It's not that hard.
But anyway, my point was that I don't for a second believe that they're this incompetent, there must be other factors at play.
It's not that hard.
But anyway, my point was that I don't for a second believe that they're this incompetent, there must be other factors at play.
Let me remind you that this computer can fire missiles at people, and has a potentially unlimited budget.
The costs of good vs. bad IT security are actually not terribly significant in the context of the overall defense budget, either.
It's really a failure of process and vision, not resource constraint. Government IT and IT security used to lead industry; now consumers especially and even enterprises are more advanced than government.
eye roll
The thing which makes it hard is humans, politics, and economics -- there is a huge amount of CYA with respect to vendor choice (hence, they're a huge Microsoft/Cisco shop), lots of little fiefdoms, an "up or out" promotion policy combined with people being in leadership roles for short periods (with minimal prior background), and lack of real accountability.
The Microsoft-ness isn't enough to kill them on its own; look at the Israeli military, which is also heavily Microsoft based, and has world-class computer security.
If you have a good engineer or a great engineer but any kind of bureaucracy, yes, it's near impossible.
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0...
"Microsoft thanks the following companies for working with us and for providing details of limited, targeted attacks against customers of Internet Explorer 6:
Google Inc. and MANDIANT; Adobe; McAfee; French government CSIRT (CERTA)"
http://technet.microsoft.com/en-us/security/bulletin/MS10-00...
A requirement that all components of the TCB be FIPS 140-2 level 3+ for anything which is routinely used in combat operations would please me, I think. Right now that's just for the crypto modules themselves.
That said, i'm not in charge of physical security of anything. I'm sure the guys with missile launching computers figure anybody that can get to the secure terminal is trustworthy.
If it's good enough for the NHS, it's good enough for uncle sam.
have fun!