Earlier quoted context omitted.
Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.
This is a straw man. Even if the top richest people paid an additional 16 billion in taxes that would run the gov for like a day. Our problem is with spending.
Microsoft is a national security threat: ex-White House cyber policy director
171–180 of 224 posts
Re: Microsoft is a national security threat: ex-White House cyber policy director
#172Earlier quoted context omitted.
> That's why militaries and defence companies go to great lengths to vet their staff What a joke, no they don't. They establish security internally by gating access, not trusting everyone because they've been "pre-vetted".
Gating access is compartmentalisation. If you're being brought onto, say, missile development, you absolutely will have to submit to both vetting (knowing who you are prior to access) and compartmentalisation (permitting access only to your relevant secrets throughout). I'm not saying that just because you have some kind of clearance you will get access to everything, but it's part of the preconditions to your own re…
A very secure codebase is designed in a way that all the sensitive parts are separated from the parts general users (and developers) have access to - it shouldn't be all imbued together such that sensitive parts about missiles are exposed to login APIs etc. as it seems like you were saying.
It may even be lower risk than not to open-source as the public is more likely to find and fix actual security quirks that a private contractor might miss (or could even be paid as a spy to purposely leave vulnerable).
There's also the community/recruitment aspect. AI/LLM companies are cleverly open-sourcing major parts of their work while keeping the only important part that makes them valuable private - it's a win:win as they keep their secrets yet provide for and stimulate a developer community.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#173I call bullshit. Someone, somewhere long ago deep inside of the bowels of the NSA decided to deprioritize actual security, and the use of the capability security model. They knowingly did this, because actually secure computing (which they already had at the time[1,2,3]) represented a threat to the NSA , or so they thought at the time. The trade-offs seemed acceptable, because there were systemic approaches at the ti…
You should probably try building a pure capability based operating system and making it usable, before blithely saying the entire industry got security wrong. Capabilities aren't magic. UNIX has had many forms of capability for a long time, NeXT/macOS/iOS uses them extensively as well, and there are still vulnerabilities regardless. Also, capabilities are irrelevant to the types of hack being discussed on this thread…
The ability, at run time, to pick a file, and give only that file, folder, or set of resources to a piece of software is essential to secure computing. As far as I know, NeXT/macOS/iOS et all don't have that ability.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#174all tax payer funded software should be open source
I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?
Re: Microsoft is a national security threat: ex-White House cyber policy director
#175Even if you pretended Microsoft didn't exist, I don't really see how any similar alternative actually presents a secure alternative. There's a mess of vulnerabilities and complexity at every layer of any modern computing stack you can think of. If you ACTUALLY want security, you're going to be dealing with computers which are 100x slower than what we're used to with a tiny fraction of the features. For the most part…
Don't hear this much about Apple. And most of tech companies run on Apple devices.
I'm also not saying this based on people reporting vulnerabilities, I'm pointing out the software we're using is fundamentally impossible to secure on merit of its complexity and the tradeoffs people make that neglect security.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#176Earlier quoted context omitted.
The US government isn't in need of a thousand high-skilled hackers. They are in need of a million normal employees with some basic security awareness. Anyone with a modicum of skill can find thousands of areas to improve. The issue is that almost nobody is in a position to get anything changed. Even basic software choices are a multi-year epic.
The NSA isn't actually supposed to be a massive Statsi-like bureaucracy, it's meant to crack codes used in wartime so that our troops know what the enemy will do next.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#177Earlier quoted context omitted.
Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.
> Naturally government pay would lag behind even the more mediocre H1Bs. Those "mediocre H1Bs" work their ass off compared to non-H1Bs because they get laid off/fired and deported on short notice with barely enough or sometimes no time to sell their belongings if they don't perform [1]. Meanwhile it's next to impossible to fire a govt employee for bad performance. Maybe the solution is to fill the govt with mediocre…
H1Bs wouldn’t be so easy to fire if the skillset were rare or difficult to fill.
Instead, companies are gaming the H1B lottery to create much lower-paid indentured servants while a sliver of the business rakes in 40% to 60% of the spread.
And the Federal government employees are paid at the same level or less.
I don’t find the H1B abuse defensible, but certainly a useful discussion point on relative salaries.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#178Earlier quoted context omitted.
Don't you find it a bit frightening that this tech is daily giving a smaller and smaller subset of people in the world the unilateral ability to project their will onto the world? At least if they tried to draft in an unjust war, the people could withhold their physical support. This was pretty effective during the Vietnam area, but it's a bargaining chip we've lost. As we saw with 702, we really have very little lev…
Well if the history in the past 3 years is relevant I would say that the power of elites to project their will onto the rest of the world is small. In both sides: Russia is still grinding through a war that may be their second Afghanistan; and on the western side it took US Congress half a year to approve some funds so someone else (Ukraine) would to fight China’s gas station.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#179Earlier quoted context omitted.
> Nice strawman. It is harder to fire govt employees than to fire private employees. Disagree? Let’s see, so it’s not a straw man when you say government employees are “essentially unfirable” but it is when someone corrects you?
Lets ignore the personal back and forth, and get back to the argument. It is harder to fire govt employees than to fire private employees. Disagree? At-will employment law doesn't apply to government entities. A very consequential law is different for private vs govt employees. > The managers you think can’t direct civil servants directly aren’t magically more capable of selecting and overseeing contracts, either. Ne…