Live data from Hacker News

X-Force Command Cyber Tactical Operations Center

ibm.com

31–40 of 52 posts

Re: X-Force Command Cyber Tactical Operations Center

#33
This is 100% intentional hype. This is designed to be deployed at a trade show or outside corp headquarters. The video states that they built a "cyber security range" in ~2016, which generated 2,000 customers. This SOC is to showcase capabilities and sell whatever IBM is bundling. It also allows them to charge for on site incident response training.

I'm sure somebody somewhere will need to call IBM and have them drive a SOC to them in an emergency. Which, I'm sure, IBM will happily charge them a small fortune for. But this is marketing.

Re: X-Force Command Cyber Tactical Operations Center

#34
post #9

It's particularly in systems like these where they usually leave SSH w/ password login, or an oudated Teamviewer install. [1] Realistically, I can see this working. For Disney. For use in action movies. In fact, "23 tons of cyber capabilities" is exactly the thing I would expect to hear from an action movie. [1]: https://www.pentestpartners.com/security-blog/pen-testing-sh...

Well, it's a setup for LARPing (see recent encrypted email thread) cybersecurity with execs as a flashy sales pitch, so the film prop aesthetic is the main feature. It's literally a roadshow. I'm just a bit disappointed that the trailer can't deploy an autonomous Tesla Cybertruck manned by David Hasselhoff.

Re: X-Force Command Cyber Tactical Operations Center

#36
All the comments seem to be trashing IBM for this, but it's kinda cool! I mean sure, this is silly and impractical (a moving truck with a bunch of foldable chairs and laptops would do just fine) but that wasn't really the point, right?

In theory, there may be someone somewhere that needs something like this but this is intended as a cool demonstration piece.

Re: X-Force Command Cyber Tactical Operations Center

#37
post #20

rather offtopic but this rolling marketing gag is powered by a Peterbuilt 579 (why is the logo blacked out??) and only weighs 23 tons. The 579 can easily haul more than double this. https://www.peterbilt.com/trucks/highway/model-579 this is a class 8 truck which retails for around $150,000 new and has a 12 liter PACCAR MX13 engine with ~450HP and 1800FP of torque. Collision mitigation, advanced cruise radar, and an a…

Disclaimer: I know nothing and this is an honest questions. I wonder if they intend to be able to use the tractor for power in situations where external power is lacking. Powering, and more importantly and power-hungry, cooling "23 tons" of equipment wouldn't be the lightest task.

Doubtful. The generator appears to be hanging off the front of the trailer. It's probably not impossible to put a PTO generator on the truck too but it would show up as some lumpy gear on the truck between the cab and trailer, with ventilation. There would also need to be extra ventilation for the engine.

Re: X-Force Command Cyber Tactical Operations Center

#38
post #30

"Putting cybercrime on the road to ruin". Bless whoever had to type that sentence and keep a straight face. This is hilarious, but honestly sign me up for the job where I get to setup an computer environment in the back of a semi. I don't think it will actually lead to any good, but it should be fun.

Imagine the vibration and ventilation problems. I was thinking "how long to unpack and set up once parked?" ... That number will be longer once this vehicle ages and travels a bit. If one wanted to make a thing like this operational while mobile that would be an even more exciting challenge.

Re: X-Force Command Cyber Tactical Operations Center

#39
post #34
post #9

It's particularly in systems like these where they usually leave SSH w/ password login, or an oudated Teamviewer install. [1] Realistically, I can see this working. For Disney. For use in action movies. In fact, "23 tons of cyber capabilities" is exactly the thing I would expect to hear from an action movie. [1]: https://www.pentestpartners.com/security-blog/pen-testing-sh...

Well, it's a setup for LARPing (see recent encrypted email thread) cybersecurity with execs as a flashy sales pitch, so the film prop aesthetic is the main feature. It's literally a roadshow. I'm just a bit disappointed that the trailer can't deploy an autonomous Tesla Cybertruck manned by David Hasselhoff.

While I do agree with you on the IBM truck remarks, I find myself heavily disagreeing with the "PGP / SMTP over TLS" is LARPing" gentleman.

For one, he makes the argument that it's all a theater. Is it broken ? Yes. Does it provide some non-negligeable level of confidentiality ? Absolutely. Is it "broken" in some way or another ? Yes. But that doesn't mean we should just fall back to regular plain unencrypted email when PGP MAKES MORE SENSE. I myself don't use PGP when it doesn't really make sense. But when sending a security vulnerability, I'd say it's pretty safe to assume you're not LARPing at that point. Sure, maybe they know you're sending a PoC. But that will at least delay them for a couple of days (or hours if you're a high value target).

A comment on that thread expressed exactly what I feel and what I assume what most of security minded people feel: Sure, it is not perfect. But if I want perfect-secrect (as perfect as it theoretically gets anyway), I'm going to use Signal. But when your company has e-mail as the main communication form, it doesn't make much sense to use another form of communication, it will hinder productivity and obstruct your company's processes.

All in all, LARPing is a strong word. If anything, we should applaud the effort confidentiality-minded people put up, and push for better protocols.

Re: X-Force Command Cyber Tactical Operations Center

#40
post #34

Earlier quoted context omitted.

Well, it's a setup for LARPing (see recent encrypted email thread) cybersecurity with execs as a flashy sales pitch, so the film prop aesthetic is the main feature. It's literally a roadshow. I'm just a bit disappointed that the trailer can't deploy an autonomous Tesla Cybertruck manned by David Hasselhoff.

While I do agree with you on the IBM truck remarks, I find myself heavily disagreeing with the "PGP / SMTP over TLS" is LARPing" gentleman. For one, he makes the argument that it's all a theater. Is it broken ? Yes. Does it provide some non-negligeable level of confidentiality ? Absolutely. Is it "broken" in some way or another ? Yes. But that doesn't mean we should just fall back to regular plain unencrypted email w…

You're probably aware, but the obvious counterargument people make to what you've said is that for some people such as activists under repressive regimes they would rather not be able to email than email under the mistaken belief what they were sending is highly secure. TFA on that article said the risk is non-technical users seeing technical users use PGP and assuming it's a good option when there are high stakes.
Post reply on HN