Live data from Hacker News

‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

airforcemag.com

241–250 of 264 posts

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#241

I will never understand when a company/government entity pay people a high salary then give them crap or low-end hardware. You should be maxing out dev machines and the rest of the company should rarely see a spinner or have to wait on their tech. It's a huge waste of time that you are paying for. I once calculated how much time I wasted waiting on slow processes at a job and then multiplied it by my effective hourly…

One big problem is misaligned incentives. At most big orgs, you have an infosec dept with authority to put all kinds of virus scanning, etc etc on every computer in the org. They get rewarded if there are no incidents; they do not get penalized if they make your machine impossible to use.

The main priority of an IT department is security.

The most secure system is one that isn't being used.

Therefore, the main priority of an IT department is to make the systems as difficult or unpleasant to use as possible.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#242
post #224
post #7

> Currently the service uses both McAfee and Tanium software packages to scan and protect service-issued endpoints like laptops. The problem isn't hardware, it's that they're using the worst antivirus known to mankind. It's not throwing money at the problem, it's about what can be removed.

I'm currently on an engagement at a retail bank for a project that went entirely off the rails (they brought me in to right it). All of the following are currently running simultaneously: * McAfee * Tanium, which is constantly firing off massive Python scripts * Aternity * Windows Defender (which is well-behaved as expected) ... wait for it ... on an SSD that has no DRAM. Yes, a cacheless SSD. Performance isn't much…

Seems about right. I've done engagements will multiple financial clients and they seem to make it their job to make every engineer as unproductive as possible.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#243

The military should evaluate wholesale replacement of spinning hard drives with SSD, rather than replacing many thousands of computers.

Windows security bloatware can still bring a system to its knees with an SSD.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#245

For perspective: I work in a difference armed force but with basically the same issue. We once had a problem with soldiers stealing memory sticks from workstations (unclassified systems). Take only one stick and the machine still works. The theft problem goes unnoticed long enough that we cannot nail down who stole what when. Answer: Give the computers only one memory stick. Thefts will then be noticed quickly. Now,…

I spent way too long trying to work out how a USB memory stick being absent would prevent system usage, and why that would be a thing.

Time for coffee.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#246
post #7

> Currently the service uses both McAfee and Tanium software packages to scan and protect service-issued endpoints like laptops. The problem isn't hardware, it's that they're using the worst antivirus known to mankind. It's not throwing money at the problem, it's about what can be removed.

Windows admins are some of the worst, especially in government. They don't understand how computers work, and so they pipe on anti-virus, anti this and that, hoping a product will magically solve the issue. But they won't move the default browser, or install an ad blocker. They won't put in policies preventing running the software in the first place or isolating its abilities. After years of having terrible, exploita…

Looks like you need to meet some better Windows admins. Being a moron is operating system agnostic.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#247
post #210

Earlier quoted context omitted.

Few articles floating around from about a month ago, this is one: https://news.ycombinator.com/item?id=29795910

Oh wow. And here I thought they were one of the relatively clean ones among the crowd of McAfee and Avast!. Agreed with the top comment there that the whole industry is reeking. Seems like the only reasonable one is Windows Defender, with the only Linux alternative being ClamAV (non-shady but questionable if it's effective at all for a workstation)

It's there mostly for the checkboxes on copliance, but it's not that bad, compared to others.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#248
post #110
post #7

> Currently the service uses both McAfee and Tanium software packages to scan and protect service-issued endpoints like laptops. The problem isn't hardware, it's that they're using the worst antivirus known to mankind. It's not throwing money at the problem, it's about what can be removed.

Oh man ... the cruft that corporate IT installs slows down the computers so much. Its better if companies start handing out linux machines if they cant afford macs. I would trade my windows laptop with IT cruft any day for a linux machine.

You have too much faith in corporate IT.

They can fuck up macs and Linux just as well.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#249

Earlier quoted context omitted.

We could have put NIST or another entity in charge of developing a federally-approved *nix distro decades ago and we'd have none of this friction today.

This would still be an awesome solution today. I hope we do this eventually. But I don't believe Windows is the problem, it's the way the DoD is trying to manage it.

Windows is definitely part of the problem, but I agree it's not the problem. Linux or MacOS are not better enough either.

Re: ‘Fix My Computer’ Cry Echos on Social Media; Air Force CIO Responds

#250

Earlier quoted context omitted.

Wouldn't any competent CIO of a company or government office big enough to need a CIO do the same? Which roadmapped strategic projects are going to get chopped so that this new project can start immediately?

What's the point of all the roadmapped projects if all of them will have 1hr+ startup times? Is the enemy going to wait for squadron commanders to log into Outlook before firing artillery? All of the strategic projects should get chopped until this one is addressed. What is the point of managing IT infrastructure if none of it works.

I'm not so familiar with the military but wouldn't it be up to brass like generals or strategic command to decide if the IT infra upgrades are a threat to combat readiness, and prioritize it accordingly?

They can give the CIO budget to do this, but the CIO can't unilaterally decide to do it.

Post reply on HN