Live data from Hacker News

In secret cyberwar game, reservist techies pummel miltary cyberwarriors

navytimes.com

51–60 of 103 posts

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#51

The fact is that people with unconventional (by military standards) are going to look at joining the military with skepticism, so right there the military is limiting its pool of potential security service men.

and women.

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#52
post #50

Earlier quoted context omitted.

The NSA has no problem paying for top talent, but they do it by going through consulting firms. It's true that most Americans would shit their pants at 6 figure soldiers, but few military skills are so valued by the open market. As we're constantly told by the tech media, you should prefer five $200,000 people to ten $100,000 people, or—god forbid—50+ people writing PowerShell scripts for minimum wage.

>It's true that most Americans would shit their pants at 6 figure soldiers, but few military skills are so valued by the open market. Infantrymen won't have marketable skills, but we are talking about military security analysts. These guys often do have skills equivalent to their civilian counterparts. You seem to be making the same assumption that many others in this thread have: that all Soldiers are infantrymen of…

The link upthread of us shows that annual pay for federal cybersecurity professionals is about on par with industry [1], especially when considering geography/cost of living.

My surprise had more to do with learning that cyberwarefare reservists exist, let alone enlisted soldiers. (I'm not familiar with the military.)

[1]: http://www.rand.org/content/dam/rand/pubs/research_reports/R... p.64

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#53
post #34

If we're trying to use uniformed military troops to hack servers remotely, we deserve to lose any 'cyber war.' They should be used to gain physical access to hardware and people, for the purpose of applying the xkcd decryption heuristic[1]. Leave the hacking to the experts. [1] http://xkcd.com/538/

>If we're trying to use uniformed military troops to hack servers remotely, we deserve to lose any 'cyber war.' Not all Soldiers are incompetent. Some of the most brilliant people I've met are people that I met while I was in the Army. China has created numerous units that focus on offensive hacking, and they are wildly successful. Now, to clarify, I'm not saying that we should have troops performing cyber attacks, I…

I know some people who were in the military who are very smart and technical, so I don't doubt there are some good people in there.

On the other hand, while this is admittedly very anecdotal, one really obvious common thread that I see in the vast majority of great hackers I've met has been a distrust (if not borderline disdain) for authority and seemingly needless process; which I have to imagine (having never served myself) doesn't fly really well in the military.

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#54
post #26
post #22

So I can off some first hand perspective here. >Do the military "cyberwarriors" even have local admin rights on their machines? We don't, hell I don't even have access to some of the basic tools I need (i.e. version control) >Hackers don't sign up for active duty military. They do, I've met the smartest people I know in the military . The hacker types never stay though they either get kicked out because they don't wa…

> Basically the problem with the military is that they won't (or can't) pay enough to retain any of the talent they have and are unwilling to compensate for the low salary by changing the "culture" they've developed over the last century. These are all problems that are slowly working their way up the policy chains. E.g. RAND has put out a very good study on all this, http://www.rand.org/pubs/research_reports/RR430.h…

In larger tech companies there's plenty of red tape, and some of the best software developers I've seen don't care a lot about ego. People I've heard talk about public sector work (never heard any talk about military software security work) complain more about cultures where there are too many incentives to focus on the narrow mission of your own organizational subunit, and little feeling of (or decision-making with a view towards) the overall goals of the broader organization.

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#55
post #29
post #25

Earlier quoted context omitted.

> We don't, hell I don't even have access to some of the basic tools I need (i.e. version control) Yap. Dealing with the military as a customer I have definitely have seen red tape that goes beyond reasonable for security and actually downright counter-productive (the steps needed to jump through to "secure" a box, many are wasteful, antiquated, yet some obvious ones are not mentioned. There are things like "tcpdump…

>I'll just use a python wrapper around libpcap then. Must be nice, last government SOC I worked in, we could only script with powershell 1.0 installed. Sadly, that was just a year ago. We had tcpdump and Wireshark, but we weren't allowed to capture anything with it.

We had tcpdump and Wireshark, but we weren't allowed to capture anything with it.

So how does anybody know there isn't data exfiltration going on?

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#56
Since when has investing in cyberwarfare skills become a substitute for writing correct code?

Instead of thinking long term, and learning to write open, correct code in sane languages, the continued emphasis is in continuing to ship bug-ridden, untested, source either open with Linux, or closed source with Windows, in an insane languages like C, then announcing that investments need to be made in cybersecurity because the planet needs to be saved from hackers.

Why not focus on getting things right in the first place?

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#57
post #29

Earlier quoted context omitted.

>I'll just use a python wrapper around libpcap then. Must be nice, last government SOC I worked in, we could only script with powershell 1.0 installed. Sadly, that was just a year ago. We had tcpdump and Wireshark, but we weren't allowed to capture anything with it.

We had tcpdump and Wireshark, but we weren't allowed to capture anything with it. So how does anybody know there isn't data exfiltration going on?

We have our top men working on this.

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#58
post #47

Earlier quoted context omitted.

I mean no disrespect to the soldiery, but why use soldiers for this, and not the DIA/NSA/CIA/various other TLAs? I guess that's what I'm confused about. Grunts wearing camouflage sitting in front of a laptop trying to outbrain someone seems humorously perverse. It's like some high-level bureaucrat has it in his mind that 'cyberattack' necessarily means that the military has to do it, because we obviously use the mili…

>I mean no disrespect to the soldiery, but why use soldiers for this, and not the DIA/NSA/CIA/various other TLAs? I specifically said that I wasn't advocating this as a military mission. I was just stating that if it was a military mission, the Soldiers themselves wouldn't be the reason that it fails. >Grunts wearing camouflage sitting in front of a laptop trying to outbrain someone seems humorously perverse. A grunt…

I guarantee you will not attract the best talent if your vision includes them wearing camouflage.

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#59
post #54
post #26

Earlier quoted context omitted.

> Basically the problem with the military is that they won't (or can't) pay enough to retain any of the talent they have and are unwilling to compensate for the low salary by changing the "culture" they've developed over the last century. These are all problems that are slowly working their way up the policy chains. E.g. RAND has put out a very good study on all this, http://www.rand.org/pubs/research_reports/RR430.h…

In larger tech companies there's plenty of red tape, and some of the best software developers I've seen don't care a lot about ego. People I've heard talk about public sector work (never heard any talk about military software security work) complain more about cultures where there are too many incentives to focus on the narrow mission of your own organizational subunit, and little feeling of (or decision-making with…

Company red tape and military culture is nothing alike.

The most "conservative" company would have techies that don't meet any customers come in a suit, and those are almost extinct now.

In a military, depending on where you are and your rank, you could detention / penalties for not being shaved, not having your shoes shined, having a haircut that's too long by a few centimeters. You often can't take a week (or even a day) off without weeks notice unless it's an emergency. You could go to jail for disobeying a higher up.

And most importantly, if you signed up for (say) 3 years, you can't quit before those three years are up. Seriously, if you think corporate red tape is anything remotely like serving in the military - you need to revisit your idea of what the military is.

Re: In secret cyberwar game, reservist techies pummel miltary cyberwarriors

#60
post #29

Earlier quoted context omitted.

>I'll just use a python wrapper around libpcap then. Must be nice, last government SOC I worked in, we could only script with powershell 1.0 installed. Sadly, that was just a year ago. We had tcpdump and Wireshark, but we weren't allowed to capture anything with it.

We had tcpdump and Wireshark, but we weren't allowed to capture anything with it. So how does anybody know there isn't data exfiltration going on?

You usually don't check for exfiltration at the workstation level.
Post reply on HN