Live data from Hacker News

‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

airforcemag.com

201–210 of 264 posts

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#202
post #106
post #8

I’m impressed with the person that waited over an hour to get into outlook. With determination like that no enemy stands a chance

That's nothing compared to Japanese consumers. We were a US company working with a Japanese software distributor to do Japanese versions of our products. Occasionally on some Japanese non-IBM compatible PCs [1] we were seeing a lockup during installation. It was the kind of lockup where CTRL-ALT-DEL does nothing, the CAPS LOCK light no longer toggles, and if you have a GUI that mouse pointer no longer moves. There's…

It sounds like, in any future war involving Japan, we should expect to find soldiers hiding out in the jungle years later, still trying to log in to their email...

https://en.wikipedia.org/wiki/Hiroo_Onoda

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#203
post #49

Earlier quoted context omitted.

> Couple that with all the security crap the DoD has to put on there (which probably spends half its time trying to grab resources from the other security software) Corporate spyware is a huge impact to performance, particularly if you have an HDD. I can’t count how many times I’ve seen a computer start to lock up because some security software needs to absolutely abuse the disk.

I'm in security, and one thing I always try to stress is that if the security software is causing work stoppages, it should be treated with the same importance as an outage. Just as you wouldn't tolerate an internet connection that went down all the time. Outages from security measures are still outages.

> I'm in security, and one thing I always try to stress is that if the security software is causing work stoppages, it should be treated with the same importance as an outage. Just as you wouldn't tolerate an internet connection that went down all the time. Outages from security measures are still outages.

Outages/workstop are pretty binary. Otoh its hard to see how much time people spend just waiting for stuff to complete. At my last job, pulling down a copy of the test db for local use was taking 30-40 minutes. But because everything else was slow, it was only after I noticed it being a lot shorter for coworkers that I even bothered investigating what was causing it (version of mysql was old, made it a 5-10 minute process after fixing a config).

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#204
post #176

It's not the hardware, it's the crap that runs on it. You want a system which is secure and usable? Time for the DoD to commission their own OS. "Nobody will know how to use it!" is an objection which can be overcome by training, which is a thing that the armed forces understand. "It won't be compatible with the COTS!" is an advantage, not a disadvantage. "It will take too long and cost too much!" means that they are…

>Time for the DoD to commission their own OS.

I am shocked that governments are not investing mega-bucks into getting a microkernel OS built that could be run on internet routers, tanks, power plants, aircraft, water treatment facilities etc. Even if microkerenel design has some impossible to overcome performance limitations, for utmost security, it would be a small price to pay knowing that hacking the OS was nearly impossible.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#205

For perspective: I work in a difference armed force but with basically the same issue. We once had a problem with soldiers stealing memory sticks from workstations (unclassified systems). Take only one stick and the machine still works. The theft problem goes unnoticed long enough that we cannot nail down who stole what when. Answer: Give the computers only one memory stick. Thefts will then be noticed quickly. Now,…

And you lose the 2x bandwidth increase you get from using two sticks of RAM. Oof.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#206

Earlier quoted context omitted.

Not, specifically but the article mentions at the end that the original laptops used for the win10 transition were using HD's (aka spinning rust) rather than SSDs because it was a lowest bidder situation. Given what I've seen of corp/gov IT, it wouldn't surprise me in the least if the "security software" (aka virus scanners, intrusion detection, etc) then proceeds to hammer the disk/CPU sufficiently that the machine…

The article mentions they use TWO different, heavy endpoint solutions. I'm shocked the computers work at all.

Haha, I just (as in 20 min ago) helpled a friend get their computer to work and they had 3 antiviruses running. It's a pretty common problem actually, helped a few people with it the last 20 years.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#207
post #7

> Currently the service uses both McAfee and Tanium software packages to scan and protect service-issued endpoints like laptops. The problem isn't hardware, it's that they're using the worst antivirus known to mankind. It's not throwing money at the problem, it's about what can be removed.

At my last job IT had tanium installed on our machines. It would make your computer nearly unusable for hours. Sometimes I felt like we had computers that were completely consumed by the overhead it took just for us to have them.

Yep, we had the misfortune to have both Mcaffee and Tanium installed. And then after they got ransomwared, they added even more endpoint crap onto every endpoint.

From the time Windows started, my laptop fans would spin like an aircraft taking off. Utterly ludicrous amount of wasted CPU time and energy.

To be clear, I think AV and EDR are valuable tools - but Mcaffee is just shit, and Tanium has really high CPU usage.

Aside from the above, all the security crapware made actually doing work difficult. Want to install software? Nah, nobody gets admin rights, instead submit a request on our shitty help desk, and if you're lucky and very perceivent, you'll get it in a month. Need to run something elevated? Nope!

And the worst of it was that Mcaffee, Tanium, PAM etc was all just glitter on a turd - general, more mundane stuff was a security joke. For example, at least 10 internal spam emails would be sent each day, to let you know about boring and irrelevant shit going on around the company - and every one looked like an actual spam email! Full of spelling errors, silly subject lines, and often the whole body was text rendered as an image. Internal web apps were hacked together by shit devs, and stuffed with security vulnerabilities. The general theme was "more shit on endpoints". Bah.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#208
post #84

Earlier quoted context omitted.

Currently a Air National Guardsmen. I've only had it take that long a handful of times. Usually when it does it is running Microsofts Endpoint Manager and trying to push updates, Scan with McAfee and Tanium, and loading a bunch of scripts in the background that are checking for compliance, setting a default AF or local Comm Squadon background, posting messages relating to the current security levels, etc. Its alot to…

I was active duty AF 20-some years ago. It's sad to see that absolutely nothing has changed.

That’s not true, they’re burning even MORE of our money now!

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#209

Earlier quoted context omitted.

No tuning of Tanium will make it not garbage.

I shouldn't take that personally, but I manage Tanium and my experience doesn't mirror yours. That said, I know they have some HUGE deployments in the Military and my piddly little 25000 client install may not be comparable.

I used to help Tanium manage their stuff for the US Navy on NMCI. I stand by my statement.

But it’s not personal at all. Neither you nor I made Tanium, and I’m sure your deployment is the gold standard of Tanium deployments that would change my mind.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#210
post #162

Earlier quoted context omitted.

Wat?

Few articles floating around from about a month ago, this is one: https://news.ycombinator.com/item?id=29795910

Oh wow. And here I thought they were one of the relatively clean ones among the crowd of McAfee and Avast!. Agreed with the top comment there that the whole industry is reeking. Seems like the only reasonable one is Windows Defender, with the only Linux alternative being ClamAV (non-shady but questionable if it's effective at all for a workstation)
Post reply on HN