Australian security and the cult of mediocrity
claireconnelly.com.au
claireconnelly.com.au
And to blame it on "Programmers" or siloed universities is about the laziest piece of analysis I've read in anything (including Trump tweets) for ages.
There are real issues in IT generally is Aus, eg large orgs outsourcing all their dev work to large and small SI's, no in house capabilities for anything other than limited governance, a reluctance to take on and train grads and a million other things.
Security is definitely something that needs to change. In my experience IT security has often been seen as a infrastructure job rather than a holistic practice that covers the life cycle of systems, but the first time I worked with a security dev team was a government org, which was great. They were much less about the firewalls, and much more focussed on good security practices, the poor application of which by devs were often demonstrated at fortnightly showcases where they would demo exploits in real time. Especially awesome was the time they dropped the entire "user" database table with some magic Hibernate exploit.
Don't go lumping the U.S. in with the UK and Denmark, it's a completely different world.
This is spot on I think. I work for an Australian private enterprise-ish organisation almost all of our IT is outsourced. The contract gets renewed every few years and goes to basically whomever is cheapest bidder which means offshore Indian/Malaysian etc support.
As far as I can see cost is only consideration given to who gets the IT contract. And I'm pretty sure these outsourced workers are under pressures of their own the impression I've gotten from my limited dealings is they seem to be mostly focused on closing tickets - I'm guessing they have some kind of performance metric based on open tickets. Often if I report an issue ticket will get silently closed and I have to escalate several times before any action - This isn't really an environment that encourages "best practices" frustrating.
I can't for the life of me understand why large companies don't want their own in-house dev/infra capability. They do everything they can to give it to someone else and then pay companies like my employer $2k a day for me to sit here and write unit tests, ansible playbooks and no end of just bog standard dev jobs.
In my case I'm meant to be mostly doing architecture rather than dev, but what good is the architecture when the actual systems and applications are not looked after properly?
But besides, the upside is that you can just go work for these consultancies anyway. Look at CommBank - its agencies, contracts and subcontractors all the way down, but those agencies are still hiring those people locally here. I have like three friends who are all working for Qantas via three different agencies.
The Federal Government is a mixed bag. The larger agencies are required to comply with the Information Security Manual, which is a prescriptive set of controls from ASD. They mostly outsource infrastructure to a contractor and then either have in-source development or outsource it depending on the amount of development performed. For example, if they need to set up a new system as a once off, its probably outsourced. If its something that will continually be added to they will hire developers.
Government departments struggle to get skilled staff who will work for government wages and pass a security clearance. They also lack a lot of knowledge around IT at upper levels. Additionally, when they budget for systems they are terrible about asking for additional CAPEX to reduce on-going OPEX. They usually undercut their budget, half implement a system and then rely on manual processes. The efficiency dividend and on-going cuts then eat into their ability to perform those manual processes.
From what I've seen at least at my org it was a "Not our core business" type of problem. A lot of orgs got hit hard by the GFC. It's hard to explain if you didn't live through it but it was a bad time, really bad. For about 5 years between around 2008-2013 huge chunks of private sector was moribund. I am an engineer (the non software type). For a while mining jobs in WA / rural QLD were only jobs going. Construction, manufacturing etc on East Coast all just died almost over night (and still has not fully rebounded).
Basically anything not considered "core" got contracted out/sold off. IT, HR, Legal, Accounting etc. Huge swathes of redundancies. Jobs that have never come back.
I think all these problems are coming back to roost for various companies now which are cause of some of the symptoms alluded to in original article (though I can't really comment of public sector not familiar with it pretty sure many public service departments went through similar outsourcing though).
The issue is once these costs are contracted out and "off the books" takes a pretty brave CEO to bring it all back in house again.
They simply don't have the culture from the top down to manage those kind of people. When your entire middle management has no software experience they are too afraid to hire software developers. It takes guts and a lot of maturity to hire people with skills you don't understand.
Is this actually true? Maybe me and my friends have all been extremely fortunate, but none of us have ever had a trouble getting a job doing development and being paid well.
Sure, there's a smaller amount of cool, hip, early-stage startups to go work at compared to... New York, but still there are loads of people hiring if all the recruiter spam is anything to go by.
And SF/NYC is exactly what I'm comparing it to. I mean, I live in NYC now and don't have any real desire to move back.
Definitely interested in hearing about your experience though, what's the most interesting software stuff going on in Australia?
Now, I'm at an airline (well, at a digital agency who are at an airline) working on their new inflight wifi product. It's pretty interesting, talking to all sorts of APIs onboard the plane, super optimising the site so its still fast to run over a satellite connection.
Yeah, Sydney isn't San Francisco - that shouldn't be a surprise to anyone. Jobs still exists, but most of them are in stable companies. If you want that 'startup life', go move to SF.
Even outside of that, a lot of big important companies are starting to take security seriously here in Australia, which I think is a great thing :)
Even if it's food for thought in general, this is a pretty weak argument as applied to the Australian government - agile practices haven't made a lot of inroads there, particularly projects supplied by companies like IBM who tend to use super-rigid waterfall. If anything the recent failures prove that less-agile processes don't guarantee you anything in terms of security.
This is complete rubbish. Management's number one responsibility is to set standards and enforce them, no matter what industry you're in. If the programmers are churning out trash, it's management's responsibility to send it back and hold them to standard. If management accepts trash, then the final product will be trash. That's not the programmers' fault, that's management's fault.
And saying that Agile can't deliver secure products is like saying field commanders can't react to changing conditions on the field. Agile is specifically what allows organizations to produce secure software! Agile is precisely what allows management to take exploit reports, prioritize them, and quickly ship fixes, and not wait months on end for the next waterfall iteration to introduce a fix. Agile is precisely what allows organizations to introduce security policy professionals into regular planning meetings and give them a say over the direction and manner of development, so that organizations can take a more holistic approach to security, rather than introduce them at the end of the waterfall during integration, where fixing fundamental problems would result in costly delays and the result is an over-reliance on firewalls and segmentation.
Insecure software is not inevitable. Management needs to prioritize a) hiring competent security professionals b) budgeting enough money for salary so that they'll actually respond to head-hunters c) give them veto/enforcement rights to prevent shipping insecure product d) give them a seat at the table so that security issues can be fixed and security as a holistic corporate culture can be adopted over time.
Agile development has a lot to answer for. It's sadly been largely elevated to a religion which excludes innovation and thought about improvement.
Here is an archive link so you don't need to suffer it: http://archive.is/0ELqt