Live data from Hacker News

NATO Classified Cloud Platform Compromised

ddosecrets.substack.com

91–100 of 122 posts

Re: NATO Classified Cloud Platform Compromised

#91

How’s that Zero Trust working out for ya?

I really wish more companies would implement Zero Trust. It's just so nonsensical to trust any device at this point - No matter how "secure" someone tells you it is, or even you think it is.

Is there a clear definition of what ZTA even is? I read the O'Reilly book, and as best I can tell, the advice was fairly obvious recommendations and also 'replace your firewall as a single point of failure and make your access-control system your single point of failure'.

Re: NATO Classified Cloud Platform Compromised

#92

Everis is the typical meat grinder, and it is known for that in Spain. Now, just as I'm writing this I'm sure someome from Everis will chime in to say he gets paid handsomely and works for amazing projects. But everyone I've known working for Everis wants to die. And if such project had to land in Spain for political reasons, there are plenty of companies capable on taking such project with way better prospects.

Article: The platform, known as NATO’s Service-Oriented Architecture and Identity Access Management (SOA & IdM) Project, is one of four core projects of NATO's IT modernization efforts. So this expresses what "modernization" is - fob as much work as possible unto a job-shop/meat-grinder operation and watch things like this happen. I don't even know whether to laugh or be appalled, the Snowden leaks happened due to co…

So you mean there are positive sides to it? Might also be true in this case since I believe they would host surveillance data on citizens.

Re: NATO Classified Cloud Platform Compromised

#94
post #68

Earlier quoted context omitted.

In line with the Persident of Nintendo who was reported to never play games. https://en.wikipedia.org/wiki/Hiroshi_Yamauchi I don't have enough context on how well Yoshitaka Sakurada is doing in his job, but at a high enough level it's possible to be a good leader without skills required to do the job few levels below. (not sure it's a good idea to strive for, but still)

These counter-examples are what "prove the rule". They succeeded despite not playing with their own products. Good for them. But they are noteworthy because they are such outliers.

Counter-examples never prove the rule. Otherwise the same logic could also be used for the inept cyber-security minister, that he is noteworthy because he is an outlier. We have had education ministers who have never been teachers, defence ministers who have never served in the military, etc. and they are not noteworthy.

Re: NATO Classified Cloud Platform Compromised

#95

Earlier quoted context omitted.

I contracted for US government agencies for a long time. At every single job the contractors were doing the "work" (they had the knowledge) and the government employees were acting as managers. I have not met a government employee with an unusually high level of technical skill (though obviously many do exist). As far as I can tell (and I worked over a decade in this environment, in many countries) government employe…

Technical government employee here. :waves: Your observation is, in general, quite correct! Back in the 80s or thereabouts, the conservative administrations started a MASSIVE shift towards outsourcing of federal government work. This was for all of the usual, largely shortsighted and inaccurate “cost saving” and “efficiency” reasons. The worst part of it is that they outsourced ALL of the technical expertise in many…

Former employee of a government contractor here.

Contracting worked on the Charlie Sheen principle: don't pay them to come around, pay them to leave.

Also, it is a much more efficient way to distribute patronage.

Re: NATO Classified Cloud Platform Compromised

#96
post #53

Earlier quoted context omitted.

Article: The platform, known as NATO’s Service-Oriented Architecture and Identity Access Management (SOA & IdM) Project, is one of four core projects of NATO's IT modernization efforts. So this expresses what "modernization" is - fob as much work as possible unto a job-shop/meat-grinder operation and watch things like this happen. I don't even know whether to laugh or be appalled, the Snowden leaks happened due to co…

> the Snowden leaks happened due to contracted-out sys admins, after all But that's a good thing, right? It's good that everybody found out that the government unlawfully collected their data etc. Snowden was not an attacker asking for money, he was an honest guy with a conscience and a whole lot of courage.

Wow you didn't know about surveillance before the terrorist Snowden's revelations? I envy you for your youth and blissful naivety let me guess Assange blew your *MIND* when he exposed a civilian death in Iraq? Hence your pro terrorist stance?

Re: NATO Classified Cloud Platform Compromised

#97

Earlier quoted context omitted.

Article: The platform, known as NATO’s Service-Oriented Architecture and Identity Access Management (SOA & IdM) Project, is one of four core projects of NATO's IT modernization efforts. So this expresses what "modernization" is - fob as much work as possible unto a job-shop/meat-grinder operation and watch things like this happen. I don't even know whether to laugh or be appalled, the Snowden leaks happened due to co…

Nearly everyone who does real work like this for the government is a contractor anymore. The government employees manage the contracts.

I'm a government employee. I work with a few dozen people across multiple locations doing actual work. Not one of us is a contractor. Zero contactors are involved in any real work. The few we have are in support positions. We have some contracted IT people who manage some of our computer systems but don't have any access to what those computers actually do. We have contacted security guards at the front gate. And I think the cleaners are contracted out but as they have NEVER cleaned my office I don't see them much.

I think there is some observational bias going on in this thread.

Re: NATO Classified Cloud Platform Compromised

#98

Earlier quoted context omitted.

I contracted for US government agencies for a long time. At every single job the contractors were doing the "work" (they had the knowledge) and the government employees were acting as managers. I have not met a government employee with an unusually high level of technical skill (though obviously many do exist). As far as I can tell (and I worked over a decade in this environment, in many countries) government employe…

That would be the plan. If it is a government contract then the government is the customer. The customer manages the project and the hired contractors do the heavy lifting. Look to the people who actually use these systems. Once it is up and running they will all be government employees. The real work, the thing the system is designed to do, starts after the IT infrastructure is up and running. The vast majority of p…

The vast majority of people reading and handling classified information are government employees? That's not the case. I was cleared at TS/SCI + polygraph and many many contractors work in that environment.

Re: NATO Classified Cloud Platform Compromised

#99

Everis is the typical meat grinder, and it is known for that in Spain. Now, just as I'm writing this I'm sure someome from Everis will chime in to say he gets paid handsomely and works for amazing projects. But everyone I've known working for Everis wants to die. And if such project had to land in Spain for political reasons, there are plenty of companies capable on taking such project with way better prospects.

Article: The platform, known as NATO’s Service-Oriented Architecture and Identity Access Management (SOA & IdM) Project, is one of four core projects of NATO's IT modernization efforts. So this expresses what "modernization" is - fob as much work as possible unto a job-shop/meat-grinder operation and watch things like this happen. I don't even know whether to laugh or be appalled, the Snowden leaks happened due to co…

Robert Hanssen was a government employee after all. It's incredibly naive to think that your employer makes any difference. https://en.wikipedia.org/wiki/Robert_Hanssen

Re: NATO Classified Cloud Platform Compromised

#100

Earlier quoted context omitted.

That would be the plan. If it is a government contract then the government is the customer. The customer manages the project and the hired contractors do the heavy lifting. Look to the people who actually use these systems. Once it is up and running they will all be government employees. The real work, the thing the system is designed to do, starts after the IT infrastructure is up and running. The vast majority of p…

The vast majority of people reading and handling classified information are government employees? That's not the case. I was cleared at TS/SCI + polygraph and many many contractors work in that environment.

In the office where you worked. In the office where I work there are zero. Classification levels don't really matter. It is about the nature of the information. Some is simply never shared with non-employees. Some isn't shared with people not wearing uniforms. Well, excepting one or two non-uniforms but they are still government employees.
Post reply on HN