But how to fix ? Most US Gov agencies are underfunded, it is either beef up security or provide services. Really a tough choice, and the outlook looks like they may lose even more funding.
But how to fix ? Most US Gov agencies are underfunded, it is either beef up security or provide services. Really a tough choice, and the outlook looks like they may lose even more funding.
Doesn't the US outspend in terms of dollars almost every single developed country on the planet at absolutely everything, even in per capita statistics, from military, police to education and healthcare? How could it be underfunded?
If you aren’t, your budget will go to someone who is.
I don't buy it thought. I think the reason why the spend is less in Europe is due to higher salary equality - good people take job in government because the salary is only 50% higher in private sector (for tech, even less for other areas).
The areas where the vast majority of Americans actually live are fairly high density.
Some cost might come down to density, but not much.
Arguable, Denmark has a super low density also if you count in Greenland.
As also written, I don't buy that argument. I think the core is inequality.
If we're considering contiguous US, then no.
Europe is 3.93 million square miles.
Contiguous US is 3.15 million square miles.
As a non-contiguous later addition, with a small population, where statistically nobody lives there per sq mile, and is not pertinent to the discussion of population density as related to infrastructure problems?
Except in what's holding US bureucratic efficiency down (what we were discussing), and requires spending inflated federal budgets for little returns, Alaska is a big factor relative to its size...
As for IT functions, all of that should be centralized under the GSA with proper security controls. There's no benefit to having every agency maintain its own IT infrastructure. Most of those staff are redundant and could be laid off.
This argument doesn't hold.
This works for email. Would you work at a company where you had to build and deploy apps on infrastructure controlled by someone in a different department and location, whose boss gave them the mandate to standardize as much as possible to reduce costs? (Hope you like Oracle…)
It’s not all or nothing here. We spend too much and get too little out of it.
Currency counterfeiting is a different set of laws than interstate financial fraud, which is a different set of laws than throwing a Snickers wrapper on the ground in Yosemite.
Which is somewhat irrevant. Teams dealing with each can still share headquarters, IT resources, support stuff, cafeterias, and lots of other things.
Our state legislature recently voted down adding a new Data Analyst position to one of their departments. That department cannot function without that position, so instead it has to use it's funding to buy that same position from a 3rd party contractor for 3x the price or more.
The result is that we pay more than anyone else for basically everything we do.
They might also generally still drug test? I don't even do drugs, but I'm not going to pee in a cup for someone to effectively do charity lol. Good luck recruiting a professional with decades of engineering experience when you treat them like they're a 16 year old working at Taco Bell. Even someone with 0 years doesn't have to deal with that kind of treatment in industry.
I wish to believe there are still people that don’t care about making Yet Another few hundred thousand and just want to actually contribute to society instead of working on ad tech or whatever bullshit.
Additional requirements not common in the private sector, such as rigorous drug testing, ethics codes, requirements on gift reporting, increased surveillance, etc., should come with additional benefits to compensate. Instead, government workers submit to these requirements and a substantial pay cut.
That's mostly because conservatives 1) desire tax cuts at any cost and 2) want to demolish the entire administrative state. The stability and consistency that comes with a well-funded civil servant class are an obstruction to their stated goals.
However, I think you're wrong, at least in part, in your third paragraph. I mean, I think the word "mostly" is wrong in that paragraph. Politicians from all political factions are (quite reasonably) under pressure to lower the cost of doing the work of government, and (quite reasonably) to raise the integrity of the process. Combined with some of the dysfunction inherent in agent-principal problems, I think that's more than enough to cause the problem you're talking about. I experience this firsthand in a jurisdiction that has much less of the "demolish the entire administrative state" that afflicts the American right wing (which I'm guessing is your point of reference).
Mind you, I am not claiming that the problem is not badly worsened by American right-wing politics. I wouldn't know. I'm just claiming that the problem is semi-intrinsic to the situation, and I strongly doubt that it's "mostly" caused by those particular political issues.
Equality is good for equality sake. This is a lesson contemporary North Americans seem to have forgotten in record time.
Background: You make an argument that at least some people should consider putting contributions to society ahead of "making yet another few hundred thousand". I agree with you, at least broadly, and I think the up-thread poster is not disagreeing.
Summary: We're discussing the act of taking a personal financial hit, for the good of society.
The word for that is "charity". That's what that word means.
---------
I also am sympathetic to the GP's point, about which you are so "disgusted", but I think there's room to disagree there.
I am sympathetic because professionally I do work that many people think is "good for society", I currently earn approximately median income (below mean) for my age/gender/nationality, far far below software engineer pay, and I am treated with unbelievable disrespect by my employer, the government. If I was not trapped in this job by personal circumstance (for now), the disrespect part would definitely factor into my decision making about staying in this allegedly-virtuous job. If you're gonna pay people below market, and you treat them badly, that's not a combination that gets you quality employees. Even if there's some social purpose.
The word for that is "charity". That's what that word means.
Calling it "charity" impies it's done out of pity/compassion.
The parent implies it should be seen as a duty / contribution to the country instead.
The wages offered are hardly poverty - just not competitive with the private sector.
Besides, "doing something out of a sense of duty", when duty meant something, has also often meant doing it for free, or even doing it on one's own dime, and it absolutely meant accepting a pay cut.
If we push it lower how are we not expecting that to require poverty? What legion of people in the US do you reckon even have "their own dimes" to spend on being full time volunteer public servants and can afford to serve from a sense of duty? Retirees?
Not all tech jobs are ads. I work in networking equipment and it pays much, much better.
Anyway, my point was they don't even give respect to the people who do that, and still treat you like their property. Same with the vaccine mandates (especially for remote workers): whether you got it isn't the point. My employers have never asked because it was never any of their business.
Regarding pay, it's actually pretty bad. A typical IT worker will be a GS-11 to GS-13 depending on location and degree (possibly lower in some locations, maybe higher in some high COL areas). GS-13 in many places is restricted to management and SMEs, though they're bumping up a lot of the "working level" grades because they realize they can't compete in hiring.
To pick a high COL area where you might find GS-13 working level IT folks, San Diego GS-13's max out at $153k. If they're actually GS and not another pay system (has a different pay raise method but usually maps to some GS grades, like Acqdemo) then it takes 18 years to go from GS-13 Step 1 to GS-13 Step 10. Most likely they aren't starting at Step 1 in any grade, let's say they start at Step 4, then it's 12 years to max. Once maxed, they only get the general pay increase every year. There are few technical GS-14 positions (this is changing, but not rapidly) even in high COL areas so the only "promotion" option for many is to go from a GS-13 technical role to a GS-13 management role (same pay) and then leverage that into a GS-14 management or technical role, if someone dies and a position opens up. GS-15 technical roles are pretty rare.
Based on my experience, every federal organization requires at least a public trust clearance for every IT contractor.
Every other agency and branch of the US government? Absolutely not.
That sounds very implausible, bordering on conspiracy theory.
We of course run these procedures while writing and formally verifying them, before handing them to the customer, not running them would be folly.
Whatever this story is sounds like the worst kind: a small nugget of truth surrounded in a giant ball of shit.
Even more than that, a customer doesn’t just hand us a pile of money and say “talk to you again in 2 years” far from it. They literally “status the status” once or more weekly. If the answer to the question of “what is the plan this week” has the answer of “we’re out of work so we’re just charging you pad our profits” won’t play.
Also, building tanks is fucking hard, I sincerely doubt any company in the industry isn’t using every penny they have to solve problems and deliver a good product.
For those that scoff at the last bit: companies are in the business of making money, and if you deliver an inferior product, you won’t get another contract.
While centrally managed economies can just mandate that state-owned factories continue to exist, private markets won't do this. If you don't order tanks and missiles, the factories that make tanks and missiles will cease to exist, and the market will reallocate resources elsewhere.
We'll start with the fact that M1s aren't built on a "base", they're built at the Joint Systems Manufacturing Center in Lima. Government owned, contractor (GDLS) run, not a base.
What they do do is refurbish older tanks, which one I suppose could distort into "disassembling", if one wanted to make a rather distorted claim.
The waste contention for that base comes from an Army proposal to temporarily shut down the factory in 2013, which was supposed to save ~$1B. GDLS explained that, sure, can do, but spinning up production again is going to cost ~$1.5B, and restarting production in 2017/18 was always planned. It's not as simple as "the politicians always allocate money to the military".
If you’re not in the military, the fact that someone else has a big budget doesn’t help you any more than your neighbor having a Mercedes helps pay your internet bill.
There are general budgets and people build in support costs, of course, but it’s terribly easy to find people who have been asking for budget to replace something years before its end of life but keep getting turned down in the congressional budgeting process. Politicians want to fund things their constituents like, but the unloved internal support app is just as much of a risk to have on your network.
Lesson learned: The organization did not effectively or efficiently collect, retain, and analyze logs.
Lesson learned: Bureaucratic processes and decentralized teams hindered the organization’s network defenders.
Lesson learned: A “known-bad” detection approach hampered detection of alternate TTPs.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
The actual issue is probably that these people are (a) ineffectual at communicating and prioritizing concerns clearly; or (b) good at communicating, but are not being listened to; or (c) they are listened to, but the organization has no practical means to fix this - no money, unable to recruit talent, etc.
Most techies often assume (b), but (a) is at least as common. The last issue - (c) - might be superficially true, although it's usually not correct in a deeper sense: there is plenty of discretionary and wasteful spending in any sufficiently large bureaucracy. Central resource allocation is just a hard problem.
Anyway, my point is that the problems that need fixing are almost never just technical. Recommendations such as "implement sufficient controls to detect malicious activity" seldom get to the root cause. They are still useful in temporarily overcoming organizational obstacles, but it usually doesn't last.
Pretty much everyone gets breached.
The only ones I don't think get breached deep are the really big software engineering companies where most of the company are also software engineers... like Google.
Software is too complex to be secure without a massive team IMO.
Assuming software can be secure (and hence not doing proper defense in depth, limiting the types and nature of information processed, etc). is the bigger issue IMO.
We could do better as an industry though. Modern operating system design makes it far too easy to shoot yourself in the foot.
Imagine a world where all we all use memory-safe/null-safe/type-safe languages, applications and data are strictly sandboxed, access to data is only granted using capabilities-based security, application-level security patches are automatically applied by the OS, data was always encrypted while at rest and while in transit, and passwords are completely replaced with passkeys / smartcards (for users) and X.509 certificates (for servers). While this isn't a panacea, it would solve a great number of the most common security vulnerabilities.
Each of these pieces exist individually. There's no reason why we can't have all of these things today, other than support for legacy applications and retraining engineers. However, it's nearly impossible to get away from legacy software needs.
But if you want low hanging fruit... stop writing C/C++, and get rid of passwords. These are the biggest flaws in the stack.
If it was popular amongst the voters to hold corporations seriously responsible, you would see politicians campaign on it and win. It's not nearly as popular as virtually anything else based on empirical data.
Another way to say this is if 80% of all voters, regardless of party prioritized this as the #1, #2, and #3 issue, politicians would pass laws. It makes the politician look good and solidifies their reelection. Likewise, politicians that vote against those laws would almost certainly not be reelected.