NATO Classified Cloud Platform Compromised
ddosecrets.substack.com
ddosecrets.substack.com
Now, just as I'm writing this I'm sure someome from Everis will chime in to say he gets paid handsomely and works for amazing projects.
But everyone I've known working for Everis wants to die.
And if such project had to land in Spain for political reasons, there are plenty of companies capable on taking such project with way better prospects.
I'm not convinced. I attended one of their recruitment events at university - lots of synergy going around. In fact I forgot about EY and a bunch of others too.
So this expresses what "modernization" is - fob as much work as possible unto a job-shop/meat-grinder operation and watch things like this happen. I don't even know whether to laugh or be appalled, the Snowden leaks happened due to contracted-out sys admins, after all.
How long before that's outsourced to Accenture too?
Edit: if only this was a joke.
I find this mind-boggling but that's how it is.
It's notoriously hard to fire public servants, or shut down underperforming departments.
It's comparatively easier to shut down an outsourced project, or switch suppliers.
(Alas, not easy enough; and the organizational skills required to win government bids are different from those required to actually deliver quality.)
The Apollo program was run by NASA, who had lots of government employees, but at the same time all the hardware and much of the software was built by contractors. The Apollo program was behind schedule and over budget for most of the project period.
NASA originally estimated the cost to somewhere between 7 and 12 billion USD; NASA Administrator increased this to 20 billion USD in 1961, but it ended up costing more than 25 billion USD in 1973 dollars.
In that case at least
a) There's no need to pay extra for the profit margins of the contractor companies (and the inevitable sub-contractors they use)
and
b) The incentives of the people doing the work are likely to be closer to the original project, in that the people doing the work are in the same organization as the project.
For me, outsourcing makes sense if the organization doesn't have enough of the specific type of work to have a fully staffed internal team, so specialist services, or if they are obliged to get an external opinion (e.g. auditing/pen testing). Otherwise you're just adding more layers of profit seeking middle-people...
I'm not so sure about incentives. The incentives aren't necessarily great in either situation. See also https://en.wikipedia.org/wiki/Public_choice
Have a look at eg the outsourced Danish firefighters. Seems to work just fine, but would be unthinkable in most countries, including the US. (Btw, Americans have more firefighters per capita than about anywhere else.)
"Shrink government" shouldnt be taken at face value.
It's relatively hard to get any work done at my job during the month of April, because about half the building is 85-88F (in a temperate mid-atlantic climate). That means that people will work in other cooler offices (problem when no one carries a cell phone) or just find reasons to leave early. I used to battle about this, but then I learned that it was for the unmovable ideal of economizing. Unfortunately, I'm a victim of economizing a 1970s building with huge plate glass windows that don't open.
Second example:office supplies. A supervisor asks me to have a room set up for a meeting. After determining that what I need is not kept on hand, I try to buy them through the government catalog as I'm supposed to. My internet connection fails, so I reboot my desktop (roughly 20-30 minutes). When it fails again, I lament that I probably have a dozen faster computers at home, ranging from 10 year old tablets to a raspberry pi, and with that I take the opportunity to step away from my office (low 80s in the summer, when this takes place, because the AC can't keep up.) I go down to my car where I can use my own air conditioning and my phone to look at the same website. The supplies aren't on the catalog, so I just order them for $10 on Amazon. Fast forward one week, when my supervisor asks how I have it ready so soon, and I get criticized for buying the supplies outside of the supply system with my own money. I place too high a value on my sanity, apparently.
Edit: I should mention that most people at this office are paid quite well relative to the area
I think there is some observational bias going on in this thread.
On the other hand the commander of the group I was doing work for pointed out that a fully trained Marine private was far to costly an asset to waste checking visitor ids.
But that's a good thing, right? It's good that everybody found out that the government unlawfully collected their data etc.
Snowden was not an attacker asking for money, he was an honest guy with a conscience and a whole lot of courage.
Abolishing the structures of domination/exploitation is the only way to have a good outcome, because it's the only way to ensure citizens will behave as decent neighbors, and not try to control and manipulate their peers. At least, that's what we anarchists believe and practice on a daily basis.
Agreed, but this is really bad news, given the amount of power three letter agencies (and the deep state in general) have.
> the good news is they're incompetent
Here I disagree. I think the NSA are about as competent as such an agency is ever likely to get. We shouldn't be happy that they still have weaknesses, rather we should be horrified at how few of them there are.
Most of the spying programs had been in place years before Snowden blew the whistle. Countless other contractors and deep state employees could have done what Snowden did had they had either the courage or the moral clarity. Quite possibly many tried and were stopped before leaking to the public.
How did the ANT catalog leaks do that? Did you not notice Russia suddenly got more aggressive (annexing Crimea etc.) after the Snowden incedent?
Your observation is, in general, quite correct! Back in the 80s or thereabouts, the conservative administrations started a MASSIVE shift towards outsourcing of federal government work. This was for all of the usual, largely shortsighted and inaccurate “cost saving” and “efficiency” reasons.
The worst part of it is that they outsourced ALL of the technical expertise in many agencies, leaving them without the expertise needed to effectively manage the work being outsourced.
This is starting to shift, thanks to recent efforts like the USDS, 18F, and such but it’s the work of decades to really change. Come join us!
Contracting worked on the Charlie Sheen principle: don't pay them to come around, pay them to leave.
Also, it is a much more efficient way to distribute patronage.
Look to the people who actually use these systems. Once it is up and running they will all be government employees. The real work, the thing the system is designed to do, starts after the IT infrastructure is up and running. The vast majority of people reading and handling classified informatiom are government employees ... most of them in uniform.
FYI, this system is apparently mean to protect "NATO Secret" material. That isnt a very high classification. I'd call it entry level, the sort of thing that nearly everyone in uniform is cleared to see.
In decreasing order of sensitivity, the categories are:
COSMIC TOP SECRET
NATO SECRET (NS)
NATO CONFIDENTIAL (NC)
NATO RESTRICTED (NR)
NATO UNCLASSIFIED (NU)
[0] https://www.act.nato.int/images/stories/structure/reserve/hq...
Ouch
I couldn't help it, it's literally in the article that this was part of the "NATO modernization" efforts. Perhaps whatever they had before would have failed too but it's clear that these "modernization" efforts aren't always better.
And did not know what to do with a USB.
This person was 50 in the year 2000, has clearly given up being part of or informed about modern society, and is made minister of cyber security.
[0]https://www.theguardian.com/world/2018/nov/15/japan-cyber-se...
I don't have enough context on how well Yoshitaka Sakurada is doing in his job, but at a high enough level it's possible to be a good leader without skills required to do the job few levels below. (not sure it's a good idea to strive for, but still)
Sure. But being 68 and not being able to use a computer in 2018? Not recognizing what a USB stick is?
This is more about the fact that this person is not up-to-speed with society, doesn't really understand what has been happening around him the last 20 years. What dense Japanese cave did they find him in? Basic interest in society seems like a minimum to become a minister. The fact that he is minister for cyber security just adds irony to injury.
This could easily have happened if NATO contracted an equally-incompetent party to create and sysadmin a non-cloud data center.
The contractors would likely never touch the live system. Just deliver the project to deploy.
If poisoned images were to be deployed into NATO datacenter, hackers would have no access to it as it's physically separated from internet.
I feel I have seen this vague promise on a lot of software projects that either failed or overran budget significantly.
And then, obviously, the project fails spectacularly. The only projects like this I've seen succeed were ones where the top dog (CEO/president, whatever) basically forced everyone to compromise personally.
Who thought this would be a good idea? And why was any of this on internet connected servers anyway?
[2] NIST SP 800-207, Figure 2, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
[3] https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
[4] NIST SP 800-207, Section 5.1, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...