NSA Hiring At Black Hat
jfruhlinger writes "It may seem strange that the US government would be recruiting tech talent at Black Hat, a security conference whose participants have a notorious ambivalence about keeping within the letter of the law. But the NSA — a shadowy organization with its own reputation for dodgy behavior — is there recruiting, and pitching itself as a haven for geeks."
It may sound like a great idea on the surface, but a leopard doesn't change its spots just because you give it a paycheck.
So either the NSA are really fucking stupid or this is some sort of honeypot trap to target some specific (or maybe even non-specific) hackers and bust them on an espionage charge when they inevitably leak some fake secrets you give them after they become "employees." If it's the latter, I'm impressed. Never seen anyone go that far with a honeypot operation. But maybe Anon and LulSec are making them desperate. Hell, maybe they're hoping they can just *luck* into busting some Anon/LulSec leaders by throwing a wide net.
So I guess it really comes down here to a question of who's more stupid--the NSA for thinking they can tame hackers or the hackers for possibly falling for a honeypot. I don't know which is the more scary possibility.
SJW: Someone who has run out of real oppression, and has to fake it.
That's exactly the sort of place I'd expect them to be recruiting.
Sincerely,
Anonymous
Not that I know anyone working at the NSA, but it isn't exactly a geek paradise.
Most geeks that I know are none too fond of rules. This is exactly the opposite of what the NSA is about. There are many rules stemming from security. Of course, all rules get extended beyond their original purpose. This makes it difficult to get any work done, which of course is the antithesis of geek.
Hoist Number One and Number Six.
Q: How do you know who the extroverts are at the NSA?
A: They look at other peoples' shoes.
All kidding aside, the NSA does have quite a powerhouse team of mathematical geniuses, computer scientists, etc. and from everyone I talked to who worked there (I'm no longer in the intel game, so it has been a while), it is a great place to work with a lot of flexibility and innovation.
-- Stu
/. ID under 2,000. I feel old now.
Aside from the silo they are assigned to (which is probably classified itself), why would they have access to classified information? Most likely they'll be in an untrusted DMZ given very specific information on what to do. Find a way to crack X, then the crack is given to someone else who can be trusted. Don't underestimate them, they make mistakes and cultivate an mythos of superpowers, but they are also very good at what they do.
Nope, that's not surprising at all. I'd be surprised if they weren't using it as a recruiting pool.
or else!
The NCIS had some nice schwag too, the FBI was giving away cheap plastic cups =(. Problem is federal pay grades suck a**, private industry pays much better. So unless the person is patriotic or something it's probably tough for them. Plus us foreigners can't get a job with them, but we can in private industry pretty easy.
Send a copy of your resume to your grandmother...
real tech guy or HR doing hiring? auto screening / key words based resume screening?
It seems that in many big corporations and GOV it's who know and or who can best game the HR system to get the job or who can be the best suck up to the boss.
And I am not talking about dress codes and behaviors. I am taking about hiring base on degrees over real would work or based on TOP school as in overall VS top tech schools VS a non tech college CS degree. More then 4-6+ years degrees VS 2-4 year degrees.
TECH / IT so big that a theory based CS degree is to board and maybe even to much away from the hand on real work. Tech schools / apprenticeship are a REAL GOOD FIT for hardening a firewall, keep up software patches and updates up to date, do penetration testings also you want a team with people in skills in different parts and not just a team filled people who need to be able to do it all. Better to have a GOOD Tech GUY and poor coder then a sub par tech guy and sub par tech guy. Also need Good coders even if they suck at other IT skills.
Certifications is other area that is good and bad to based hiring on.
But hiring based on degrees only can give you people who know alot of theory but not much on the side of doing IT / hacking / coding. People who have any degrees Even NON TECH / CS ones getting jobs over some one with years of doing hands on work.
Also baseing hiring on degrees and Certifications can get you people who are good at taking tests and not knowing how use the stuff covered.
Saying no to it contractors, consultants over people with more a fixed at one place jobs is a other area that keeps good people out as well.
Most of these people are frustrated authoritarians.
It's how they can justify imposing their view of the legality of their actions on their victims.
real tech guy or HR doing hiring? auto screening / key words based resume screening?
Are you kidding me? Have you never applied for high profile jobs and got rejected? If it was not clear, then yes, real tech guys do go outside to find out what potential candidates know. HR is only for finding out when they are ready to join, and to negotiate the pay.
Black Hat is a security conference that, over the last decade or so, has become predominantly attended by security executives, government employees, etc. E.g. very few "black hats" and it never really was about that. DefCon has been more the open casting call for all color of hats. Black Hat is a professional conference that costs thousands of dollars to attend. So... why wouldn't you go to the one place that has top CISO/CSO and security researchers in it?
If the article was "NSA to open recruiting booth at DefCon..." then the rest of the article would be somewhat accurate... other than they forgot to talk about all the 12 year olds, rave fiends, clove cigarette smokers, scene wanna-be, etc.
I head about the people that the tech guys want just to get shot down by HR for any number of things.
Umm, they don't want em' to change their spots. Do you think the Chinese or Russians hire good little boys for their industrial espionage programs? If you're breaking the law, then you either hire criminals, or else try to make ordinary people into criminals (patriotism, ribbons, etc.).
She's the hottest NCIS cop around!!!
Who did the ground work to see what is really there and or the one to push the kill button.
They will fit right into NSA, the organization that is wire-tapping everyone in the US without a warrant.
Criminals, in other words.
"The Constitution, the WHOLE Constitution, and nothing but the CONSTITUTION."
Definitely the choice for recruitment.
Heck, I'd work for the NSA if I were an american. If you're a security freak, wouldn't you want to go work for someone who takes security serious for a change? Where your request for a firewall isn't overruled by marketing because they fear (without substantiating facts, of course) that it'll slow down the website and impact the "user experience" ?
Sure you have other pressures to bow to (politics) - but, as has become a frequent saying in several companies I worked for, often accompanied with a sigh: Working with professionals, just once.
Assorted stuff I do sometimes: Lemuria.org
Sounds more like it should be "black hats" sponsored by Target. And that might even be funny if one of the sustaining partners of this conference didn't happen to be Microsoft. Anyone who's a real black hat probably wouldn't be caught dead here anyway.
Anyone else feel like Defcon has lost it's potency? I could be wrong, but i feel like the more popular it gets, etc. There are some great presentations, but there's certainly less great presentations.
Also, with more popularity comes... lawyers. From what i can remember there were five presentations that were canceled due to court ordered gag orders.
Not to mention if you are a black hat, the last place you'd want to be is hanging out in a crowd full of law enforcement officials.
the government was able to convince the judge to use an obscure 1959 NSA law to redact UNCLASSIFIED information from the defense exhibits, so that they would not be publically shown at trial.
there is a lot more to the Drake case regarding evidence, the CIPA, and the Silent Witness Rule.
how about thomas drake, did you talk to him?
The National Security Agency has many fascinating career opportunities for talented mathematicians, scientists, and engineers. If you're interested in working for the NSA, pick up the phone, call your mom, and ask for an application.
Why does NSA have mountains of money and NASA none? Don't we have our priorities backward!
maybe its changed alot.
even if you portray yourself as a 'haven for geeks' and recruit some of the people from black hat, eventually you will be asking those recruits to take actions against their own comrades in black hat world. and you will ask them to turn against some principles the underground world has. they will turn against on some of them sometimes. and sometimes, they wont. what is 100% guaranteed is that, there WILL be times they wont turn back - and thats not something you, as a secretive government organization, would want.
.... bad for you. good for 'the people'.
yes, its a dodgy, black underworld in which there is little law. but, it has its own principles that noone codified or maintains. and even if you can find one or two henry morgans to betray those, there will be endless number of blackbeards to do them in. not to mention that, even the henry morgans you can get, will occasionally and eventually turn on you. yeah, its not too much different than pirates of the earlier ages. however, there is much more social consciousness present in this era of piracy.
actually i shouldnt even be telling you that. any casual observer would have known these, if s/he had been interested in i.t. in any way since 1985 or so. you should probably already have some such people in your employ, and yet, you are still hiring at black hat. i guess you dont take on advice/recommendations from your employees
Read radical news here
Be aware that they only hire you for a fixed period of time (18 months on average) with a strict contract, and they get all up in your shit, analyze your web browsing, learn about all your family friend networks and then add you to their database before ending your contract and wishing you well. Unless you are can dig up enough dirt on your superiors during the time you are there to blackmail them into keeping you around. That is how it works.
Nobody does the ground work, that's HARD. Just drop the bombs and move on, so many targets, so little time.
Black Hat != Def Con. Def Con is the convention for Hackers. https://www.defcon.org/html/links/dc-about.html Black Hat is the convention for Corporates. http://www.blackhat.com/html/about.html
Yes, because they NSA has the time and inclination to wiretap 300 million people.
is one way to get geeks to work for the "good side" or at least to use their talents for a job. At least someone at NSA is thinking in a right way. One way is to spend $ to train and hire applicants and the other way is to train talented people who think differently. It is usually easier to swing a liberal minded individual or a geek. You will be hitting 2 birds by one stone, removing one potentially bad hacker from the pool and gaining a talented employee.
Seriously, this goes hand in hand with wall street hiring all the engineers, to avoid them going elsewhere and providing competition to a market that is already running over every other. If there is no one left smart enough to understand and question what wall street is doing, then wall street wins, and the NSA is following in the same direction....avoid any possible discovery by having all the good ones playing for your team.
After reading several times I still can't find any news here...
In love, war and slashdot discussions, everything is allowed.
Ever heard the old adage of "It takes a thief (to catch one)"? This is GOOD, SOLID REASONING on the part of the NSA!
Now, since you're calling them "stupid"? Ever heard of "SeLinux"?? Guess who's largely responsible for THAT excellent "bolt on" to std. Linux??? That's right - THE NSA!
APK
P.S.=> Want to CATCH hacker/cracker types, OR @ least be able to understand their "mindset, std. modus operandi, &/or motivations"?? HIRE THEM! Most effective defense weapon they could be using, no questions asked!
... apk
The people who attend black Hat have to pay and in some cases a significant chunk of change. My 2 day class was about $2200 (granted I could have saved a bit if I had registered early). The presenters are, for the most part, some of the industries best and brightest with some of the most up-to-date topics you will find anywhere. Not to mention that some of them already have clearances (be it through 3 letter agencies or them being contractors for companies that support 3 letter agencies). Black Hat is a logical choice to look for and recruit talent while learning what might be the cutting edge.
Command of the English language is probably on their checklist as well. Thanks for sending your resume.
- For the complete works of Shakespeare: cat