiting a
           | professional with decades of engineering experience when you
           | treat them like they're a 16 year old working at Taco Bell.
           | Even someone with 0 years doesn't have to deal with that kind
           | of treatment in industry.
        
             | SanderNL wrote:
             | Charity? I sympathize somewhat, but I'm also disgusted by
             | the utter lack of respect for government and societal
             | service in general. That shit means something.
             | 
             | I wish to believe there are still people that don't care
             | about making Yet Another few hundred thousand and just want
             | to actually contribute to society instead of working on ad
             | tech or whatever bullshit.
        
               | arcimpulse wrote:
               | Regardless of whether or not one personally enjoys the
               | work one is doing, if one really is contributing to
               | society, one should get fairly compensated for it.
               | 
               | Additional requirements not common in the private sector,
               | such as rigorous drug testing, ethics codes, requirements
               | on gift reporting, increased surveillance, etc., should
               | come with additional benefits to compensate. Instead,
               | government workers submit to these requirements _and_ a
               | substantial pay cut.
               | 
               | That's mostly because conservatives 1) desire tax cuts at
               | any cost and 2) want to demolish the entire
               | administrative state. The stability and consistency that
               | comes with a well-funded civil servant class are an
               | obstruction to their stated goals.
        
               | jholman wrote:
               | I vouched your comment, because I think you're precisely
               | making the relevant point in the first two paragraphs.
               | 
               | However, I think you're wrong, at least in part, in your
               | third paragraph. I mean, I think the word "mostly" is
               | wrong in that paragraph. Politicians from all political
               | factions are (quite reasonably) under pressure to lower
               | the cost of doing the work of government, and (quite
               | reasonably) to raise the integrity of the process.
               | Combined with some of the dysfunction inherent in agent-
               | principal problems, I think that's more than enough to
               | cause the problem you're talking about. I experience this
               | firsthand in a jurisdiction that has much less of the
               | "demolish the entire administrative state" that afflicts
               | the American right wing (which I'm guessing is your point
               | of reference).
               | 
               | Mind you, I am _not_ claiming that the problem is not
               | _badly worsened_ by American right-wing politics. I
               | wouldn 't know. I'm just claiming that the problem is
               | semi-intrinsic to the situation, and I strongly doubt
               | that it's "mostly" caused by those particular political
               | issues.
        
               | tossandthrow wrote:
               | The issue is that the housing price is set by the people
               | that _do_ care about making Yet Another few hundred
               | thousand.
               | 
               | Equality is good for equality sake. This is a lesson
               | contemporary North Americans seem to have forgotten in
               | record time.
        
               | jholman wrote:
               | I'm confused. You're complaining about the use of the
               | word "charity"?
               | 
               | Background: You make an argument that at least some
               | people should consider putting contributions to society
               | ahead of "making yet another few hundred thousand". I
               | agree with you, at least broadly, and I think the up-
               | thread poster is not disagreeing.
               | 
               | Summary: We're discussing the act of taking a personal
               | financial hit, for the good of society.
               | 
               | The word for that is "charity". That's what that word
               | means.
               | 
               | ---------
               | 
               | I also am sympathetic to the GP's point, about which you
               | are so "disgusted", but I think there's room to disagree
               | there.
               | 
               | I am sympathetic because professionally I do work that
               | many people think is "good for society", I currently earn
               | approximately median income (below mean) for my
               | age/gender/nationality, far far below software engineer
               | pay, and I am treated with unbelievable disrespect by my
               | employer, the government. If I was not trapped in this
               | job by personal circumstance (for now), the disrespect
               | part would definitely factor into my decision making
               | about staying in this allegedly-virtuous job. If you're
               | gonna pay people below market, and you treat them badly,
               | that's not a combination that gets you quality employees.
               | Even if there's some social purpose.
        
               | coldtea wrote:
               | > _Summary: We 're discussing the act of taking a
               | personal financial hit, for the good of society.
               | 
               | The word for that is "charity". That's what that word
               | means._
               | 
               | Calling it "charity" impies it's done out of
               | pity/compassion.
               | 
               | The parent implies it should be seen as a duty /
               | contribution to the country instead.
        
             | Jtsummers wrote:
             | Drug testing is mostly limited (for civilians) to those
             | with access to sensitive, secret, or TS information. In
             | those orgs, you have higher odds of being drug tested as a
             | contractor in the same team than as a federal civilian.
             | 
             | Regarding pay, it's actually pretty bad. A typical IT
             | worker will be a GS-11 to GS-13 depending on location and
             | degree (possibly lower in some locations, maybe higher in
             | some high COL areas). GS-13 in many places is restricted to
             | management and SMEs, though they're bumping up a lot of the
             | "working level" grades because they realize they can't
             | compete in hiring.
             | 
             | To pick a high COL area where you might find GS-13 working
             | level IT folks, San Diego GS-13's max out at $153k. If
             | they're actually _GS_ and not another pay system (has a
             | different pay raise method but usually maps to some GS
             | grades, like Acqdemo) then it takes 18 years to go from
             | GS-13 Step 1 to GS-13 Step 10. Most likely they aren 't
             | starting at Step 1 in any grade, let's say they start at
             | Step 4, then it's 12 years to max. Once maxed, they only
             | get the general pay increase every year. There are few
             | technical GS-14 positions (this is changing, but not
             | rapidly) even in high COL areas so the only "promotion"
             | option for many is to go from a GS-13 technical role to a
             | GS-13 management role (same pay) and then leverage that
             | into a GS-14 management or technical role, if someone dies
             | and a position opens up. GS-15 technical roles are pretty
             | rare.
        
           | segasaturn wrote:
           | The military? Yes. They get more money than they know what to
           | do with - I heard a story about how there's a base where all
           | they do is build M1 Abrams tanks on an assembly line, then
           | disassemble the tanks, and re-assemble, and then disassemble,
           | Ad Infinium, in order to spend all the money they're
           | allocated. It's always a political winner for Congress to
           | give more money to the military, so their budget has become
           | astronomical and only continues to grow.
           | 
           | Every other agency and branch of the US government?
           | Absolutely not.
        
             | jlund-molfese wrote:
             | Do you have any source for the claim that there is a
             | factory with the sole purpose of assembling and
             | disassembling M1 Abrams tanks without actually delivering
             | or upgrading any of them?
             | 
             | That sounds very implausible, bordering on conspiracy
             | theory.
        
             | kube-system wrote:
             | I'm not sure about that particular story, but many similar
             | stories are rooted in a very real issue of maintaining
             | domestic supply chain expertise.
             | 
             | While centrally managed economies can just mandate that
             | state-owned factories continue to exist, private markets
             | won't do this. If you don't order tanks and missiles, the
             | factories that make tanks and missiles will cease to exist,
             | and the market will reallocate resources elsewhere.
        
             | groby_b wrote:
             | Look, I heard a lot of things from the guy at the street
             | corner too, but that doesn't make it true.
             | 
             | We'll start with the fact that M1s aren't built on a
             | "base", they're built at the Joint Systems Manufacturing
             | Center in Lima. Government owned, contractor (GDLS) run,
             | not a base.
             | 
             | What they _do_ do is refurbish older tanks, which one I
             | suppose could distort into  "disassembling", if one wanted
             | to make a rather distorted claim.
             | 
             | The waste contention for that base comes from an Army
             | proposal to temporarily shut down the factory in 2013,
             | which was supposed to save ~$1B. GDLS explained that, sure,
             | can do, but spinning up production again is going to cost
             | ~$1.5B, and restarting production in 2017/18 was always
             | planned. It's not as simple as "the politicians always
             | allocate money to the military".
        
           | nitwit005 wrote:
           | When political candidates vow to "trim the fat" of the US
           | government, the military is typically off limits, but the
           | other government departments certainly aren't.
        
           | Denvercoder9 wrote:
           | You'd have to look at purchase power, not dollars, to see how
           | much they can actually do with all that spending. You get a
           | lot further with $5 in a place where wages are $1, than with
           | $20 in a place where wages are $15.
        
           | acdha wrote:
           | You can only spend money on what your budget specifically
           | allows. If you're in the military, the fact that you are
           | authorized to procure $1B aircraft doesn't mean you can hire
           | a $200k IT security engineer to protect your HR system and
           | you can go to jail if you try to pay for an application
           | upgrade out of that budget unless it's directly linked to
           | that program.
           | 
           | If you're not in the military, the fact that someone else has
           | a big budget doesn't help you any more than your neighbor
           | having a Mercedes helps pay your internet bill.
           | 
           | There are general budgets and people build in support costs,
           | of course, but it's terribly easy to find people who have
           | been asking for budget to replace something years before its
           | end of life but keep getting turned down in the congressional
           | budgeting process. Politicians want to fund things their
           | constituents like, but the unloved internal support app is
           | just as much of a risk to have on your network.
        
         | treflop wrote:
         | Private companies get breached often too (see AT&T).
         | 
         | Pretty much everyone gets breached.
         | 
         | The only ones I don't think get breached deep are the really
         | big software engineering companies where most of the company
         | are also software engineers... like Google.
         | 
         | Software is too complex to be secure without a massive team
         | IMO.
        
           | lazide wrote:
           | Eh, a massive team makes its own major issues. See the many
           | Google leaks over the years.
           | 
           | Assuming software can be secure (and hence not doing proper
           | defense in depth, limiting the types and nature of
           | information processed, etc). is the bigger issue IMO.
        
           | tjohns wrote:
           | > Software is too complex to be secure without a massive team
           | IMO.
           | 
           | We could do better as an industry though. Modern operating
           | system design makes it far too easy to shoot yourself in the
           | foot.
           | 
           | Imagine a world where all we all use memory-safe/null-
           | safe/type-safe languages, applications and data are strictly
           | sandboxed, access to data is only granted using capabilities-
           | based security, application-level security patches are
           | automatically applied by the OS, data was always encrypted
           | while at rest and while in transit, and passwords are
           | completely replaced with passkeys / smartcards (for users)
           | and X.509 certificates (for servers). While this isn't a
           | panacea, it would solve a great number of the most common
           | security vulnerabilities.
           | 
           | Each of these pieces exist individually. There's no reason
           | why we can't have all of these things today, other than
           | support for legacy applications and retraining engineers.
           | However, it's nearly impossible to get away from legacy
           | software needs.
           | 
           | But if you want low hanging fruit... stop writing C/C++, and
           | get rid of passwords. These are the biggest flaws in the
           | stack.
        
             | infamouscow wrote:
             | There is no incentive for the industry to do better. As for
             | government penalties being an incentive:
             | 
             | If it was popular amongst the voters to hold corporations
             | seriously responsible, you would see politicians campaign
             | on it and win. It's not nearly as popular as _virtually
             | anything else_ based on empirical data.
             | 
             | Another way to say this is if 80% of all voters, regardless
             | of party prioritized this as the #1, #2, and #3 issue,
             | politicians would pass laws. It makes the politician look
             | good and solidifies their reelection. Likewise, politicians
             | that vote against those laws would almost certainly not be
             | reelected.
        
       | breck wrote:
       | I loved security training at Microsoft.
       | 
       | I remember one time Satya said the red teams reported to him
       | which Microsoft services they were currently in. He would then
       | ask the heads of those services if they had detected any
       | breaches. Sometimes there would be services that had been
       | breached for years, undetected. Must have been hard for Satya to
       | keep a straight face.
       | 
       | One phrase that struck with me from their security training:
       | "Assume Breach".
        
         | selimthegrim wrote:
         | This sounds like China Mieville.
        
         | Thorrez wrote:
         | The red team would beach them then wait years before telling
         | them?
         | 
         | The goal the the red team should be to increase security.
         | Waiting years before telling them means there's a years-long
         | delay before security can be improved. That goes against the
         | goal.
        
         | Aaronstotle wrote:
         | Maybe they should have warned them after some time, because
         | Microsoft has gotten breached a few times in the last few
         | years.
        
         | renewiltord wrote:
         | > Be me: security researcher on Death Star
         | 
         | > hired to find flaws in space station
         | 
         | > find that exhaust port has flaw
         | 
         | > single blast to it would lead to reactor
         | 
         | > would blow whole station
         | 
         | > tell my boss
         | 
         | > he asks engineers if there's flaw
         | 
         | > they say no
         | 
         | > he snickers behind their back
         | 
         | > "we know better, don't we anon?"
         | 
         | > doesn't tell engineers
         | 
         | > mfw blown up by Luke Skywalker
        
       | asynchronous wrote:
       | I really really want to root for CISA, but just a few months ago
       | they leaked a trove of critical infrastructure documents that
       | they had collected from partners, that if they hadn't collected
       | wouldn't be in the wrong hands currently.
        
       | academia_hack wrote:
       | Until the US federal government pays civilian tech talent
       | competitively, this is always going to be an issue.
       | 
       | Your typical hands-on-keyboard blue team engineer in federal
       | government is a GS-12 getting paid around $68,000 per year (or
       | $99k in very high cost of living areas like DC). They have
       | expensive health benefits, 13 days of PTO a year, put a huge
       | chunk of their paycheck (almost 5%) into a mandatory pension plan
       | that consistently underperforms the market, and can literally go
       | to jail for making mistakes at work depending on the statutory
       | context they work in.
       | 
       | The best people in these jobs burn out fast and quit or they end
       | up having to abandon IC work for GS-14/15 jobs (max pay is around
       | $190 for those) in order to keep up with cost-of-living and
       | justify their careers.
       | 
       | As a result, you have almost zero genuinely capable
       | principal/senior engineers in government who have the authority
       | to architect complex IT systems for security. Instead you get
       | contractors who charge the taxpayers enormous overhead costs and
       | cut corners wherever possible.
       | 
       | If there's one letter to write your congress person to improve
       | government - my vote would be for civil service reform to attract
       | and retain actual top tech talent. They've done it for doctors
       | and lawyers (both of whom can get paid well above the $190k GS
       | pay ceiling), but engineering is still not treated as a
       | comparably skilled professional trade.
        
         | 2OEH8eoCRo0 wrote:
         | Yes, because civilian tech companies are never hacked.
         | 
         | I do largely agree with your post but I'm also suspicious that
         | stratospheric civilian tech compensation is a bubble.
        
           | academia_hack wrote:
           | Totally. I think comp is a necessary but not sufficient
           | precondition for fixing government technology. The actual
           | solutions (good authentication and least privilege systems,
           | robust monitoring, rapid intrusion detection and response,
           | secure by default system architectures) all take talented
           | people to execute and the government doesn't have enough of
           | those in-house. Instead most systems are built with a
           | 7-figure contract to Booz Allen and friends and then
           | maintenance and sustainment is left as an exercise to the
           | reader.
        
           | ImPostingOnHN wrote:
           | I might take less total compensation in exchange for feeling
           | like I'm making my government better.
           | 
           | But I'd need to be paid more to suffer though any enormous
           | bureaucracy, so it tends to balance out to needing market
           | rates.
        
           | ch4s3 wrote:
           | Almost every job in government pays better in the private
           | sector and usually by a lot.
        
             | acdha wrote:
             | This is a common misperception but it's not that simple.
             | Here's an old study discussing how it varies based on the
             | field, where the lower level jobs do tend to pay better but
             | higher-skill jobs have the opposite trend:
             | 
             | https://www.cbo.gov/publication/52637
             | 
             | Since the Obama era, this has gotten worse because there
             | were a ton of people trying to score political points
             | saying they were cutting waste by freezing civil servants'
             | salaries and that really got ugly in tech jobs because
             | salaries were booming once things like the Silicon Valley
             | wage collusion lawsuit and high demand for security,
             | DevOps, etc. started raising the ceiling for the private
             | sector. In 2010 the top end of the GS scale was competitive
             | once you factored in benefits, hours, etc. but a decade
             | later that just wasn't the case. I knew multiple people who
             | were trying to stay in the public sector but it was
             | literally 2-3 times more money if they went private even
             | though their skills were considered mission critical for
             | their agencies.
             | 
             | This sabotages contract work, too, because there isn't
             | anyone qualified to guide or review the work and that tends
             | to burn orders of magnitude more money than simply paying
             | more directly would.
        
         | autoexecbat wrote:
         | Last time I was looking for a job I read about various
         | interesting government jobs, and then gave up when I finally
         | understood the pay structures.
        
           | treesknees wrote:
           | The pay will almost always be lower than equivalent private
           | sector tech positions. The difference is in benefits,
           | retirement and pension.
           | 
           | A nice balance might be working somewhere as a civilian
           | contractor for those government projects.
        
             | halJordan wrote:
             | With that attitude, the pay will always be lower. Letting
             | the dogma be self-reinforcing isnt the winning strat. The
             | difference isnt even benefits, retirement, and pension.
             | Maybe in the 80/90s or even 00s that was the case, but it's
             | a dead philosophy carried by dead justifications.
        
           | yimmothathird wrote:
           | I was fine for the pay structure on its own. I gave up when I
           | was rejected for not having the hyper specific domain
           | experience they wanted for the pay they were asking for. This
           | was primarily a CRUD job btw and I was qualified by any other
           | standard.
        
             | PyWoody wrote:
             | I tried so hard to get into gov't tech but ultimately gave
             | up. Jumping from the private sector to public seems
             | impossible to me as an outsider.
             | 
             | A friend of mine, who is a lawyer and does HR for the
             | federal gov't, spent about a week helping me get my fed
             | resume tightened up and I still got nothing. I don't even
             | care about the pay cut. It just seems like interesting
             | work.
        
         | shrimp_emoji wrote:
         | "Improve" government by scaling it back down to where it was
         | when pennies from tarrifs could pay for it instead of 25%
         | Federal income tax that already gives you mediocre results.
        
           | Vicinity9635 wrote:
           | But then who would pay for all of Israel's bombs? Think of
           | the foreign nation whose citizens are happier and healthier
           | than you with single payer healthcare?
        
         | booi wrote:
         | I call BS. I've never heard of anybody in government "going to
         | jail" for some sort of mistake. Sure, there's all kinds of
         | threats and regulatory control but when it comes down to it
         | barely anybody is held to any kind of responsibility. It's
         | practically impossible to fire someone in the government for
         | incompetence and that's coming from engineers I know in
         | government who work with essentially weaponized incompetence.
        
           | SkyPuncher wrote:
           | Well you clearly haven't put any effort into finding
           | examples.
           | 
           | https://www.justice.gov/usao-dc/pr/former-federal-
           | government...
           | 
           | Yes, he shouldn't have accepted bribes, but in the private
           | sector this would have been extremely unlikely to result in
           | jail time.
           | 
           | Even if jail time isn't a common thing, it's far closer to
           | happening to the average person working in the government
           | than it is to those working in the private sector. The
           | private sector simply fires bad employees. The government
           | seeks to be made whole.
        
             | saalweachter wrote:
             | I'm not really impressed by someone going to jail for
             | accepting bribes, even if it's less likely to happen in the
             | private sector.
             | 
             | Show me someone going to jail for bringing down prod or
             | making the wrong architecture call or choosing the wrong
             | platform/backend/language or even just getting burnt out
             | and spending a week on the clock re-watching all of Star
             | Trek: Voyager. I want to go, "Holy shit, that could have
             | been me!", not "Well no shit he went to jail."
        
             | Scaevolus wrote:
             | When you write "making mistakes at work", readers imagine
             | mistakes like "breaking prod", not "mistakes" like taking
             | bribes.
        
         | ForHackernews wrote:
         | I'm not sure more money => more talent in quite the direct
         | relationship you're suggesting here. If this were true, the
         | cryptocurrency industry would be the most secure in the world,
         | since they pay their engineers the most.
        
       | mrpippy wrote:
       | The exploited vulnerability (CVE-2022-21587) is some Oracle
       | E-Business web thing, nothing Solaris-specific like it sounded
       | from the article.
        
       | clwg wrote:
       | I'm not a huge fan of how red teaming is generally conducted.
       | It's sometimes necessary, but the CISA report seems to indicate
       | that the organization wasn't responding to their requests the way
       | they wanted, leading to a communication breakdown right from the
       | start. The vulnerability was patched and the red team's initial
       | compromise was contained, so they targeted them with phishing,
       | owned their domain controllers, then maintained access for months
       | while pivoting to partner organizations, then published a public
       | report.
       | 
       | It's hard to establish constructive dialogue after that, allot of
       | bad feelings and burnt bridges - and sometimes HR. It's tough
       | because there's generally allot of dynamics at play, but I'm sure
       | the impact of this testing was felt by people within the targeted
       | org.
        
         | Jtsummers wrote:
         | > The vulnerability was patched and the red team's initial
         | compromise was contained, so they targeted them with phishing,
         | owned their domain controllers, then maintained access for
         | months while pivoting to partner organizations, then published
         | a public report.
         | 
         | You're missing a few steps between the pivot to partner
         | organizations and the report. The public report was made on 11
         | July 2024. They revealed the breach to the target last year,
         | June 2023, and then began a collaboration effort at that point,
         | running through September 2023. They also don't name and shame
         | in this public report, we don't know what the target
         | organization was.
        
           | clwg wrote:
           | My next sentence is really a comment on that step.
           | 
           | I generally find that working incrementally alongside the
           | teams provides better outcomes. This is not to say you can't
           | use black-box testing or perform unscoped testing, but
           | collaborating throughout the process gives you additional
           | visibility that can save a lot of time, especially in large-
           | scale and diverse environments. People generally respond in a
           | more positive and collaborative manner as well.
        
       | treflop wrote:
       | I don't see how this is that newsworthy.
       | 
       | There are many federal agencies. One of them will fuck up.
       | 
       | Same with private companies.
       | 
       | If you have 100 people doing the same thing, at least one of them
       | is going to fuck it up.
        
       | cafard wrote:
       | Long ago I worked on a government contract at a civil agency,
       | which ran WordPerfect Office on DG minis. The main contractor won
       | a contract with another division in that agency, setting up a
       | slightly spiffier version. Somebody at the COTR's office at the
       | other division encouraged or perhaps dared us to break in. It
       | took about two hours. We let them know at once, but I think that
       | with a bit of discretion we could have maintained our presence
       | for a long time.
        
       ___________________________________________________________________
       (page generated 2024-07-12 23:00 UTC)