‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds
airforcemag.com
airforcemag.com
Quite a different tone. He seems desperate, but he's not self centered.
[0]: https://www.linkedin.com/posts/michaeljkanaan_technology-fut...
I know of a military computer (simulation display, 4x4K screens) running off a single 64gb stick because they couldn't bring themselves to install 4x16 or even 2x32.
Time for coffee.
The problem isn't hardware, it's that they're using the worst antivirus known to mankind. It's not throwing money at the problem, it's about what can be removed.
* McAfee
* Tanium, which is constantly firing off massive Python scripts
* Aternity
* Windows Defender (which is well-behaved as expected)
... wait for it ... on an SSD that has no DRAM. Yes, a cacheless SSD. Performance isn't much better than a cheap USB flash drive, which is expected when an identical SSD costs $18 on NewEgg.The system is effectively I/O bound all the time. The quad-core (8th gen Intel core) idles at 70% utilization, constantly spiking to 100%. The commit charge for getting into the Explorer shell is 13.8GB of the 8GB of physical memory. The laptop itself appears to have a street value of about $240 on eBay. Quality unit with a 1366x768 TN display.
-----
The 30 day discovery period is about to end. I am not supplying an SoW for any further work. I told them the reason nothing gets done by their teams is because the hardware they give everyone is trash, and I can't solve their architectural issues when IT doesn't supply tools to get work done. I wish them the best of luck.
From the time Windows started, my laptop fans would spin like an aircraft taking off. Utterly ludicrous amount of wasted CPU time and energy.
To be clear, I think AV and EDR are valuable tools - but Mcaffee is just shit, and Tanium has really high CPU usage.
Aside from the above, all the security crapware made actually doing work difficult. Want to install software? Nah, nobody gets admin rights, instead submit a request on our shitty help desk, and if you're lucky and very perceivent, you'll get it in a month. Need to run something elevated? Nope!
And the worst of it was that Mcaffee, Tanium, PAM etc was all just glitter on a turd - general, more mundane stuff was a security joke. For example, at least 10 internal spam emails would be sent each day, to let you know about boring and irrelevant shit going on around the company - and every one looked like an actual spam email! Full of spelling errors, silly subject lines, and often the whole body was text rendered as an image. Internal web apps were hacked together by shit devs, and stuffed with security vulnerabilities. The general theme was "more shit on endpoints". Bah.
Trend Micro is the same way. The only thing that eventually made it bearable was getting an SSD, but it still sucks.
But there's only so much you can do with a 7th gen dual core mobile i7
Now...McAfee? a)Was a pig, but b)did we really need to scan the entire disk every Friday afternoon?
That said, I know they have some HUGE deployments in the Military and my piddly little 25000 client install may not be comparable.
But it’s not personal at all. Neither you nor I made Tanium, and I’m sure your deployment is the gold standard of Tanium deployments that would change my mind.
99% of the time it’s not Tanium, but 1% of the time is very much is.
On the upside, you learn every part of the stack as you have to defend yourself at each and every turn.
But be honest, it was Tanium that got my dog knocked up, wasn’t it?! Just admit it!
After years of having terrible, exploitable software on windows, it's the natural result. Some manager gets a pdf exploit, and on windows there's simply nothing you can do about it. But IT has to do something, so to make them look good they throw another anti-virus on.
To me, the whole ordeal screams: software bloat, software misconfiguration, background service overload. You could snappily send mail 15 years ago, and the computational task itself hasn't grown much, besides bloated browser login windows.
Try booting a 2 GB RAM machine to some RAM-preloading Linux thumbdrive and you'll see why the problem is not "spinning rust HDDs" and "only 4 GB RAM"
Reading the article was indeed surprising and depressing - it certainly is a plausible scenario! The question is: is such a disfigured desktop experience an acceptable result, given that the physical hardware enables much, much more productivity?
They're absolutely running some sort of modern Windows so I don't see how this is relevant at all. MS-DOS2.0 would also work like a dream on those specs, who cares?
It destroyed performance. Also it was poorly configured by the checkmark-brigade in their “security & compliance” department.
All I’m saying is careful what you wish for.
Edit: spelling
They can fuck up macs and Linux just as well.
It would have been more cost-efficient and secure to smash our machines with sledgehammers than force us to run this ... junk.
We were a US company working with a Japanese software distributor to do Japanese versions of our products. Occasionally on some Japanese non-IBM compatible PCs [1] we were seeing a lockup during installation.
It was the kind of lockup where CTRL-ALT-DEL does nothing, the CAPS LOCK light no longer toggles, and if you have a GUI that mouse pointer no longer moves. There's usually pretty much nothing to do at that point except hit the reset button or toggle power.
It was quite rare, giving us not much to work with. Our Japanese partners decided it was rare enough to go ahead and ship handling the (hopefully) handful of people that hit it via tech support.
So we shipped. And they got something like 100 support calls--but the callers were not upset. In fact they were happy with the product except that they wanted to suggest that the installer should be made faster or should run in the background so they could use the computer while the install takes place. The reports said that the install took something like 20-30 hours.
I can't even conceive of a US consumer letting a computer that appears totally locked up while installing a small utility program sit for up to 30 hours.
(BTW, knowing that it was just very slow rather than frozen was enough of a clue to let us figure it out. We needed to scan for hard drives and CD-ROM drives. The way we were doing that was hitting some sort of edge case on a particular model of controller's firmware that made some requests take a long time. We were able to change the drive scan to avoid that controller's edge case).
Seriously now...Hearing the pain here frustrates me because i am actually in favor of paying my taxes because i know when handled properly then roads, bridges, infrastructure, other things, and yes, the right tools for our military are done then everyone benefits...but when things are not managed right, it chafes me so much because the pain ripples all the way through from civil servants unable to do their job, to military folks not having tools to help defend us, to civilians being put at risk while going over unsafe bridges, to commerce not being efficient because roads suck, etc.
Just from reading your comment, sounds like the biggest problem is the vendor overlap here. MS Endpoint Manager, MacAfee and Tanium all seem to be doing the same thing.
This seems like scope creep on an epic scale. It's almost like someone came to USAF IT every 3 years and said "we signed a contract with X vendor, add it to the laptops".
Given what I've seen of corp/gov IT, it wouldn't surprise me in the least if the "security software" (aka virus scanners, intrusion detection, etc) then proceeds to hammer the disk/CPU sufficiently that the machine cannot make forward progress. My wife's work machine (a fairly nice, if slim dell) sits there with one of its 4 cores at 100% running a McAfee process hammering the disk doing some kind of scan pretty much 100% of the time. The result is that it pushes that core to max turbo, overheats the system and then throttles the whole thing to ~800Mhz. It then takes a minute or two to open word/etc. And that is with a fairly fast SSD, add in the spinning rust, and i'm sure it would take much longer.
And of course its locked down sufficiently that its not possible to even try and fix it.
Scanning through the replies, I'll also add that if you are loading your entire profile from the network, this often becomes much more problematic than the IT people may have initially calculated, because even if you can transfer a gigabyte in 10 seconds, you can't transfer a gigabyte in 10 seconds to thousands of users simultaneously, and logins are highly temporally correlated. It doesn't take much at all to have a cascading network failure as a result, even under perfect conditions, as that 10 second window becomes a 20 second window, which catches ten more people and it turns into a 40 second window, and it explodes quite fast from there as suddenly everyone everywhere is waiting for minutes or hours to load from the same overloaded profile server(s).
From what I've witnessed of this, what you'll get is a number of these answers operating at once.
I found out this is a thing when Chrome and Firefox started to put their files in the user's home directory by default. If that has to traverse a network - and who knows where all that data is coming from or how fast the internet connection is - that can take a long time.
The idea that you can log into any PC and your local desktop and documents all appear seems really nice, but the implementation weeds are nasty: I tell people to store things they want to access on multiple computers on a network share, and we replicate basically nothing between client PCs.
Outlook also likes to download a large chunk of a user's mail archive locally each time you open it on a PC, but you can configure it a bit, and Outlook generally "works fine" while downloading. I suspect it gets hairier at DOD scale though.
At my company people would remotely log in on Sunday evenings to avoid the hou long wait while a few hundred gigs get copied across the network. Why not chnage the location of the local repo, you ask? Of course our machines are locked down and we have no access to the local drive...
There's lots of reasons it can happen though (especially on Windows, where the mood for 20 years was "cram it all into apply on login GPOs and scripts"). My guess in this case since the machine costs $109 (used, I assume), is that it is running spinning rust and 4GB of RAM, which on Windows 10 isn't a lot of fun. Couple that with all the security crap the DoD has to put on there (which probably spends half its time trying to grab resources from the other security software) and I could definitely see an hour.
Corporate spyware is a huge impact to performance, particularly if you have an HDD. I can’t count how many times I’ve seen a computer start to lock up because some security software needs to absolutely abuse the disk.
Outages/workstop are pretty binary. Otoh its hard to see how much time people spend just waiting for stuff to complete. At my last job, pulling down a copy of the test db for local use was taking 30-40 minutes. But because everything else was slow, it was only after I noticed it being a lot shorter for coworkers that I even bothered investigating what was causing it (version of mysql was old, made it a 5-10 minute process after fixing a config).
I’ve got a hint that a lot of it is doing stuff that the OS might even consider malicious.
Then they also inject themselves into processes and 'hook' into operating system routines to check things the feeds to not provide: which files are being accessed, how often, what memory is allocated, what type of memory is allocated, which threads are running, where they are running and what they are doing, if there's mismatches between what the operating system told are the modules loaded, and what it can find in memory.
Most of this software can be configured so that the resource usage is relatively tame, but then on the next pentest the security people will notice all sorts of ways the products did not catch them (this is the usual case). And then things are tuned to max in short order :) And then you have security software running multiple rules and scans on each file any process opens. And processes open a lot of files, all the time.
I didn't know what this meant, so I looked it up on DuckDuckGo.
The first relevant result was from... a DoD website.
You do not want to apply all of their reccomendations to any computer, but I will say that fully STIG'd computer will actually not take that long to boot up, aside from the first application of the policies. Login performance usually comes down to drive maps, printer maps, and startup programs.
>Currently the service uses both McAfee and Tanium software packages to scan and protect service-issued endpoints like laptops. But the computing power required by multiple programs often interferes with the user’s work, and damages the user experience, or UX.
The problem isn't hardware necessarily (well it is here), but it's also the bundled software. Not only are these machines old but they are having to load all this extra shit that slows down the whole experience that much more.
On macs MDM is also needed for a bunch of enterprise setttings. like pre authorizing apps to do stuff, or remote locking 'missing' machines.
To be clear, it’s not apple’s fault —- but they do own the OS and the scheduler.
I’ve previously experimented with the kill command, stopping and starting applications. Apple could do this automatically and reduce that 5% to 1%, or even 0.1%.
This assumes that Slack is doing something over and over many times, rather that just being super-slow at doing the thing once.
Slack is a chat app, and as you say has no business requiring 5% of a CPU. If it’s doing that because it checks for new messages more often than once per second, Apple can help them with that. If they actually require more than a second to check for messages, then their requirements or their developers need to change.
The last agent they installed had a nasty habit of pegging the CPU at 100% and locking up virtual machines for 10-15s at a time anytime there was heavy disk activity. Luckily I still have root on the local machine so I wrote a quick script to loop and kill that process whenever it spawned. I'm not bragging about that, but it is what it is I guess.
The most secure system is one that isn't being used.
Therefore, the main priority of an IT department is to make the systems as difficult or unpleasant to use as possible.
An "impossible to use" machine won't have any incidents reported against it
Personally I don't care much about my laptop except htat it can drive a large external display and does fast networking. I only use it to connect to a VM I make in teh cloud, which is multiples faster and more powerful than my macbook pro.
So, he made his workers use crappy computers and a dodgy network he set up. He claimed it made them make better applicaitons, but I can easily say that if the job hadn't been critically important for me, I'd give my opinion and move on.
I build software for Aristocrats and I expect my tools to be first class. That said, I've reached a level of trust where my l eadership trusts me to manage millions of dollars worth of cloud inventory and much of my messaging to my users is: "please do not attept to save $400 by using $1000 of your time"
1 fast PC for speedy development and 1 slow laptop for testing. It makes no sense to give developers a slower computer simply to make them develop better. It's like saying that post office workers must now use bicycles instead of motor vehicles in order to encourage them to find shortcuts. I'm not a successful CEO, though, so maybe I'm just talking out my ass.
Developers, especially highly paid ones, are as selfish as anyone else on the planet. If you have a strategy to make them care about literally a single other person, I suggest you go for it.
Testing on slow devices is important but using a slow device as primary dev machine would just waste too much time.
This is how we get software catastrophes like Teams. There is no earthly reason for it to suffer from the bugs and performance issues that it does and I have to believe the developers responsible for it are completely unaware of how much this software sucks to use because of their hot rod developer workstations. They still dog food at Microsoft don’t they?
Ha ha ha, no, probably not. A relatively recent post from an alleged ex-Microsoft employee said that all the designers use Macs, which might be the reason Windows keeps getting worse.
I'm not defending the practice and I am firmly in the "High performance orgs require people to have the best tools you can reasonably buy"
Bean counters will, by contrast, rarely cut their own budgets because they control the budget.
Is it? Without IT can a business even run?
> and often "owns" the expense of issuing laptops.
That's just accounting done wrong. The correct way to do accounting around internal IT is to have IT bill projects/departments for their use.
VMs and plain Docker containers are for suckers apparently. We went from one not like prod environment to another, but at least this one costs us a few millions in salary per year to create. Someone is getting a promotion, right?
The selling company is obviously going to min/max this contract as much as they can. You could order a bunch of laptops if you had the authority I guess, but it will not be making on to the network since that is under contract too (probably the same company)
Companies have been doing this for so long they’ve lost all knowledge of how modern IT is supposed to work.
We see no problem in assuming that people need the lowest-common-denominator operating system in computer to suit the people instead of the people learning how to use a proper computer, though.
If something is mission critical, then it should NOT be running on Windows. And if people find it a little harder to use because it takes a little bit of learning, so be it.
"It's not as simple as that!" Bullshit. If something matters, it's worth extra energy to do it right. In reality, it's only extra energy at first. Once people learn how to use it, it's LESS energy because it works, it works the first time, and it works properly, unlike Windows.
I mean, they are. Student pilots often solo at 8-10 hours total flight time.
Second, that only takes into account seat time, not all of the other study required to understand the instruments and other assorted knowledge.
You want a system which is secure and usable? Time for the DoD to commission their own OS.
"Nobody will know how to use it!" is an objection which can be overcome by training, which is a thing that the armed forces understand.
"It won't be compatible with the COTS!" is an advantage, not a disadvantage.
"It will take too long and cost too much!" means that they aren't in a good position now and lots of jobs will be created.
"Nobody wants to work on a military system!" is technically true, but run it out of NASA or the Department of Energy and develop it with an open source license (effectively a necessity, anyway). Also, it turns out that lots of people and companies will work on things when money is involved.
I am shocked that governments are not investing mega-bucks into getting a microkernel OS built that could be run on internet routers, tanks, power plants, aircraft, water treatment facilities etc. Even if microkerenel design has some impossible to overcome performance limitations, for utmost security, it would be a small price to pay knowing that hacking the OS was nearly impossible.
It doesn't. There's no inherent hit on microkernel performance. What exists are limitations of hardware that wasn't designed for it, and a complete lack of interest on creating hardware optimized for them.
We talk craptons about "innovation" and torrents of words on "cybersecurity" yet underpin daily life on recursive kludges on 1980s operating system and software technology. It's quite Kafkaesque!
This isn't just a matter of "spending more on IT" - they likely already spend too much. It's just spending on the wrong things.
No amount of layering crap on top will overcome the rotten, slapdash foundations of systems like windows, nor the diverging motivations between MS and and their customers. Especially customers like the U.S. Government. The amount of vendor lock-in to the shitty MS ecosystem, begetting atrocities like critical data living on godforsaken Sharepoint, is profoundly saddening. It's remarkable how everyone just uses hardware that's orders of magnitude faster than 1990s computers, yet interactions are far slower.
I once tried (reluctantly) connecting my USG-issued laptop onto my fairly locked-down home network. The amount of spew it continually issued onto the network was disgusting and I just disconnected it and drove in to complete whatever mandatory update they demanded.
Instead of creating yet another goddamn "cybersecurity czar", how about we try to take what we've learned in the past 40-50 years in computer science and try to properly engineer the software foundations for the next 30 years? This is absolutely something the USG could instigate and accomplish, if the initiative was run by the right people. I know some of them!
I'd advise they start with a Linux distro. They can audit/replace components as they go to increase security over time. Even North Korea wasn't paranoid to build it's own OS[0].
What matters is the configuration of the OS and the network, and most importantly the selection and configuration of applications, whether hosted or client (or both). That is where DoD should focus their resources.
Invoking the broken window fallacy is not a good sign for the coherence of your argument.
I'm not entirely sure whether I should interpret this post literally or as a satire of NIH syndrome.
Competing software ecosystems can constitute valuable economic activity. Broken Windows is, if anything, the current state of affairs: running important things on Microsoft Windows is becoming intolerable, with layers of expensive (dollars and computrons) fixes being applied. Is it economically better to start over or to keep trying to defend the indefensible?
https://www.google.com/search?q=frustrating
My, a lot of those images involve computers for some reason...
Then the game started and you pressed E to heal. Not sure what I expected, but was super disappointed
Which seems just stupid in its face, but then you realize that almost all of the budgeting is line itemed for specific capabilities.
If leadership can’t change resources around to fix such a glaring problem due to legal/budgeting rules, then I’m sorry to say they can’t win a conflict.
Pretending corruption isn’t corruption because it is signed into law is one of the great blind spots of America, one on which it will continue to lose in its foreign excursions just like every major conflict it’s been in since I’ve been alive.
All of the strategic projects should get chopped until this one is addressed. What is the point of managing IT infrastructure if none of it works.
They can give the CIO budget to do this, but the CIO can't unilaterally decide to do it.
If I recall correctly there was a slew of issues, for one, the certificate on their Exchange server was expired, but more frustratingly, the site he needed to access seemed to use some sort of TLS version or feature that didn’t work in IE. That’d be fine and all, as they worked in other browsers, but what didn’t work in other browsers was the entire interface implemented as a Java Applet.
Imagine implementing a new Java Applet today?
Do this also with security researchers and developers.
DO NOT CONTRACT typical approved suppliers. Those are the non-technical leeches bleeding the public coffers.
Some context:
- It takes 20-30 minutes to go from login to having excel or outlook up
- Opening a program like Outlook, Chrome etc takes on the order of minutes once booted up/settled
- Regular problems regarding permissions, popups that take minutes to close, licenses for things like Adobe etc
- If you call comm, they blame it on Sq leadership not buying faster computers
- Substantial latency on every action
- Each computer is often shared by a rotation of ~30 people, which may contribute to the issue
- I harbor suspicions DoD comm leadership has been compromised by a foreign power
I've worked around our scheduling and training software being useful by deploying a webapp used in an unofficial context. The AF dumped an updated to the official software recently that made it go from bad to unusable, and now I get new account requests every week.One approach - not ideal: Non-DoD computers on squadron Wi-Fi. Can't connect to network drives etc, but is a lifesaver for one off mission planning products. Or get whatever queep you can at home before coming in.
Basically we were not allowed to use any free/open source software. The reason is that we couldn't "purchase a support contract" for the thing we were using. Not that we would actually try and buy support, company just wanted the capability of getting support.
This drove down to the trivial. I remember we needed a calendar to display a team meetings. There was a kick ass open source calendar that did everything we needed it to. Well we couldn't get it approved because there was no "provided support", I pleaded with them that it's a fucking calendar widget and we don't need support, the response was always "well what if someone has to support this in the future", like lady this isn't some super complicated financial system, it's a fucking calendar.
This example repeats itself throughout the industry. The US Govt has the capability to build their own OS, their own security and tech, but they instead choose to engage with a million different vendors to get their job done. It's like a SaaS startup that gets a bunch of subscriptions to software they may or may not use, just on a much larger and grander scale.
Good job we don't live in that world.
I've read sci-fi books that are more realistic than this. Only the wildest cyber-crime novels portray the military network systems and administration ops as competent. When watching "Alias" a long time ago, I had to laugh every time I saw an instantly responding laptop from sleep that basically took 1 second to show a login screen (of course they used Linux so it is actually possible, especially if they picked laptops with good compatibility).
And in light of Spectre/Meltdown and the complete hardware and software security circus that we've been witnessing for years (a new CVE in a popular software on a regular basis, anyone?), I also have my doubts that the military control their physical computer supply chain that well and from "trusted" vendors, but who knows. They love doing it, so that part maybe they got right. Doesn't change the fact that they have thousands of machines that are potentially back-doored on the hardware level, even below ring zero.
--
Needless to say I completely agree with the article. Like 1h to just log-in, WTF?! And another 20 minutes to just send an email?!
I have a laptop with a Celeron J4155 CPU and 12GB RAM and a SATA III SSD that starts Manjaro + XFCE in 10-12 seconds. A browser and mail client are fully started and ready to use another 10-15 seconds later. The machine doesn't lag on any of the casual tasks that I do on it, unless I play a 4K YouTube video.
It costed me exactly $170 on the second-hand market, and has a very acceptable 3000x2000 display as well. Maybe the military should look into those laptops.
Sounds like they're going to get the F-35 of antivirus software. Having multiple programs might not be the problem, but consolidating to just one is an easy sell for a lucrative non-solution.
I mean, what if they just bought their people budget laptops with 8-12GB RAM and an SSD, lol. Will be much cheaper over a course of 3-5 years.
Or have good network ops and not allow viruses inside in the first place. A lot of corps have super paranoid (and actually good) teams doing that.
I just turned in a 7400 Latitude...the motherboard on it is dated 2018, it was out of production 6 months before it was given to me as a new machine...that was to last 4-5 years. it was out of date on day one and we kept getting them due to lifecycle hardware contracts.
Running Teams, Outlook, and a few Chrome tabs was enough to leave the poor mobile i7 running at 100% all day long. I'm certain it resulted in an enterprise cost increase in repair costs due to thermal damage...fans...dust...
The exact same system with a fresh Ubuntu install would be quiet and quick...but the layers of policy, software, and workloads keep pushing for more of everything....what Moore gives, Microsoft taketh away...
The cost of a new laptop is negligible in the grand scheme (~3m employees, 1k per laptop = 3B on a 700B budget) and saves them from a logistical nightmare.
Replacing all the HDDs bij SSD is a perfect example of being 'penny wise but pound foolish'.
I'd imagine the kind of people who get Linux running on a toaster would be up for getting an Outlook-compatible email client running on a toaster-equivalent PC.
And that's the point where IT should go, run a filter in the inventory list for all models < 2018 and have local IT service desks replace them. If you know your users are of the type to not cause any trouble with IT due to culture, you go the other way around to bypass that culture.
> Currently the service uses both McAfee and Tanium software packages to scan and protect service-issued endpoints like laptops
In my experience McAfee alone will do exactly what this thread describes. But you then combine it with another security solution, and you end in on contention hell.
They can even scan one another during scans of underlying files/processes unless they're both correctly excluded from one another.
Frankly I'd love an explanation as to why Windows 7 works just fine on a hard drive but Windows 10 staggers around like it's been shot.
Windows 7 had an independent QA team, and Windows 10 did not. I'd guess that some Microsoft developers and testers for 7 had SSDs, but most had spinning disks; but during the 10 development, most developers were using SSDs and neglected to test with spinning hard drives.
It's terrible, and doesn't make sense. When 7 booted, especially if you didn't have a lot of ram, it would thrash the hard drive for a while, but once the update service and windows defender got fully started and calmed down, you'd be good to go. From what I can tell, Windows 10 never stops thrashing the drive, and whatever it's up to ruins performance for anything else you want to do with the drive.
Apparently all you need to do is call IT and get a new computer! I wonder why none of these service men and women thought of that?
1. How fucked is the PC? Do we have the skills/time to fix it?
2. Is the person an officer or important civilian? Are they in a leadership role?
If a low-ranking airman had a slow laptop, we'd give them advice and tips to speed up the PC and send them on their way unless it was a chronic issue. If it was a high-ranking officer who had a slight performance degradation, we'd replace the PC that day. These weren't codified rules, it was just the culture of our organization and the military in general.
The problem is they all are in the same boat and there is no actual "wonder team" that could ever possibly save them.
It's becoming more and more difficult to write an initial access file for every single EDR and anti-virus combination out there. But if you know what you're working towards it's a breeze :)
The above made me stop and ask "The Air Force has an esports group??"
At every agency I've worked at, people were given sub-par machines. The joke was, "We bill by the hour, don't we?"
McCann, AKQA, Digitas... was always standard to give people 5+ year-old laptops, often without even wiping them between staff members. We had one new hire, a junior UX designer, try and screen share with a client only to realize all of the bookmarks were packed with porn sites.
I remember in 2018 getting an 11" MacBook Air with 2 GB of RAM on it... as the team lead for a $25M project. Just a total joke. It was on par with what the devs were given. "Be happy they gave you a Mac!"
Meanwhile, 50% of the CPU was taken up with some BS security scanning program IT installed that require you be on the company VPN, and junky VPN software that hadn't been updated in 5+ years and only supported like 15 people trying to use it across the whole company... and it seldom worked from clients' offices... the moment I got on-site, my laptop was nothing more than a paperweight. And even if I could log in, all my bandwidth and CPU would be spent trying to backup the computer.
And... when I fought for better machines for my staff, at AKQA I was told by the MD, "Just drop it, we aren't going to spend any more money on hardware. You're being obnoxious and there's no benefit." Meanwhile my team was bringing their own external keyboards, mice, and monitors (and dongles) because the company wouldn't supply them. Ever try and design for 4k screens on a 11" MacBook Air with 2 GB of RAM? Ha. Most everyone just resorted to bringing personal equipment when they had to go on-site. It was too painful to use the company-issued junk.
It's a lack of understanding. Some bean counter who only uses his computer for checking Facebook all day assumes that nobody else does anything else, so 2 GB of RAM seems like enough. Meanwhile, the IT guys -- who aren't ever client facing and seldom needed the powerful machines -- all got top of the line equipment. "They're IT, they need it..." Um... wait what? At a time when I couldn't get my designers even 1 4k monitor, the IT guys were all rocking dual Apple Cinema Displays. Yay agencies!
Anyway look, it's all maddening. Make sure it's easy for anyone to put in for the tools they need to do the job well. Give everyone a new computer ever 3 years, keep staff happy and productive. Give the old ones to charity, get a tax write-off. Seems like that would work fine.
Maybe they could share notes on best practices/trade equipment
On Sundays, Space Force gets to login on the "good computers", Navy on Tuesdays
Seriously, this sounds like a national security risk or consultant's wet dream.
Do other countries run Microsoft too?
:-((
Had to read that twice
Get rid of Windows, reset the entire chain by moving to Chromebooks. Schools have proven this truth: the only way to deploy to large numbers of transient and unsophisticated users is to go thin-client. That will force the DOD to build scalable networked services. Most of the time, using off-the-shelf services is fine. If DOD can be in AWS then they can also be in GSuite.
Everyone will have excuses why everything in .mil needs to be custom or done to some twisted set of DOD requirements, or why Windows is essential. That's fine, the problems will never go away
It would not surprise me to learn that NKorea with its in-house linux is able to run IT better than DOD.