[HN Gopher] CISA broke into a US federal agency, and no one noti...
___________________________________________________________________
CISA broke into a US federal agency, and no one noticed for a full
5 months
Author : rntn
Score : 110 points
Date : 2024-07-12 18:19 UTC (4 hours ago)
(HTM) web link (www.theregister.com)
(TXT) w3m dump (www.theregister.com)
| sybercecurity wrote:
| The only reason they noticed is because they were told, so it
| really it should have been "..and no one noticed."
| jmclnx wrote:
| Nice they are doing their job and glad they exist.
|
| But how to fix ? Most US Gov agencies are underfunded, it is
| either beef up security or provide services. Really a tough
| choice, and the outlook looks like they may lose even more
| funding.
| akira2501 wrote:
| Lesson learned: The assessed organization had insufficient
| controls to prevent and detect malicious activity.
|
| Lesson learned: The organization did not effectively or
| efficiently collect, retain, and analyze logs.
|
| Lesson learned: Bureaucratic processes and decentralized teams
| hindered the organization's network defenders.
|
| Lesson learned: A "known-bad" detection approach hampered
| detection of alternate TTPs.
|
| https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
| doe_eyes wrote:
| The problem with such "lessons learned" is that they are
| usually not lessons learned - I bet there were numerous
| people within the organization who knew about these issues
| before the test.
|
| The actual issue is probably that these people are (a)
| ineffectual at communicating and prioritizing concerns
| clearly; or (b) good at communicating, but are not being
| listened to; or (c) they are listened to, but the
| organization has no practical means to fix this - no money,
| unable to recruit talent, etc.
|
| Most techies often assume (b), but (a) is at least as common.
| The last issue - (c) - might be superficially true, although
| it's usually not correct in a deeper sense: there is plenty
| of discretionary and wasteful spending in any sufficiently
| large bureaucracy. Central resource allocation is just a hard
| problem.
|
| Anyway, my point is that the problems that need fixing are
| almost never just technical. Recommendations such as
| "implement sufficient controls to detect malicious activity"
| seldom get to the root cause. They are still useful in
| temporarily overcoming organizational obstacles, but it
| usually doesn't last.
| Rinzler89 wrote:
| _> Most US Gov agencies are underfunded_
|
| Doesn't the US outspend in terms of dollars almost every single
| developed country on the planet at absolutely everything, even
| in per capita statistics, from military, police to education
| and healthcare? How could it be underfunded?
| lazide wrote:
| The first thing you learn in government is that _you're_
| always underfunded.
|
| If you aren't, your budget will go to someone who is.
| throwway120385 wrote:
| The US is really really big. People way underestimate how
| huge it is in terms of land area. You could fit Europe inside
| the US. So the reason Germany or France underspend the US has
| more to do with the area they have to cover and the number of
| people they have in their borders.
| dmix wrote:
| > even in per capita statistics
| tossandthrow wrote:
| The argument is density. Things tend to be cheaper per
| capita, when density is high.
|
| I don't buy it thought. I think the reason why the spend
| is less in Europe is due to higher salary equality - good
| people take job in government because the salary is
| _only_ 50% higher in private sector (for tech, even less
| for other areas).
| vidarh wrote:
| There are only a couple of US states less dense than e.g.
| Norway, and even in those states the vast majority of the
| population live in small, higher density areas.
|
| The areas where the vast majority of Americans actually
| live are fairly high density.
|
| _Some_ cost might come down to density, but not much.
| tossandthrow wrote:
| Agreed, only trying to make the comment justice - not
| agreeing.
|
| Arguable, Denmark has a super low density also if you
| count in Greenland.
|
| As also written, I don't buy that argument. I think the
| core is inequality.
| coldtea wrote:
| > _You could fit Europe inside the US._
|
| If we're considering contiguous US, then no.
|
| Europe is 3.93 million square miles.
|
| Contiguous US is 3.15 million square miles.
| saalweachter wrote:
| I'm guessing the poster was thinking of "Europe" as more
| like "the EU" or "Europe minus Russia"; 1.1 million of
| Russia's 6.6 million square miles are part of Europe's
| 3.93; take it away, and "Europe" drops to more like 2.8
| million square miles, a smidge less than the contiguous
| US.
| Jtsummers wrote:
| In total the US executive is very well funded, but individual
| agencies aren't always well-funded and often lack the
| specific skillset to properly utilize funding even if they
| have it, especially wrt IT systems when that's outside their
| main field of expertise.
| dmix wrote:
| Yes the should try having less of them. There's 438 total,
| it'd probably take CISA years to red team all of them.
| oneplane wrote:
| So your solution to a problem that exists because there
| isn't enough capacity to go around is to compound that
| problem by having even less capacity?
| nradov wrote:
| The federal government does too much. We could simply
| eliminate many of those agencies and save money for
| taxpayers, or redirect those resources to more important
| functions. There is excess capacity, it's just in the
| wrong places.
|
| As for IT functions, all of that should be centralized
| under the GSA with proper security controls. There's no
| benefit to having every agency maintain its own IT
| infrastructure. Most of those staff are redundant and
| could be laid off.
| notaustinpowers wrote:
| I worry for having a centralized IT infrastructure as
| that now puts every single agency at risk from a single
| attack. No one would call a neighborhood "secure" if
| every home used the same key.
| acdha wrote:
| > As for IT functions, all of that should be centralized
| under the GSA with proper security controls. There's no
| benefit to having every agency maintain its own IT
| infrastructure. Most of those staff are redundant and
| could be laid off.
|
| This works for email. Would you work at a company where
| you had to build and deploy apps on infrastructure
| controlled by someone in a different department and
| location, whose boss gave them the mandate to standardize
| as much as possible to reduce costs? (Hope you like
| Oracle...)
| Uvix wrote:
| That was your fairly typical on-premise corporate
| hosting. Things have gotten _better_ with the cloud but
| it 's still hardly a free-for-all, use-whatever-you-want-
| with-no-oversight situation.
| acdha wrote:
| Cloud environments helped, but the kind of massively
| centralized environment they're talking about in the
| cloud work still tends to mean "get 4 levels of approvals
| and you can get a t3.medium using our AMI with Java 6".
| My point is just that successful IT needs people who
| understand the mission and share your incentives - you
| can outsource email and other generic services but most
| people here work on things which aren't one-size fits
| all.
| LamaOfRuin wrote:
| Everyone agrees the government does too much of some
| stuff and not enough of other stuff. No one agrees on
| what belongs in which category.
| fleabagmange wrote:
| Omar a minimum we need to deduplicate insane degrees of
| replication. Why does virtually every government agency
| have dedicated law enforcement? Narrow it down,
| reallocate budget, eliminate the wasteful overhead.
|
| It's not all or nothing here. We spend too much and get
| too little out of it.
| redserk wrote:
| Law enforcement is incredibly difficult, especially with
| the number and types of laws on the books. You want
| multiple different law enforcement agencies so they can
| specialize based on the field of law they are in.
|
| Currency counterfeiting is a different set of laws than
| interstate financial fraud, which is a different set of
| laws than throwing a Snickers wrapper on the ground in
| Yosemite.
| coldtea wrote:
| > _Currency counterfeiting is a different set of laws
| than interstate financial fraud_
|
| Which is somewhat irrevant. Teams dealing with each can
| still share headquarters, IT resources, support stuff,
| cafeterias, and lots of other things.
| mrguyorama wrote:
| The US government is broadly disallowed, for political
| reasons, from doing anything. So they have to buy services on
| the open market, where they get charged through the nose.
|
| Our state legislature recently voted down adding a new Data
| Analyst position to one of their departments. That department
| cannot function without that position, so instead it has to
| use it's funding to buy that same position from a 3rd party
| contractor for 3x the price or more.
|
| The result is that we pay more than anyone else for basically
| everything we do.
| iisan7 wrote:
| I generally agree that the government often hamstrings
| itself. But consider also that you can't terminate state
| employees easily, and their benefits packages often cost
| more than 100% of their salary. The salary itself and the
| working conditions often don't attract the best talent.
| Thus it's not always so cut and dry in terms of what's the
| best outcome for the public interest.
| Jtsummers wrote:
| It's getting centralized anyways, just not inside any
| federal agency. Instead they're outsourcing it to
| companies like MS and Google who provide hosted services.
| This gives the agency cover so long as they do their part
| (like making use of MFA, using encryption on email). Then
| they can offer a claim of making their best-effort and
| going with industry "standards" (standard as in common,
| not as in ISO, ANSI, or others).
| ndriscoll wrote:
| My understanding is that regardless of funding, the US
| federal government has standardized pay scales that top out
| way below what private industry pays, so even well funded
| agencies can only possibly get junior developers/IT or people
| that are willing to take a significant (50-80%) pay
| reduction. The very most you can possibly make as a GS15 in
| 2024 is 191,900, and they have locality-adjusted pay with
| most localities being below that.
|
| They might also generally still drug test? I don't even do
| drugs, but I'm not going to pee in a cup for someone to
| effectively do charity lol. Good luck recruiting a
| professional with decades of engineering experience when you
| treat them like they're a 16 year old working at Taco Bell.
| Even someone with 0 years doesn't have to deal with that kind
| of treatment in industry.
| SanderNL wrote:
| Charity? I sympathize somewhat, but I'm also disgusted by
| the utter lack of respect for government and societal
| service in general. That shit means something.
|
| I wish to believe there are still people that don't care
| about making Yet Another few hundred thousand and just want
| to actually contribute to society instead of working on ad
| tech or whatever bullshit.
| arcimpulse wrote:
| Regardless of whether or not one personally enjoys the
| work one is doing, if one really is contributing to
| society, one should get fairly compensated for it.
|
| Additional requirements not common in the private sector,
| such as rigorous drug testing, ethics codes, requirements
| on gift reporting, increased surveillance, etc., should
| come with additional benefits to compensate. Instead,
| government workers submit to these requirements _and_ a
| substantial pay cut.
|
| That's mostly because conservatives 1) desire tax cuts at
| any cost and 2) want to demolish the entire
| administrative state. The stability and consistency that
| comes with a well-funded civil servant class are an
| obstruction to their stated goals.
| jholman wrote:
| I vouched your comment, because I think you're precisely
| making the relevant point in the first two paragraphs.
|
| However, I think you're wrong, at least in part, in your
| third paragraph. I mean, I think the word "mostly" is
| wrong in that paragraph. Politicians from all political
| factions are (quite reasonably) under pressure to lower
| the cost of doing the work of government, and (quite
| reasonably) to raise the integrity of the process.
| Combined with some of the dysfunction inherent in agent-
| principal problems, I think that's more than enough to
| cause the problem you're talking about. I experience this
| firsthand in a jurisdiction that has much less of the
| "demolish the entire administrative state" that afflicts
| the American right wing (which I'm guessing is your point
| of reference).
|
| Mind you, I am _not_ claiming that the problem is not
| _badly worsened_ by American right-wing politics. I
| wouldn 't know. I'm just claiming that the problem is
| semi-intrinsic to the situation, and I strongly doubt
| that it's "mostly" caused by those particular political
| issues.
| tossandthrow wrote:
| The issue is that the housing price is set by the people
| that _do_ care about making Yet Another few hundred
| thousand.
|
| Equality is good for equality sake. This is a lesson
| contemporary North Americans seem to have forgotten in
| record time.
| jholman wrote:
| I'm confused. You're complaining about the use of the
| word "charity"?
|
| Background: You make an argument that at least some
| people should consider putting contributions to society
| ahead of "making yet another few hundred thousand". I
| agree with you, at least broadly, and I think the up-
| thread poster is not disagreeing.
|
| Summary: We're discussing the act of taking a personal
| financial hit, for the good of society.
|
| The word for that is "charity". That's what that word
| means.
|
| ---------
|
| I also am sympathetic to the GP's point, about which you
| are so "disgusted", but I think there's room to disagree
| there.
|
| I am sympathetic because professionally I do work that
| many people think is "good for society", I currently earn
| approximately median income (below mean) for my
| age/gender/nationality, far far below software engineer
| pay, and I am treated with unbelievable disrespect by my
| employer, the government. If I was not trapped in this
| job by personal circumstance (for now), the disrespect
| part would definitely factor into my decision making
| about staying in this allegedly-virtuous job. If you're
| gonna pay people below market, and you treat them badly,
| that's not a combination that gets you quality employees.
| Even if there's some social purpose.
| coldtea wrote:
| > _Summary: We 're discussing the act of taking a
| personal financial hit, for the good of society.
|
| The word for that is "charity". That's what that word
| means._
|
| Calling it "charity" impies it's done out of
| pity/compassion.
|
| The parent implies it should be seen as a duty /
| contribution to the country instead.
| Jtsummers wrote:
| Drug testing is mostly limited (for civilians) to those
| with access to sensitive, secret, or TS information. In
| those orgs, you have higher odds of being drug tested as a
| contractor in the same team than as a federal civilian.
|
| Regarding pay, it's actually pretty bad. A typical IT
| worker will be a GS-11 to GS-13 depending on location and
| degree (possibly lower in some locations, maybe higher in
| some high COL areas). GS-13 in many places is restricted to
| management and SMEs, though they're bumping up a lot of the
| "working level" grades because they realize they can't
| compete in hiring.
|
| To pick a high COL area where you might find GS-13 working
| level IT folks, San Diego GS-13's max out at $153k. If
| they're actually _GS_ and not another pay system (has a
| different pay raise method but usually maps to some GS
| grades, like Acqdemo) then it takes 18 years to go from
| GS-13 Step 1 to GS-13 Step 10. Most likely they aren 't
| starting at Step 1 in any grade, let's say they start at
| Step 4, then it's 12 years to max. Once maxed, they only
| get the general pay increase every year. There are few
| technical GS-14 positions (this is changing, but not
| rapidly) even in high COL areas so the only "promotion"
| option for many is to go from a GS-13 technical role to a
| GS-13 management role (same pay) and then leverage that
| into a GS-14 management or technical role, if someone dies
| and a position opens up. GS-15 technical roles are pretty
| rare.
| segasaturn wrote:
| The military? Yes. They get more money than they know what to
| do with - I heard a story about how there's a base where all
| they do is build M1 Abrams tanks on an assembly line, then
| disassemble the tanks, and re-assemble, and then disassemble,
| Ad Infinium, in order to spend all the money they're
| allocated. It's always a political winner for Congress to
| give more money to the military, so their budget has become
| astronomical and only continues to grow.
|
| Every other agency and branch of the US government?
| Absolutely not.
| jlund-molfese wrote:
| Do you have any source for the claim that there is a
| factory with the sole purpose of assembling and
| disassembling M1 Abrams tanks without actually delivering
| or upgrading any of them?
|
| That sounds very implausible, bordering on conspiracy
| theory.
| kube-system wrote:
| I'm not sure about that particular story, but many similar
| stories are rooted in a very real issue of maintaining
| domestic supply chain expertise.
|
| While centrally managed economies can just mandate that
| state-owned factories continue to exist, private markets
| won't do this. If you don't order tanks and missiles, the
| factories that make tanks and missiles will cease to exist,
| and the market will reallocate resources elsewhere.
| groby_b wrote:
| Look, I heard a lot of things from the guy at the street
| corner too, but that doesn't make it true.
|
| We'll start with the fact that M1s aren't built on a
| "base", they're built at the Joint Systems Manufacturing
| Center in Lima. Government owned, contractor (GDLS) run,
| not a base.
|
| What they _do_ do is refurbish older tanks, which one I
| suppose could distort into "disassembling", if one wanted
| to make a rather distorted claim.
|
| The waste contention for that base comes from an Army
| proposal to temporarily shut down the factory in 2013,
| which was supposed to save ~$1B. GDLS explained that, sure,
| can do, but spinning up production again is going to cost
| ~$1.5B, and restarting production in 2017/18 was always
| planned. It's not as simple as "the politicians always
| allocate money to the military".
| nitwit005 wrote:
| When political candidates vow to "trim the fat" of the US
| government, the military is typically off limits, but the
| other government departments certainly aren't.
| Denvercoder9 wrote:
| You'd have to look at purchase power, not dollars, to see how
| much they can actually do with all that spending. You get a
| lot further with $5 in a place where wages are $1, than with
| $20 in a place where wages are $15.
| acdha wrote:
| You can only spend money on what your budget specifically
| allows. If you're in the military, the fact that you are
| authorized to procure $1B aircraft doesn't mean you can hire
| a $200k IT security engineer to protect your HR system and
| you can go to jail if you try to pay for an application
| upgrade out of that budget unless it's directly linked to
| that program.
|
| If you're not in the military, the fact that someone else has
| a big budget doesn't help you any more than your neighbor
| having a Mercedes helps pay your internet bill.
|
| There are general budgets and people build in support costs,
| of course, but it's terribly easy to find people who have
| been asking for budget to replace something years before its
| end of life but keep getting turned down in the congressional
| budgeting process. Politicians want to fund things their
| constituents like, but the unloved internal support app is
| just as much of a risk to have on your network.
| treflop wrote:
| Private companies get breached often too (see AT&T).
|
| Pretty much everyone gets breached.
|
| The only ones I don't think get breached deep are the really
| big software engineering companies where most of the company
| are also software engineers... like Google.
|
| Software is too complex to be secure without a massive team
| IMO.
| lazide wrote:
| Eh, a massive team makes its own major issues. See the many
| Google leaks over the years.
|
| Assuming software can be secure (and hence not doing proper
| defense in depth, limiting the types and nature of
| information processed, etc). is the bigger issue IMO.
| tjohns wrote:
| > Software is too complex to be secure without a massive team
| IMO.
|
| We could do better as an industry though. Modern operating
| system design makes it far too easy to shoot yourself in the
| foot.
|
| Imagine a world where all we all use memory-safe/null-
| safe/type-safe languages, applications and data are strictly
| sandboxed, access to data is only granted using capabilities-
| based security, application-level security patches are
| automatically applied by the OS, data was always encrypted
| while at rest and while in transit, and passwords are
| completely replaced with passkeys / smartcards (for users)
| and X.509 certificates (for servers). While this isn't a
| panacea, it would solve a great number of the most common
| security vulnerabilities.
|
| Each of these pieces exist individually. There's no reason
| why we can't have all of these things today, other than
| support for legacy applications and retraining engineers.
| However, it's nearly impossible to get away from legacy
| software needs.
|
| But if you want low hanging fruit... stop writing C/C++, and
| get rid of passwords. These are the biggest flaws in the
| stack.
| infamouscow wrote:
| There is no incentive for the industry to do better. As for
| government penalties being an incentive:
|
| If it was popular amongst the voters to hold corporations
| seriously responsible, you would see politicians campaign
| on it and win. It's not nearly as popular as _virtually
| anything else_ based on empirical data.
|
| Another way to say this is if 80% of all voters, regardless
| of party prioritized this as the #1, #2, and #3 issue,
| politicians would pass laws. It makes the politician look
| good and solidifies their reelection. Likewise, politicians
| that vote against those laws would almost certainly not be
| reelected.
| breck wrote:
| I loved security training at Microsoft.
|
| I remember one time Satya said the red teams reported to him
| which Microsoft services they were currently in. He would then
| ask the heads of those services if they had detected any
| breaches. Sometimes there would be services that had been
| breached for years, undetected. Must have been hard for Satya to
| keep a straight face.
|
| One phrase that struck with me from their security training:
| "Assume Breach".
| selimthegrim wrote:
| This sounds like China Mieville.
| Thorrez wrote:
| The red team would beach them then wait years before telling
| them?
|
| The goal the the red team should be to increase security.
| Waiting years before telling them means there's a years-long
| delay before security can be improved. That goes against the
| goal.
| Aaronstotle wrote:
| Maybe they should have warned them after some time, because
| Microsoft has gotten breached a few times in the last few
| years.
| renewiltord wrote:
| > Be me: security researcher on Death Star
|
| > hired to find flaws in space station
|
| > find that exhaust port has flaw
|
| > single blast to it would lead to reactor
|
| > would blow whole station
|
| > tell my boss
|
| > he asks engineers if there's flaw
|
| > they say no
|
| > he snickers behind their back
|
| > "we know better, don't we anon?"
|
| > doesn't tell engineers
|
| > mfw blown up by Luke Skywalker
| asynchronous wrote:
| I really really want to root for CISA, but just a few months ago
| they leaked a trove of critical infrastructure documents that
| they had collected from partners, that if they hadn't collected
| wouldn't be in the wrong hands currently.
| academia_hack wrote:
| Until the US federal government pays civilian tech talent
| competitively, this is always going to be an issue.
|
| Your typical hands-on-keyboard blue team engineer in federal
| government is a GS-12 getting paid around $68,000 per year (or
| $99k in very high cost of living areas like DC). They have
| expensive health benefits, 13 days of PTO a year, put a huge
| chunk of their paycheck (almost 5%) into a mandatory pension plan
| that consistently underperforms the market, and can literally go
| to jail for making mistakes at work depending on the statutory
| context they work in.
|
| The best people in these jobs burn out fast and quit or they end
| up having to abandon IC work for GS-14/15 jobs (max pay is around
| $190 for those) in order to keep up with cost-of-living and
| justify their careers.
|
| As a result, you have almost zero genuinely capable
| principal/senior engineers in government who have the authority
| to architect complex IT systems for security. Instead you get
| contractors who charge the taxpayers enormous overhead costs and
| cut corners wherever possible.
|
| If there's one letter to write your congress person to improve
| government - my vote would be for civil service reform to attract
| and retain actual top tech talent. They've done it for doctors
| and lawyers (both of whom can get paid well above the $190k GS
| pay ceiling), but engineering is still not treated as a
| comparably skilled professional trade.
| 2OEH8eoCRo0 wrote:
| Yes, because civilian tech companies are never hacked.
|
| I do largely agree with your post but I'm also suspicious that
| stratospheric civilian tech compensation is a bubble.
| academia_hack wrote:
| Totally. I think comp is a necessary but not sufficient
| precondition for fixing government technology. The actual
| solutions (good authentication and least privilege systems,
| robust monitoring, rapid intrusion detection and response,
| secure by default system architectures) all take talented
| people to execute and the government doesn't have enough of
| those in-house. Instead most systems are built with a
| 7-figure contract to Booz Allen and friends and then
| maintenance and sustainment is left as an exercise to the
| reader.
| ImPostingOnHN wrote:
| I might take less total compensation in exchange for feeling
| like I'm making my government better.
|
| But I'd need to be paid more to suffer though any enormous
| bureaucracy, so it tends to balance out to needing market
| rates.
| ch4s3 wrote:
| Almost every job in government pays better in the private
| sector and usually by a lot.
| acdha wrote:
| This is a common misperception but it's not that simple.
| Here's an old study discussing how it varies based on the
| field, where the lower level jobs do tend to pay better but
| higher-skill jobs have the opposite trend:
|
| https://www.cbo.gov/publication/52637
|
| Since the Obama era, this has gotten worse because there
| were a ton of people trying to score political points
| saying they were cutting waste by freezing civil servants'
| salaries and that really got ugly in tech jobs because
| salaries were booming once things like the Silicon Valley
| wage collusion lawsuit and high demand for security,
| DevOps, etc. started raising the ceiling for the private
| sector. In 2010 the top end of the GS scale was competitive
| once you factored in benefits, hours, etc. but a decade
| later that just wasn't the case. I knew multiple people who
| were trying to stay in the public sector but it was
| literally 2-3 times more money if they went private even
| though their skills were considered mission critical for
| their agencies.
|
| This sabotages contract work, too, because there isn't
| anyone qualified to guide or review the work and that tends
| to burn orders of magnitude more money than simply paying
| more directly would.
| autoexecbat wrote:
| Last time I was looking for a job I read about various
| interesting government jobs, and then gave up when I finally
| understood the pay structures.
| treesknees wrote:
| The pay will almost always be lower than equivalent private
| sector tech positions. The difference is in benefits,
| retirement and pension.
|
| A nice balance might be working somewhere as a civilian
| contractor for those government projects.
| halJordan wrote:
| With that attitude, the pay will always be lower. Letting
| the dogma be self-reinforcing isnt the winning strat. The
| difference isnt even benefits, retirement, and pension.
| Maybe in the 80/90s or even 00s that was the case, but it's
| a dead philosophy carried by dead justifications.
| yimmothathird wrote:
| I was fine for the pay structure on its own. I gave up when I
| was rejected for not having the hyper specific domain
| experience they wanted for the pay they were asking for. This
| was primarily a CRUD job btw and I was qualified by any other
| standard.
| PyWoody wrote:
| I tried so hard to get into gov't tech but ultimately gave
| up. Jumping from the private sector to public seems
| impossible to me as an outsider.
|
| A friend of mine, who is a lawyer and does HR for the
| federal gov't, spent about a week helping me get my fed
| resume tightened up and I still got nothing. I don't even
| care about the pay cut. It just seems like interesting
| work.
| shrimp_emoji wrote:
| "Improve" government by scaling it back down to where it was
| when pennies from tarrifs could pay for it instead of 25%
| Federal income tax that already gives you mediocre results.
| Vicinity9635 wrote:
| But then who would pay for all of Israel's bombs? Think of
| the foreign nation whose citizens are happier and healthier
| than you with single payer healthcare?
| booi wrote:
| I call BS. I've never heard of anybody in government "going to
| jail" for some sort of mistake. Sure, there's all kinds of
| threats and regulatory control but when it comes down to it
| barely anybody is held to any kind of responsibility. It's
| practically impossible to fire someone in the government for
| incompetence and that's coming from engineers I know in
| government who work with essentially weaponized incompetence.
| SkyPuncher wrote:
| Well you clearly haven't put any effort into finding
| examples.
|
| https://www.justice.gov/usao-dc/pr/former-federal-
| government...
|
| Yes, he shouldn't have accepted bribes, but in the private
| sector this would have been extremely unlikely to result in
| jail time.
|
| Even if jail time isn't a common thing, it's far closer to
| happening to the average person working in the government
| than it is to those working in the private sector. The
| private sector simply fires bad employees. The government
| seeks to be made whole.
| saalweachter wrote:
| I'm not really impressed by someone going to jail for
| accepting bribes, even if it's less likely to happen in the
| private sector.
|
| Show me someone going to jail for bringing down prod or
| making the wrong architecture call or choosing the wrong
| platform/backend/language or even just getting burnt out
| and spending a week on the clock re-watching all of Star
| Trek: Voyager. I want to go, "Holy shit, that could have
| been me!", not "Well no shit he went to jail."
| Scaevolus wrote:
| When you write "making mistakes at work", readers imagine
| mistakes like "breaking prod", not "mistakes" like taking
| bribes.
| ForHackernews wrote:
| I'm not sure more money => more talent in quite the direct
| relationship you're suggesting here. If this were true, the
| cryptocurrency industry would be the most secure in the world,
| since they pay their engineers the most.
| mrpippy wrote:
| The exploited vulnerability (CVE-2022-21587) is some Oracle
| E-Business web thing, nothing Solaris-specific like it sounded
| from the article.
| clwg wrote:
| I'm not a huge fan of how red teaming is generally conducted.
| It's sometimes necessary, but the CISA report seems to indicate
| that the organization wasn't responding to their requests the way
| they wanted, leading to a communication breakdown right from the
| start. The vulnerability was patched and the red team's initial
| compromise was contained, so they targeted them with phishing,
| owned their domain controllers, then maintained access for months
| while pivoting to partner organizations, then published a public
| report.
|
| It's hard to establish constructive dialogue after that, allot of
| bad feelings and burnt bridges - and sometimes HR. It's tough
| because there's generally allot of dynamics at play, but I'm sure
| the impact of this testing was felt by people within the targeted
| org.
| Jtsummers wrote:
| > The vulnerability was patched and the red team's initial
| compromise was contained, so they targeted them with phishing,
| owned their domain controllers, then maintained access for
| months while pivoting to partner organizations, then published
| a public report.
|
| You're missing a few steps between the pivot to partner
| organizations and the report. The public report was made on 11
| July 2024. They revealed the breach to the target last year,
| June 2023, and then began a collaboration effort at that point,
| running through September 2023. They also don't name and shame
| in this public report, we don't know what the target
| organization was.
| clwg wrote:
| My next sentence is really a comment on that step.
|
| I generally find that working incrementally alongside the
| teams provides better outcomes. This is not to say you can't
| use black-box testing or perform unscoped testing, but
| collaborating throughout the process gives you additional
| visibility that can save a lot of time, especially in large-
| scale and diverse environments. People generally respond in a
| more positive and collaborative manner as well.
| treflop wrote:
| I don't see how this is that newsworthy.
|
| There are many federal agencies. One of them will fuck up.
|
| Same with private companies.
|
| If you have 100 people doing the same thing, at least one of them
| is going to fuck it up.
| cafard wrote:
| Long ago I worked on a government contract at a civil agency,
| which ran WordPerfect Office on DG minis. The main contractor won
| a contract with another division in that agency, setting up a
| slightly spiffier version. Somebody at the COTR's office at the
| other division encouraged or perhaps dared us to break in. It
| took about two hours. We let them know at once, but I think that
| with a bit of discretion we could have maintained our presence
| for a long time.
___________________________________________________________________
(page generated 2024-07-12 23:00 UTC)