Live data from Hacker News

NATO Classified Cloud Platform Compromised

ddosecrets.substack.com

41–50 of 122 posts

Re: NATO Classified Cloud Platform Compromised

#41
post #19

My only question is; why such project was connected to the internet at all ?

There's no NATO related data there - it's just a project for NATO.

If poisoned images were to be deployed into NATO datacenter, hackers would have no access to it as it's physically separated from internet.

Re: NATO Classified Cloud Platform Compromised

#42
post #39

Reading the start of this article reminded me of a somewhat unrelated thing I saw: I remember seeing in "tech influencer" youtube video on how "Japan hasn't kept up with the west" when it comes to IT. Not to be super orientalist or whatever and assume Japan is doing better the US in IT, but what should they do instead, go the US route and put every thing on the cloud? Is that better ? I couldn't help it, it's literal…

Stop using fax will be enough to be considered modern by my standards

A type writer is more secure.

Re: NATO Classified Cloud Platform Compromised

#43

Earlier quoted context omitted.

Nearly everyone who does real work like this for the government is a contractor anymore. The government employees manage the contracts.

> The government employees manage the contracts. How long before that's outsourced to Accenture too?

No no, the companies executing the contracts are the experts, they know what’s best to put in them. It comes as free consult.

Edit: if only this was a joke.

Re: NATO Classified Cloud Platform Compromised

#44
post #11

Everis is the typical meat grinder, and it is known for that in Spain. Now, just as I'm writing this I'm sure someome from Everis will chime in to say he gets paid handsomely and works for amazing projects. But everyone I've known working for Everis wants to die. And if such project had to land in Spain for political reasons, there are plenty of companies capable on taking such project with way better prospects.

So it's akin to Capgemini, Infosys, Accenture, Deloitte, PwC, TCS and the like?

I wouldn't put Deloitte or PwC with the other ones. But yeah, you can add Atos techmindra etc for body shops. Accenture pretends to be like a big4 (like most consultancy) but they are much closer to an Atos/Infosys than PwC.

Re: NATO Classified Cloud Platform Compromised

#45
Not that I think internal efforts are always success stories, but outsourcing your identity and access management to the lowest bidder sounds like a recipe for disaster.

Who thought this would be a good idea? And why was any of this on internet connected servers anyway?

Re: NATO Classified Cloud Platform Compromised

#46
post #11

Earlier quoted context omitted.

So it's akin to Capgemini, Infosys, Accenture, Deloitte, PwC, TCS and the like?

I wouldn't put Deloitte or PwC with the other ones. But yeah, you can add Atos techmindra etc for body shops. Accenture pretends to be like a big4 (like most consultancy) but they are much closer to an Atos/Infosys than PwC.

> wouldn't put Deloitte or PwC with the other ones.

I'm not convinced. I attended one of their recruitment events at university - lots of synergy going around. In fact I forgot about EY and a bunch of others too.

Re: NATO Classified Cloud Platform Compromised

#47
post #38

Earlier quoted context omitted.

It really is one of the dumbest things in government work. Politicians want to "shrink government" so they don't want many actual employees that would probably be well paid, stable, but someone needs to do the work. Thus, enter the I-too-want-to-shrink-the-government politicians who agree but then farm it out to contractors, some whom they might work for one day (or even come from in some cases in the US!). And so th…

Do you think projects run and implemented by people directly employed by the government have a better track record?

https://en.wikipedia.org/wiki/Apollo_11

Re: NATO Classified Cloud Platform Compromised

#49

> It will drive innovation and reduce operational costs by ensuring much greater reuse of capabilities. I feel I have seen this vague promise on a lot of software projects that either failed or overran budget significantly.

It's because it practically boils down to: "We want all of the functionalities we are currently using in a variety of different systems in one system, but we're unwilling to make any compromises on the feature list. Everything has to be implemented exactly as it is in it's current system."

And then, obviously, the project fails spectacularly. The only projects like this I've seen succeed were ones where the top dog (CEO/president, whatever) basically forced everyone to compromise personally.

Re: NATO Classified Cloud Platform Compromised

#50

Reading the start of this article reminded me of a somewhat unrelated thing I saw: I remember seeing in "tech influencer" youtube video on how "Japan hasn't kept up with the west" when it comes to IT. Not to be super orientalist or whatever and assume Japan is doing better the US in IT, but what should they do instead, go the US route and put every thing on the cloud? Is that better ? I couldn't help it, it's literal…

System error: Japan cybersecurity minister admits he has never used a computer[0]

And did not know what to do with a USB.

This person was 50 in the year 2000, has clearly given up being part of or informed about modern society, and is made minister of cyber security.

[0]https://www.theguardian.com/world/2018/nov/15/japan-cyber-se...

Post reply on HN