The U.S. Spent $2.2M on Security System That Wasn’t Implemented
propublica.org
propublica.org
I'm not surprised multiple vendors haven't adopted the system yet.
2.2 million on a research initiative and not immediately adopting it until it's proven and widespread seems perfectly reasonable to me.
The (abridged) title made it sound worse IMO.
Also, really, the TLDR should be just use TUF + in-toto already.
[1] https://www.datadoghq.com/blog/engineering/secure-publicatio...
“In security, you almost never go from making something possible to impossible,” Cappos told ProPublica, “You go from making it easy to making it hard...”
Whether or not his system would've done that is probably up for debate, but I love that quote!
> NYU academic gets some federal funding to make a supply chain security tool
> A supply chain breach occurs
> NYU academic says: If only the federal government had compelled all it's vendors to use my tool, this could have been avoided
It's just a rather substance-less piece of self promotion imo. I do a lot of work in supply chain security too. Perhaps if the federal government had hired me, none of this would have ever happened. Can I have a ProPublica article too? /s
You can see this happen at all levels of society. I'm sure most of us would have seen a pattern like this unfold at work. But the media especially loves it wrt public interest scandals, because they're such solid revenue generators for them.
Nice lead, you couldn't even get a Tetris clone installed for $2.2 Million.
Talk on in-toto -- https://www.usenix.org/conference/usenixsecurity19/presentat...
It would need explaining why it's not academia.