Pentagon Contractors Openly Post Job Listings For Offensive Hackers
Sparrowvsrevolution writes "In the wake of confirmation that the U.S. government was involved in the creation of Stuxnet and likely Flame, a look over job listings on defense contractor sites shows just how explicitly the Pentagon and the firms that service it are recruiting offense-oriented hackers. Northrop Grumman, Raytheon, Lockheed Martin, SAIC, and Booz Allen have all posted job ads that require skills like 'exploit development,' have titles like 'Windows Attack Developer,' or asks them to 'plan, execute, and assess an Offensive Cyberspace Operation.'"
Who would better know how to defend against these attacks than someone who knows how to develop and implement them?
For that exquisitely offensive hacker smell...
Aren't all hackers offensive?
http://www.rootstrikers.org/
the government is hiring people to hack my software with the intention of doing harm. If I was Apple or Google I'd be looking at this closely. Even if you hate Microsoft, this seems pretty ambiguous. I wonder if there's something in the Windows EULA that Microsoft should sue the government for violating.
So then, why don't we have a Department of Offense instead of just a Department of Defense? If the lie, I mean creative labeling works for DOD, why not use it for hacking titles also?
Also, I wonder if the inadvertent Stuxnet admission had anything to do with the change. Why mention such in job ads anyhow?
Table-ized A.I.
But rocketing demand and a lagging supply of skilled hackers is boosting salaries and driving the defense industry’s war for talent into the open, says Alan Paller, the director of research at the cybersecurity education-focused SANS Institute. He cites SANS’ statistics that highly skilled cybersecurity staffers were paid as much as $175,000 in 2011, up 25 to 30 percent from two years before, and points to comments from the Booz Allen Hamilton executive Patrick Gorman to Bloomberg last year that the company tries to hire 1,000 cybersecurity experts a year, and struggles to find them.
Gentlemen, the next new fad. Here's a trick question: how many script kiddies does it take to develop an exploit?
Don't respond!!! It's a trap!!
Once I was a four stone apology. Now I am two separate gorillas.
the only downside... can't smoke weed at work
http://www.youtube.com/watch?v=BBMtl79atFs
insensitive clod overlords obligatory xkcd car analogy russian reversals whoosh pedant fanbois ftfy in 3...2...1..PROFIT
Best advertising you could ask -- for Linux or Mac.
A feeling of having made the same mistake before: Deja Foobar
Well I'm glad that they're posting the job listings openly.
Secretly posted listings don't usually have a great response rate.
Quoting another slashdotter: "This is just a reporter's opinion sourced from conversations with people whose names he won't reveal at times he won't reveal..... he details the exact contents of a meeting that consisted of president Obama, vice president Biden, and CIA director Leon Panetta. For him to have this conversation, it means he has interviewed either the president, the vice president, or Panetta on this. Fat fucking chance. It's probably true, but no it's no way in hell close to "offical"."
My AC stalker: " I personally agree with your posts most of the time, but that won't keep me from modding you troll"
This is right up my alley.
People always say that I'm highly offensive...
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
I bet the clearance interviews are interesting and probably resemble a job interview. Have fun with the EQIP form!
The electric yellow has got me by the brain banana
...looking for! :)
M00v^g 0N
what would be the nearest "bird farm" to Redmond?? or maybe the nearest Jam Factory??
Any person using FTFY or editing my postings agrees to a US$50.00 charge
Do I get the job or do I have to cuss like a sailor, give every client the finger, dress gaudy, and be generally uncouth as well?
I don't need to explain why training terrorists might not be the best idea for our long term interest, right?
Leave it to the government to use outside contractors which demand a ridiculously high salary for this, when they could just develop more offensive capabilities with the people they already have. There are hundreds of military people who could perform this task with a little training and education, but the Pentagon, in their infinite wisdom, would rather those people sit on mountain tops playing Guitar Hero.
Even in my short 8 years in the Army, I saw a complete brain dump of technical jobs. The people who replaced me keep getting more incapable, because all the capable ones get out and take contracting jobs. Then the Army can't fulfill their mission, so the contractors hire back the same former military people to fill their previous slots, with 3x the salary and benefits.
sudo make me a sandwich
There's no intelligent life in U$A...
Now that there is an economic "boom" in offensive hacking in the US (and probably elsewhere, too), what are the core skill sets that one should have? Computer languages, networking, social engineering? Any non-IT skills, like physics, EE, etc.?
Northrop Grumman, Raytheon, Lockheed Martin... aren't these big, bueracratic arms companies? Wouldn't it be better off hiring experienced, hard core programers, from small, specialized companies? Pay off John Carmack, David Cutler, etc.
Recently US senators and members of Congress have been demanding punishment for anyone responsible for the recent media accounts of US involvement in Stuxnet and Flame. Can we assume that there's going to be a thorough investigation of what is in effect confirmation of those media stories? Starting with the HR departments of those giant defense (or offense) contractors and going as far as the evidence leads? Are we holding our breath?
Sorry, I forgot there are ads on the Web; I use Lynx.
Call it the Department of Offensive Matters and it can be shortened to DOOM, which would be awesome.
Troll is not a replacement for I disagree.
Don't do it, hackers! Save your productive energy for the private sector, where you will produce something of value instead of bureaucratic waste.
I had one gig with a dod contractor, you could not pay me enough to do it again. Ok, I am lying but the rate would be near insanity.
Got Code?
Why should the firm have to pay these guys? The Feds only have to threaten charges to them to work for the lulz. What did we spend all that money on Congressmen for? Is there no justice? Laxity, laxity, laxity!
I'm taking this up at the next stockholder's meeting!
Good, you're the first one to point out part of this problem.
A lot of people learn hands on... so where are you supposed to learn this stuff legally? It kinda makes me laugh in the summary "a drying up supply of hackers". Okay, so we have 100 articles calling hackers terrorists, then you're complaining why people stop hacking?
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
Hire Kevin Mitnick. He's the most dangerous hacker in the world. All he has to do is call up Iran and whistle into the phone, and they nuke themselves!
The time of hacker ethics comes to an end. So now - aside from White Hats and Black Hats, you will have Navy Hats stating "we do this just for greater good of America".
outside contractors which demand a ridiculously high salary for this
Well sort of, but not ridiculous for the job. Very few people are capable of delivering the goods. Can you deliver? Here, you go find a zero-day exploit for each of these: Apache, IIS, Exchange, Samba. All typical OS versions must be supported, with ASLR and NX enabled. Occasional crashes are not OK. Oh, you get 18 months. Have fun!
they could just develop more offensive capabilities with the people they already have. There are hundreds of military people who could perform this task with a little training and education
OMG no. Some extremely bright people can manage to do the job with less than a Computer Science degree... for example, 3 years of MIT or Stanford. Normally it takes people with a BS degree and a decade of low-level experience, or an MS degree and a half dozen years of low-level experience.
You get to creep out everybody who ever knew you going back 10 years. The FIB (not FBI, but most people will hear "FBI") will show up at their doorstep asking about you. This includes ex-wives, inlaws, former co-workers, former landlords, former classmates, college roommates, the people who lived next door to you...
Comfortable with assemble, low level development. Device driver and kernel hacking. Embedded devs are perfect.
They have most of the baseline skills needed and can be trained up to round things out.... and very importantly probably kept their noses clean enough to get the clearance.
I think I have this job interview nailed. I called the interviewer an asshole and then stole his credit card numbers. Then I went home and slept with his daughter.
I have a particular hatred for any software that steals arbitrary peoples data. I however do not have a hatred for software that is used to take out software that steals random peoples data. Nothing is more fun than pulling out all the stops against a particular malicious person.
What would be cool, though impossible to do very effectively (don't call the huge LOIC botnets effective...), is if there was a sort of huge botnet that had an ungodly amount of people in it, opt-in only obvious, that could be used to counter the various malicious people, that would be cool. I know for a fact I could write a very effective botnet, because I have, I just won't embed it in malicious code, and I won't put anything malicious in it. I'm too smart I guess.
See, I don't know who you are. I don't know what you want. If you are looking for ransom, I can tell you I don't have money. But what I do have are a very particular set of skills; skills I have acquired over a very long career. Skills that make me a nightmare for people like you. If you let my daughter go now, that'll be the end of it. I will not look for you, I will not pursue you. But if you don't, I will look for you, I will find you, and I will kill you.
Because, you see, malicious people are HEATHEN!!!! They are HERETICS!. They use the skills provided to them by our JESUS, the great NSA, and they use it to THEIR OWN ADVANTAGE! GOD HATES THEM!
ok here's how my post went, i first paragraph was semi-serious, first sentence was definitely serious. second paragraph wasn't that serious at all, because i simply don't care. then i got bored because slashdot isn't very good now.