Live data from Hacker News

NSA revelations could hurt collaboration with 'betrayed' hackers

reuters.com

41–50 of 106 posts

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#41

There have always been reasons to object to working in national defense. During the Cold War quite a few physicists and engineers chose not to go into defense work because they did not want to feel like they were hastening nuclear Armageddon. And yet, the U.S. government developed effective new defense and energy technologies during this time. There are reasons to work for the government that are attractive to top te…

Yes to play devils advocate working for Google on say algo updates means you are responsible for people losing their jobs.

And I wont go into two faced nature of removing organic search terms from Google analytics but allowing the PPC customers access to that data.

if I where Matt Cutts id sleep happier working for the NSA than Google at the moment

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#42
post #32
post #29

The most dangerous and stupid meme percolating in pop tech culture is that the people engaged with tech culture have a unique claim to computer science, electrical engineering, cryptography, information security, and privacy technology. The Slashdot diaspora genuinely believes that most of the world's computer engineering talent reads their comments. The reality is that not only does money do a fine job of buying tal…

>In fact, I think it's likely that they're significantly smarter than any of us. Bear that in mind when you design your NSA-proof email applications. Math is math and it's relatively easy to implement decent encryption -- it is possible to pass data securely from end to end. The larger issue with these projects is that they're usually proposed by someone that can sling a bit of Ruby and fashions him/herself a cyber r…

Math is math

Physics is physics. We all know time is fixed, the universe has been around forever, and atoms are the smallest indivisible component of matter.

The world, under the guise of "everybody is created equal," has fallen under the spell of "everybody has the same intellectual capacity" (which is clearly wrong). Yahoo isn't paying a high school dropout $100 million + $80 million because of his snazzy FU-my-mom-dresses-me haircut — they're paying him that because he's different. He's better. He's done more in five years than you've done in 20. You can't train that. People just are.

The government tries to grab all the clearly better-than-everybody-else undergrads through their sneaky alliances with CS departments and professors. They usually win.

Programs are programs and it's relatively easy to implement a program. But, some programs are worth billions of dollars and others aren't worth half a farthing. It's the people who make a difference.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#43
post #29

The most dangerous and stupid meme percolating in pop tech culture is that the people engaged with tech culture have a unique claim to computer science, electrical engineering, cryptography, information security, and privacy technology. The Slashdot diaspora genuinely believes that most of the world's computer engineering talent reads their comments. The reality is that not only does money do a fine job of buying tal…

Generally I'd agree except for two points.

1) From what I've seen, at least on the military side, the "training people" concept was actually one of the things they've sacrificed over the past decade or so (and even in the late 1990s) -- it's still obviously done in areas where it's "inherently military or governmental" like flying fighter aircraft, but contractorization has caused the government sphere to revert to more like the commercial world -- fewer people genuinely trained to a good standard from scratch. There's both a higher bar for entry, and a lower output quality.

It might be totally different in the civilian government world stateside, but somehow I doubt it.

The only government jobs which seem to successfully recruit and build skills are government offense jobs (NSA TAO, etc.). Judging by results, on the defense side, they're doing a horrible job of recruiting and using their recruits. From that I've seen of DHS and USCYBERCOM recruiting, it's no better than the commercial world. USCYBERCOM has the benefit of the entire incoming recruit stream of the military, but they've been fairly slow even to train tech/operator level people. That the military is taking that big a role on civilian defense is a sign that DHS/etc. haven't been very successful recruiting for defense.

2) "10 years ahead of private industry" -- not really, since there's essentially a fusion of the contractor space and government. If BAH were somehow vastly more effective than commercial companies, you'd expect them to go into profitable civilian work as well, but only an abject fucking moron would hire any of the defense contractors to do anything if not required to do so by the government (government work is NOT more profitable than the best commercial work, so a competent firm would be motivated to do both). The flow goes the other way; Palantir came from the commercial world back into the government world.

Underestimating one's adversary is always a bad idea, but overestimating them is also bad (if it causes you to give up). The fundamental issue is that a large number of people don't consider USG to be their adversary, and for the most part, it isn't -- congress has abjectly failed in its oversight role, and programs have gotten far too big (in budget and scope), infringing rights (mainly theoretically, still), but a lot of people believe there's both a proper defense role for the military, and that the threats are growing/changing and require IT security.

Remember, even if you love the USG/NSA mission, they have three big handicaps: secrecy, bureaucracy, and security (i.e. being US citizen only). Think about how fucked up a tech company would be if it got to the scale of Microsoft or Google but without being able to hire non-citizens, have people enter/leave freely, hire anyone with at all a shady background, interact much with the outside world, etc. Then add politicians and political appointees, plus 1-2 year stint military, into key roles. From everything I've heard, NSA dealt with that in ancient times (pre-1990s) pretty well, by having career NSA people run things for other career NSA people, but they ended up in a rat-hole of focusing on the PSTN/leased line and under-exploiting the Internet. There were three main eras: the real cold war where everything was mission-driven by the soviets, the "lost years" between the end of the cold war and 9/11, and the new agency post-9/11 focused on commercial systems and "terrorists". CIA had the same challenge...a spy v spy mission, then counterdrug/etc. insanity, and then became basically global assassins and jailers.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#44
I'm not convinced. People are very good at cognitive dissonance.

If you're passionate about tech, then there are some very interesting projects to work on in government.

Rocket scientists want to build rockets. Roboticists want to build robots. Hackers want to hack. They've gotten good at what they do by subordinating other concerns to their driving interests. So, why would they be put off by something that doesn't seem to directly affect them or their loved-ones?

EDIT> Regarding the furor over heavy-handed prosecution of tech-assisted offences: that only matter if you choose the wrong side. I.e. Work on this cool stuff, stay in line, and you'll never have a problem with the law. Not a hard sell.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#45
post #29

The most dangerous and stupid meme percolating in pop tech culture is that the people engaged with tech culture have a unique claim to computer science, electrical engineering, cryptography, information security, and privacy technology. The Slashdot diaspora genuinely believes that most of the world's computer engineering talent reads their comments. The reality is that not only does money do a fine job of buying tal…

> NSA, which has been ~10 years ahead of private industry for the last couple decades, before which time they were even further ahead.

Do you have anything to back this up other than the old rumor that NSA (specifically their crypto) was ahead of private industry by 10 years, something even Bill Binney said is probably not accurate any more. And mind you, this old "10 year ahead" phrase was always specific about crypto, nothing else.

> In fact, I think it's likely that they're significantly smarter than any of us. Bear that in mind when you design your NSA-proof email applications.

I wouldn't bet on it. NSA and many other government agencies are full of incompetent or barely adequate people. Just look at our intelligence failures regarding terrorism and in both wars the last 10 years. NSA has a huge budget with billions of dollars to throw at their problems, so they get stuff done, sure, but smarter than private industry? Nah.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#46
post #29

The most dangerous and stupid meme percolating in pop tech culture is that the people engaged with tech culture have a unique claim to computer science, electrical engineering, cryptography, information security, and privacy technology. The Slashdot diaspora genuinely believes that most of the world's computer engineering talent reads their comments. The reality is that not only does money do a fine job of buying tal…

Bear that in mind when you design your NSA-proof email applications.

Oh the patrony!

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#47
post #43
post #29

The most dangerous and stupid meme percolating in pop tech culture is that the people engaged with tech culture have a unique claim to computer science, electrical engineering, cryptography, information security, and privacy technology. The Slashdot diaspora genuinely believes that most of the world's computer engineering talent reads their comments. The reality is that not only does money do a fine job of buying tal…

Generally I'd agree except for two points. 1) From what I've seen, at least on the military side, the "training people" concept was actually one of the things they've sacrificed over the past decade or so (and even in the late 1990s) -- it's still obviously done in areas where it's "inherently military or governmental" like flying fighter aircraft, but contractorization has caused the government sphere to revert to m…

I agree with you regarding defense. I do not think any part of the USG is truly competent at defending their own systems.

I agree with you that the USG is contractorizing infosec --- though note that this makes it even easier for them to recruit --- and that contractorization degrades their capabilities.

I disagree with you on offensive security. I also think you should be aware that the contractor resources the offensive side has don't entirely overlap the defensive stuff; there are better contractors available for the offensive stuff.

And all this goes out the window when it comes to pure signals intelligence and cryptography, where we're not even close.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#48
post #45
post #29

The most dangerous and stupid meme percolating in pop tech culture is that the people engaged with tech culture have a unique claim to computer science, electrical engineering, cryptography, information security, and privacy technology. The Slashdot diaspora genuinely believes that most of the world's computer engineering talent reads their comments. The reality is that not only does money do a fine job of buying tal…

> NSA, which has been ~10 years ahead of private industry for the last couple decades, before which time they were even further ahead. Do you have anything to back this up other than the old rumor that NSA (specifically their crypto) was ahead of private industry by 10 years, something even Bill Binney said is probably not accurate any more. And mind you, this old "10 year ahead" phrase was always specific about cryp…

Yes, I do have things to back it up. No, I'm not simply referring to cryptography. NSA is a very large organization; Bill Binney's say-so doesn't mean a whole lot to me. Look at the kinds of people that "graduate" from NSA TAO, and note that that's the program they let us know about.

If you want to be wishful about this point, I won't stop you.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#49
post #47
post #43

Earlier quoted context omitted.

Generally I'd agree except for two points. 1) From what I've seen, at least on the military side, the "training people" concept was actually one of the things they've sacrificed over the past decade or so (and even in the late 1990s) -- it's still obviously done in areas where it's "inherently military or governmental" like flying fighter aircraft, but contractorization has caused the government sphere to revert to m…

I agree with you regarding defense. I do not think any part of the USG is truly competent at defending their own systems. I agree with you that the USG is contractorizing infosec --- though note that this makes it even easier for them to recruit --- and that contractorization degrades their capabilities. I disagree with you on offensive security. I also think you should be aware that the contractor resources the offe…

Absolutely on the sigint/elint/etc and traffic analysis side, they are probably decades ahead (mainly because no one else actually cares. Pretty much the closest competition is people trying to meet FCC B regulations and amateur radio people. It's not even a race. There's CR and maybe a couple others beating the drum on side channel emissions and the commercial market seems to not care.)

I assume offensive is focused almost exclusively within NSA and maybe a few elements of DOE/DHS (I'd be utterly terrified if every random OIG office within the government had an offensive security team, like they do have SWAT teams now...) It's also probably a case where they can have a huge lead because (for legal reasons, as well as market reasons) there's limited demand in the commercial world for "full contact" offensive security -- just pentesters and the like, or actual criminal activity, or for the lulz.

The other thing is resources other than ideas. Even I could come up with ideas like "oh, so we need to intercept all the traffic? Let's put fiber splitters at the MAEs and IXes and such.", but having the resources to subsidize facilities, work with carriers, etc. is entirely different.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#50
post #48
post #45

Earlier quoted context omitted.

> NSA, which has been ~10 years ahead of private industry for the last couple decades, before which time they were even further ahead. Do you have anything to back this up other than the old rumor that NSA (specifically their crypto) was ahead of private industry by 10 years, something even Bill Binney said is probably not accurate any more. And mind you, this old "10 year ahead" phrase was always specific about cryp…

Yes, I do have things to back it up. No, I'm not simply referring to cryptography. NSA is a very large organization; Bill Binney's say-so doesn't mean a whole lot to me. Look at the kinds of people that "graduate" from NSA TAO, and note that that's the program they let us know about . If you want to be wishful about this point, I won't stop you.

> Yes, I do have things to back it up.

Such as? Bill Binney, having actually been one of the top mathematicians at NSA for 30 years, carries more weight than you do, unless you want to share specifics that back up the regurgitation of the "10 year ahead" phrase.

Post reply on HN