NSA Hiring At Black Hat
jfruhlinger writes "It may seem strange that the US government would be recruiting tech talent at Black Hat, a security conference whose participants have a notorious ambivalence about keeping within the letter of the law. But the NSA — a shadowy organization with its own reputation for dodgy behavior — is there recruiting, and pitching itself as a haven for geeks."
It may sound like a great idea on the surface, but a leopard doesn't change its spots just because you give it a paycheck.
So either the NSA are really fucking stupid or this is some sort of honeypot trap to target some specific (or maybe even non-specific) hackers and bust them on an espionage charge when they inevitably leak some fake secrets you give them after they become "employees." If it's the latter, I'm impressed. Never seen anyone go that far with a honeypot operation. But maybe Anon and LulSec are making them desperate. Hell, maybe they're hoping they can just *luck* into busting some Anon/LulSec leaders by throwing a wide net.
So I guess it really comes down here to a question of who's more stupid--the NSA for thinking they can tame hackers or the hackers for possibly falling for a honeypot. I don't know which is the more scary possibility.
SJW: Someone who has run out of real oppression, and has to fake it.
That's exactly the sort of place I'd expect them to be recruiting.
Not that I know anyone working at the NSA, but it isn't exactly a geek paradise.
Most geeks that I know are none too fond of rules. This is exactly the opposite of what the NSA is about. There are many rules stemming from security. Of course, all rules get extended beyond their original purpose. This makes it difficult to get any work done, which of course is the antithesis of geek.
Hoist Number One and Number Six.
Q: How do you know who the extroverts are at the NSA?
A: They look at other peoples' shoes.
All kidding aside, the NSA does have quite a powerhouse team of mathematical geniuses, computer scientists, etc. and from everyone I talked to who worked there (I'm no longer in the intel game, so it has been a while), it is a great place to work with a lot of flexibility and innovation.
-- Stu
/. ID under 2,000. I feel old now.
Nope, that's not surprising at all. I'd be surprised if they weren't using it as a recruiting pool.
or else!
So the plan is to hire some Houdini's, put them in a cage, and tell them not to escape, huh? Hope that's a really good lock.
SJW: Someone who has run out of real oppression, and has to fake it.
Send a copy of your resume to your grandmother...
real tech guy or HR doing hiring? auto screening / key words based resume screening?
It seems that in many big corporations and GOV it's who know and or who can best game the HR system to get the job or who can be the best suck up to the boss.
And I am not talking about dress codes and behaviors. I am taking about hiring base on degrees over real would work or based on TOP school as in overall VS top tech schools VS a non tech college CS degree. More then 4-6+ years degrees VS 2-4 year degrees.
TECH / IT so big that a theory based CS degree is to board and maybe even to much away from the hand on real work. Tech schools / apprenticeship are a REAL GOOD FIT for hardening a firewall, keep up software patches and updates up to date, do penetration testings also you want a team with people in skills in different parts and not just a team filled people who need to be able to do it all. Better to have a GOOD Tech GUY and poor coder then a sub par tech guy and sub par tech guy. Also need Good coders even if they suck at other IT skills.
Certifications is other area that is good and bad to based hiring on.
But hiring based on degrees only can give you people who know alot of theory but not much on the side of doing IT / hacking / coding. People who have any degrees Even NON TECH / CS ones getting jobs over some one with years of doing hands on work.
Also baseing hiring on degrees and Certifications can get you people who are good at taking tests and not knowing how use the stuff covered.
Saying no to it contractors, consultants over people with more a fixed at one place jobs is a other area that keeps good people out as well.
Most of these people are frustrated authoritarians.
It's how they can justify imposing their view of the legality of their actions on their victims.
Well, NCIS has gone Hollywood. It's been a decade since the FBI was living up to a reputation someone else was building for it.
Black Hat is a security conference that, over the last decade or so, has become predominantly attended by security executives, government employees, etc. E.g. very few "black hats" and it never really was about that. DefCon has been more the open casting call for all color of hats. Black Hat is a professional conference that costs thousands of dollars to attend. So... why wouldn't you go to the one place that has top CISO/CSO and security researchers in it?
If the article was "NSA to open recruiting booth at DefCon..." then the rest of the article would be somewhat accurate... other than they forgot to talk about all the 12 year olds, rave fiends, clove cigarette smokers, scene wanna-be, etc.
I head about the people that the tech guys want just to get shot down by HR for any number of things.
Solution: weld the cages shut. Alternatively, give him a few good punches in the abdomen.
Who did the ground work to see what is really there and or the one to push the kill button.
They will fit right into NSA, the organization that is wire-tapping everyone in the US without a warrant.
Criminals, in other words.
"The Constitution, the WHOLE Constitution, and nothing but the CONSTITUTION."
Definitely the choice for recruitment.
Heck, I'd work for the NSA if I were an american. If you're a security freak, wouldn't you want to go work for someone who takes security serious for a change? Where your request for a firewall isn't overruled by marketing because they fear (without substantiating facts, of course) that it'll slow down the website and impact the "user experience" ?
Sure you have other pressures to bow to (politics) - but, as has become a frequent saying in several companies I worked for, often accompanied with a sigh: Working with professionals, just once.
Assorted stuff I do sometimes: Lemuria.org
Sounds more like it should be "black hats" sponsored by Target. And that might even be funny if one of the sustaining partners of this conference didn't happen to be Microsoft. Anyone who's a real black hat probably wouldn't be caught dead here anyway.
the government was able to convince the judge to use an obscure 1959 NSA law to redact UNCLASSIFIED information from the defense exhibits, so that they would not be publically shown at trial.
there is a lot more to the Drake case regarding evidence, the CIPA, and the Silent Witness Rule.
how about thomas drake, did you talk to him?
I don't think patriotism has much to do with FBI service.
It is more likely TDS.
Tiny Dick Syndrome.
I have a brother-in-law and a sister who work in emergency services and another sister who works as a med tech. They all say that in their experience, a statistically significant percentage of cops have smaller-than-average penises.
You make some pretty serious errors in logic here But the most egregious is the supposition that all who attend Black Hat are untrustworthy, bad people. The vast majority are actively engaged in cyber-defense related activities. They are there to gain a better understanding of what the potential threats are, what current techniques are used in exploitation and how to defend against them. There is, of course the standard spread of good/bad/indifferent people, but don't make sweeping assumptions about people out of ignorance. That being said, the United States has a very serious asymmetric threat issue in cybersecurity. No nation is more connected, more dependent or more vulnerable. It is in the best interest of this nation to have NSA recruit where the smart people are. And this week, that's in Vegas. p.s. You can be a "bad" hacker, one who builds attacks, exploits and payloads and still be a "good" American. Exploits and payloads are no different than bullets and missiles, it takes special talent to build them, they cause damage and they are exceptionally useful.
maybe its changed alot.
even if you portray yourself as a 'haven for geeks' and recruit some of the people from black hat, eventually you will be asking those recruits to take actions against their own comrades in black hat world. and you will ask them to turn against some principles the underground world has. they will turn against on some of them sometimes. and sometimes, they wont. what is 100% guaranteed is that, there WILL be times they wont turn back - and thats not something you, as a secretive government organization, would want.
.... bad for you. good for 'the people'.
yes, its a dodgy, black underworld in which there is little law. but, it has its own principles that noone codified or maintains. and even if you can find one or two henry morgans to betray those, there will be endless number of blackbeards to do them in. not to mention that, even the henry morgans you can get, will occasionally and eventually turn on you. yeah, its not too much different than pirates of the earlier ages. however, there is much more social consciousness present in this era of piracy.
actually i shouldnt even be telling you that. any casual observer would have known these, if s/he had been interested in i.t. in any way since 1985 or so. you should probably already have some such people in your employ, and yet, you are still hiring at black hat. i guess you dont take on advice/recommendations from your employees
Read radical news here
No, the plan is to hire some Houdini's, put them in a cage, tell them to escape and write down how they did it.
Make SELinux enforcing again!
Nobody does the ground work, that's HARD. Just drop the bombs and move on, so many targets, so little time.
I wouldn't mind working with Abby, actually.
Black Hat != Def Con. Def Con is the convention for Hackers. https://www.defcon.org/html/links/dc-about.html Black Hat is the convention for Corporates. http://www.blackhat.com/html/about.html
Sorry, but there's no reality in your fantasy land scenario. Working for the NSA is quite banal and very typically office-like. Part of the allure of the NSA is that it's all this cool super secret stuff, when in reality, its just a bunch of UNIX and Windows boxes and a pool of laborers with clearances run by PHBs.
Yes, because they NSA has the time and inclination to wiretap 300 million people.
Seriously, this goes hand in hand with wall street hiring all the engineers, to avoid them going elsewhere and providing competition to a market that is already running over every other. If there is no one left smart enough to understand and question what wall street is doing, then wall street wins, and the NSA is following in the same direction....avoid any possible discovery by having all the good ones playing for your team.
Well, all 3 of the people in question do watch Fox News and American Idol.
So maybe take it with a grain of salt?
After reading several times I still can't find any news here...
In love, war and slashdot discussions, everything is allowed.
Command of the English language is probably on their checklist as well. Thanks for sending your resume.
- For the complete works of Shakespeare: cat