Earlier quoted context omitted.
A type writer is more secure.
Maybe, until you need to send those docs somewhere.
NATO Classified Cloud Platform Compromised
51–60 of 122 posts
Re: NATO Classified Cloud Platform Compromised
#52Re: NATO Classified Cloud Platform Compromised
#53Everis is the typical meat grinder, and it is known for that in Spain. Now, just as I'm writing this I'm sure someome from Everis will chime in to say he gets paid handsomely and works for amazing projects. But everyone I've known working for Everis wants to die. And if such project had to land in Spain for political reasons, there are plenty of companies capable on taking such project with way better prospects.
Article: The platform, known as NATO’s Service-Oriented Architecture and Identity Access Management (SOA & IdM) Project, is one of four core projects of NATO's IT modernization efforts. So this expresses what "modernization" is - fob as much work as possible unto a job-shop/meat-grinder operation and watch things like this happen. I don't even know whether to laugh or be appalled, the Snowden leaks happened due to co…
But that's a good thing, right? It's good that everybody found out that the government unlawfully collected their data etc.
Snowden was not an attacker asking for money, he was an honest guy with a conscience and a whole lot of courage.
Re: NATO Classified Cloud Platform Compromised
#54My only question is; why such project was connected to the internet at all ?
There's no NATO related data there - it's just a project for NATO. If poisoned images were to be deployed into NATO datacenter, hackers would have no access to it as it's physically separated from internet.
Re: NATO Classified Cloud Platform Compromised
#55Not that I think internal efforts are always success stories, but outsourcing your identity and access management to the lowest bidder sounds like a recipe for disaster. Who thought this would be a good idea? And why was any of this on internet connected servers anyway?
Re: NATO Classified Cloud Platform Compromised
#56Everis is the typical meat grinder, and it is known for that in Spain. Now, just as I'm writing this I'm sure someome from Everis will chime in to say he gets paid handsomely and works for amazing projects. But everyone I've known working for Everis wants to die. And if such project had to land in Spain for political reasons, there are plenty of companies capable on taking such project with way better prospects.
So it's akin to Capgemini, Infosys, Accenture, Deloitte, PwC, TCS and the like?
Re: NATO Classified Cloud Platform Compromised
#57Earlier quoted context omitted.
Nearly everyone who does real work like this for the government is a contractor anymore. The government employees manage the contracts.
It really is one of the dumbest things in government work. Politicians want to "shrink government" so they don't want many actual employees that would probably be well paid, stable, but someone needs to do the work. Thus, enter the I-too-want-to-shrink-the-government politicians who agree but then farm it out to contractors, some whom they might work for one day (or even come from in some cases in the US!). And so th…
"Shrink government" shouldnt be taken at face value.
Re: NATO Classified Cloud Platform Compromised
#58Reading the start of this article reminded me of a somewhat unrelated thing I saw: I remember seeing in "tech influencer" youtube video on how "Japan hasn't kept up with the west" when it comes to IT. Not to be super orientalist or whatever and assume Japan is doing better the US in IT, but what should they do instead, go the US route and put every thing on the cloud? Is that better ? I couldn't help it, it's literal…
This could easily have happened if NATO contracted an equally-incompetent party to create and sysadmin a non-cloud data center.
Re: NATO Classified Cloud Platform Compromised
#59Reading the start of this article reminded me of a somewhat unrelated thing I saw: I remember seeing in "tech influencer" youtube video on how "Japan hasn't kept up with the west" when it comes to IT. Not to be super orientalist or whatever and assume Japan is doing better the US in IT, but what should they do instead, go the US route and put every thing on the cloud? Is that better ? I couldn't help it, it's literal…
System error: Japan cybersecurity minister admits he has never used a computer[0] And did not know what to do with a USB. This person was 50 in the year 2000, has clearly given up being part of or informed about modern society, and is made minister of cyber security. [0] https://www.theguardian.com/world/2018/nov/15/japan-cyber-se...
I don't have enough context on how well Yoshitaka Sakurada is doing in his job, but at a high enough level it's possible to be a good leader without skills required to do the job few levels below. (not sure it's a good idea to strive for, but still)
Re: NATO Classified Cloud Platform Compromised
#60My only question is; why such project was connected to the internet at all ?
A computing cloud that's not connected to the internet is completely useless. Besides, how else would the lowest bidder international contractor be able to work on it?
The contractors would likely never touch the live system. Just deliver the project to deploy.