Slashdot Mirror


Report: DHS Failing On Cybersecurity

chicksdaddy writes: It's always interesting to listen to what politicians say on their way out of office — after the pressure to get re-elected and say "on message" has been lifted. Eisenhower's historic farewell address in 1961 warned Americans about the influence of the Military-Industrial Complex. Twenty years later, Jimmy Carter warned of the distorting influence of "single-issue groups and special interest organizations" on the political process. And, this week, outgoing Sen. Tom Coburn (R-OK) used his final days in office to issue a blistering report on the Department of Homeland Security. Coburn argued that DHS was failing on each of its five, critical missions, among them: cyber security.

The report, "A Review of the Department of Homeland Security's Missions and Performance (PDF)," was released on Saturday. In it, the outgoing Senator said that DHS's strategy and programs "are unlikely to protect us from the adversaries that pose the greatest cybersecurity threat."

Despite spending $700 million annually on a range of cybersecurity programs, Coburn said it is hard to know whether the Department's efforts to assist the private sector in identifying, mitigating or remediating cyber incidents provide "significant value" or are worth the expense. DHS programs are still heavily weighted towards software vulnerability mitigation, Coburn says, an activity that "will not protect the nation from the most sophisticated attacks and cybersecurity threats."

68 comments

  1. No it isn't! by Anonymous Coward · · Score: 3, Insightful

    It's doing exactly what it was intended to do: bilk appropriations to well connected people and Corporations in the name of National Security. If anyone EVER thought it was something other than that, they're far too naive for the present reality!

    1. Re:No it isn't! by Required+Snark · · Score: 2

      Remember, the real name of DHS is DHP: Department of Homland Pork.

      --
      Why is Snark Required?
    2. Re:No it isn't! by Anonymous Coward · · Score: 0

      Hah Homland? Can't even get your snark right.

    3. Re:No it isn't! by Livius · · Score: 0

      Coburn is not revealing anything, he's simply a continuing part of the disinformation campaign that misinforms the public as to the true purpose of the Department of Homeland Security.

      Hard to believe, but there's still quite a few people out there fooled by it all.

    4. Re:No it isn't! by Noah+Haders · · Score: 3, Funny

      Department of Hamland Pork?

    5. Re:No it isn't! by Opportunist · · Score: 1

      Uh... care to elaborate? It somehow doesn't make a lot of sense that way.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    6. Re:No it isn't! by Anonymous Coward · · Score: 0

      Exactly, this is a scathing review of DHS from a member of Congress which is kind of rare. You'd think Slashdot would be going freaking nuts about jumping behind this. Instead they're all nitpicking it to death because it's from a Republican.

      Can't even use the weapons of their enemies. What a disgrace.

    7. Re:No it isn't! by Cardoor · · Score: 1

      you're forgetting providing 'jobs' for those who would be otherwise disenfranchised, and liable to cause problems.

    8. Re:No it isn't! by Anonymous Coward · · Score: 0

      If they did, then /dotters would have to change their stance on the NSA and admit that spying -unethical or not- is still actually an effective way of obtaining information, and curtailing it would be rendering DHS ineffective, unable to predict and prevent future attacks.
      Only time will truly tell if all this Homeland stuff is really security theater pork, or actually preventing attacks of any kind; not just terrorists, but cyberattacks or nation sponsored attacks.
      There's a fine line between paranoia and complacency. Complacency is what enabled 9/11 to happen. Paranoia is what enabled eroding of privacy to happen.

  2. Consider the source by ISoldat53 · · Score: 1, Insightful

    I would believe this more if it weren't coming from Tom Coburn.

    1. Re:Consider the source by Anonymous Coward · · Score: 3, Insightful

      Tom Coburn isn't all bad. I believe that people with medical degrees who have taken the hypocratic oath make pretty good leaders. They often seem genuinely concerned with the welfare of people. Lawyers often get too involved with winning against the adversary. Tom definitely can grandstand and play politics, but he also seems to genuinely believe in what he is doing and care about people.

    2. Re:Consider the source by Anonymous Coward · · Score: 0

      Care to expound on your statement? Or is it just some knee-jerk liberal objection to anything a conservative politician says or does?

    3. Re:Consider the source by blue+trane · · Score: 1

      Coburn cares more about figures in a ledger book than about people suffering needlessly just so his budget looks pretty to him.

    4. Re:Consider the source by blue+trane · · Score: 1

      Coburn's fixation on budget deficits is absolutely contrary to humanitarian compassion. Deficits don't matter, as Reagan proved. To cut food stamps and suicide prevention programs in the name of "pay-go" is morally, ethically, and economically wrong.

    5. Re:Consider the source by Anonymous Coward · · Score: 0

      Coburn's fixation on budget deficits is absolutely contrary to humanitarian compassion. Deficits don't matter, as Reagan proved. To cut food stamps and suicide prevention programs in the name of "pay-go" is morally, ethically, and economically wrong.

      ORLY?

      Ask Greece.

      Or Detroit.

    6. Re:Consider the source by Opportunist · · Score: 1

      I can't speak for Detroit, but Greece I know fairly well. If you make a country cut back on everything that could keep the inland purchasing power from faltering completely (which it now did) but force it to honor its weapon purchases (or Germany would've had to find someone else to buy its subs), you should not wonder if the economy gets a wee bit lopsided.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    7. Re:Consider the source by Anonymous Coward · · Score: 0

      He was also against waste in government. Granted, some of his positions on waste were not well founded, see http://www.livescience.com/484..., but a lot of the things he pointed to were wasteful and unnecessary. Who can be for government waste? Is government waste a humanitarian thing? Paying people to do stupid stuff? I agree that cutting food stamps to keep tax breaks for the uber wealthy is morally, ethically, and economically wrong, but there is more to Dr. Coburn than his party line votes.

    8. Re:Consider the source by Anonymous Coward · · Score: 0

      ... but force it to honor its weapon purchases ...

      This is problem with cost-cutting policies like Austerity: The government has to honour their business deals so they can't spend less on daily business. What they can spend less money on, is people. So when people have less money, austerity ensures the government doesn't provide a safety net.

      ... wonder if the economy gets a wee bit lopsided.

      The Australian economy has zero growth so something must be done. The conservative government though, wants to pay the deficit and spend a few billion dollars more on 'national security'. So their planned solution is simple: Stop paying welfare. We've all seen the welfare system at work: The ethnic minorities are guaranteed their busy-work projects. They can't throw babies and single parents onto the street. They probably can't do much to retirees and pensioners. That leaves the diseased and disabled, the homeless and the unemployed to suffer this policy. A portion of parliament, thankfully, isn't agreeing with this plan.

    9. Re:Consider the source by DarkOx · · Score: 1

      Deficits don't matter, as Reagan proved

      Reagan proved nothing of the sort. Reagan proved nothing of the sort. He proved short term deficits are okay if anything and we pretty much always knew that.

      Reagan's spending was in the context of a very different world. There was literally no economy or currency that could provide the secure wealth store the US and dollar offered at the time. Today there is plenty of mostly safe sovereign debt to buy out there. There was no possibility of the first world trading oil in anything but the dollar; while still along way off its imaginable today. Most importantly however there was a definable end in sight, eventually the USSR would be defeated at which time some of the most expensive weapons efforts could be scaled back, after which the budget would balance.

      That brings us to the late Bush and Clinton economic boom, what was one of the characteristics of that, oh yes the budget nearly balanced, and if you did some really fucking creative accounting with lots of spin could even claim a surplus! So if anything Reagan might have proven deficits DO matter.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    10. Re:Consider the source by kilfarsnar · · Score: 1

      Coburn's fixation on budget deficits is absolutely contrary to humanitarian compassion. Deficits don't matter, as Reagan proved. To cut food stamps and suicide prevention programs in the name of "pay-go" is morally, ethically, and economically wrong.

      ORLY?

      Ask Greece.

      Or Detroit.

      Unlike Greece or Detroit, the federal government can print its own currency. Thus it is not constrained by its ability to tax or borrow. It literally has all the money it needs all the time. So it is correct that deficits don't matter. We could pay off the entire national debt tomorrow if we chose to. I'm not saying we should; it would have other ramifications. But the idea that we just don't have the money for a given project or program is just not true. The US cannot go bankrupt and has all the money it needs.

      --
      "What the American public doesn't know is what makes them the American public." -Ray Zalinsky (Tommy Boy)
    11. Re:Consider the source by ISoldat53 · · Score: 1

      No and yes

  3. DHS fails everything...except trampling our rights by Anonymous Coward · · Score: 0

    This is the agency responsible for helping to militarize our civilian law enforcement, full-body nudie scanners and the 100-mile 'Constitution Free Zone.' Mission Accomplished

  4. Were good at spying on ourselves by Anonymous Coward · · Score: 1

    Just ask the NSA on how good we are at spying on ourselves. But we seem to be looking at ourselves as the biggest threats when in fact our enemies have been accruing more and more technology and intelligence to attack what would hurt the US the most, commerce. People have said for decades that the US is too cozy with China and that makes us vulnerable. The US used to make almost everything it consumed in commerce and now we have lost that edge and even in technology and its security we seem destine to ignore the gorilla in the room. DHS is another waste of a government agency, created by politicians to sooth the American people. We have a military, CIA, FBI, Boarder Patrol, Local and State Police, National Guard, Coast Guard, and other well oiled national defense organizations. Did we need a Department of Homeland Security? NO. What we needed was to beef up our long standing defenses and make offensive moves to thwart attacks. Let's not be stupid and wait for our homeland to be attacked. Let's make sure they won't attack us by using measured attacks, be it electronic, physical, or restrictions to make sure we are protected. Another agency we did not need.

  5. Gee, wonder why by Snotnose · · Score: 2

    Take a bunch of overly bureaucratic organizations that have needed weeding out for decades, create a huge new bureaucracy to oversee them all, and WTF can you expect?

    / Bush was the worst president in my 50+ year lifetime
    // Homeland security never made any sense to me
    /// I vote Republican prolly 70% of the time

    1. Re:Gee, wonder why by oDDmON+oUT · · Score: 1

      You sir have restored my faith in humanity.

      --
      Some days it's just not worth
      chewing through my restraints.
    2. Re:Gee, wonder why by Anonymous Coward · · Score: 0

      I'm curious, how would you rank the presidents during your tenure here? I'm only in my mid-30s, but my rank (worst to best) would be Obama, Carter, Bush Jr, Clinton, Bush Sr, Reagan.

      FWIW, my all-time least favorite president of the last century is FDR. No other president single-handedly did more to subvert the Constitution in such a short time.

    3. Re:Gee, wonder why by Anonymous Coward · · Score: 0

      Bush jr, Obama, Carter , Bush sr, Reagan then Clinton

    4. Re:Gee, wonder why by AHuxley · · Score: 1

      It was such a good idea. Replace all the well paid union workers sitting around at small and remote sites with new computer systems and cheap networks.
      Less staff cost, less union workers and a few experts could care for a larger system of networked equipment over wide areas.
      So a lot of once secure air gapped sites where connected with low cost networks and everything seemed ok. Fewer on site workers, the same oversight and maintenance.
      Now for the next huge boondoggle. Remote site security upgrades. Shared logs to see who is trying to map the networks.
      What the "huge new bureaucracy" needs now is news "stories" about ip ranges and malware from distant regimes and their educated experts.
      All the new domestic upgrades and staff with a new legal system for the growing cyber bureaucracy :)
      For all the new cyber costs, a human team back on site with less networks will not be so expensive soon.

      --
      Domestic spying is now "Benign Information Gathering"
    5. Re:Gee, wonder why by Anonymous Coward · · Score: 1

      What's the ranking criteria?

      By most criteria, Bush Jr is the worst president of my lifetime. If you're a billionaire, maybe he ranks better because of who he appointed to the supreme court. But, on almost all counts, he was disastrously bad, and everything he touched turned to shit.

      I guess I'd have to begrudgingly rank Clinton best, although I don't like him or Hillary at all. But, the economy did pretty well under his watch, and he didn't run up a lot of debt.

      I really don't get the Obama hate. I'd rank him in the middle, because he hasn't done anything super great, but he hasn't made any huge mistakes, either. He was a steady hand with middle-of-the-road policies during a very trying time. All the winging about Obama destroying America seems like pure fantasy to me.

      I'm curious, what do you think would have happened to America without the new deal? I wasn't alive then, but from what I've read, the country was teetering on revolution, and the new deal might have been what brought us back from that cliff.

    6. Re:Gee, wonder why by Opportunist · · Score: 1

      Looking back, the US had a few good, a few bad, a few shining and a few shady characters as presidents. I liked Bush Sr., well, ok, I did not like him, but his politics was fairly sensible. I loathed Bush Jr, not just for his questionable politics and HORRIBLE financial decisions, but mostly for what he did to the image of the US. He turned the general sentiment towards the US of one of admiration and aspiration, where the US was THE country, where everything goes and everything is possible, into one of ridicule and shame, where the US are the butt of very crude jokes along with the US voters being seen as a bunch of idiots for not only voting him in once but twice. If that administration can claim any kind of achievement, then to wash away decades of built up admiration and reverence within just 8 years.

      But still, nothing in the past few decades can hold a candle to Eisenhower.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  6. Lies by Anonymous Coward · · Score: 1

    People fail to realize that if it wasn't for the Department of Homeland Security, Al Qaeda would be flying airplanes into buildings every single day. Mind you, I wouldn't shed a tear if a million white people died, but just think of all the African-Americans that the DHS is protecting. God bless the DHS.

  7. Quiet! They might be listening.... by freeze128 · · Score: 1

    The *LAST* thing we need is DHS thinking that they know security better than computer professionals. This article is just an invitation to get DHS to install "protection" software onto our PCs, or otherwise screw up the internet.

  8. What does Coburn know about infosec? by bouldin · · Score: 2

    Why does anybody care what a 66-year-old doctor from Wyoming thinks about information security?

    The report criticizes the DHS as ineffective at "cybersecurity" because of.. zero days or something.

    It's clear that neither Coburn, nor the author of the report, understands infosec or how it is different from kinetic war. You can't amass troops or use force. It's very difficult to even know who attacked you.

    You can do something like building defensive lines, but that's exactly what the report criticizes.

    1. Re:What does Coburn know about infosec? by Anonymous Coward · · Score: 0

      The only thing that's clear from your post is that you didn't read the report.

    2. Re:What does Coburn know about infosec? by bouldin · · Score: 1

      I read the infosec part. The report criticizes DHS for concentrating on vulnerability management and using signature-based detection, which it suggests is not worthwhile because of zero-day vulnerabilities. It criticized the DHS for not following best practices itself.

      That criticism is fair, but also applies to almost all infosec efforts, both in the public and private sector.

      The only suggestion offered by the report was to cite a "cybersecurity expert" who says we should focus on deterrence. The report did not explain what deterrence means in this context. What are they suggesting? We hang malware to death to set an example? We sanction North Korea every time we think maybe they sponsored an attack that we traced back to China? The metaphor to warfare does not hold, and that failure is lost on the author[s] of the report. They don't get it.

    3. Re:What does Coburn know about infosec? by Anonymous Coward · · Score: 0

      What are they suggesting?

      Air-dropping free CD/DVDs of Windows ME over North Korea with copies of the Interview?

    4. Re:What does Coburn know about infosec? by Fire_Wraith · · Score: 1

      DHS isn't very effective at cybersecurity - but not for the reasons he cites (something about stopped clocks being right twice a day comes to mind).

      First, when it comes to 'cybersecurity', they have no actual authority. The best they can do is suggest and advise. I'm not saying they should have authority to make anyone fix vulnerabilities or whatever, I'm just pointing out that you can't really expect that they'll be effective at protecting X if the people in charge of X don't have to listen to a word they say. It's like saying, "here, defend these networks, but you have to ask them politely to tell you what their problems are, and when you point out the problems, they don't have to fix it if they don't want to." Again, that's not to say they should be granted intrusive authority, but we also shouldn't expect them to act as if they can.

      Second is quality of talent. They're fighting an uphill battle in terms of personnel. They have to compete against both the private sector and other agencies in the government/national security business. Would you rather work for DHS or Google? For DHS or the NSA? Etc... Even if they hire people with lots of potential and train them up, those people will go find something better before long. There was an article a month or two back (I want to say it was in the Washington Post) that talked about exactly that problem - DHS couldn't keep anybody, because the best and brightest quickly jumped ship to go someplace better (either in pay, prestige, other compensation, or something on those lines).

  9. they are doing some things right, like free classe by raymorris · · Score: 1

    You won't normally find me talking about the federal government being very effective at anything, but they have done some things right with cyber security. For example, their series of free online classes covering cyber security is much better than I would have expected.

    Of course they did contract that out to a STATE agency, and a rather unique one that whose budget process and operations is more like a private business - if people don't like the product (the classes), the agency doesn't get paid. So maybe I can acknowledge the good results without it being political heresy. :)

    Disclaimer - I work nearby the cyber security program that made the classes, so I may not be objective. Then again, I don't praise most people I work with. I was expecting the classes to not be very good, and I was genuinely surprised at how good they are.

  10. we need more by Anonymous Coward · · Score: 0

    Typical politician - his comments could be interpreted to mean almost anything. The effort is wasted. We're not doing enough. Who knows?

  11. Dear Taxpayer? by Anonymous Coward · · Score: 0

    Is that pretty standard? Doesn't that like rule out like 46% of the population or some such? Shouldn't he have instead began the report with "Dear Voter"?

    1. Re:Dear Taxpayer? by kilfarsnar · · Score: 1

      That's even less of the population.

      --
      "What the American public doesn't know is what makes them the American public." -Ray Zalinsky (Tommy Boy)
  12. IT security is not the DHS's mandate by Anonymous Coward · · Score: 0

    That would be the Defense Security Service.

    The Department of Homeland Security is about physical security.

    1. Re:IT security is not the DHS's mandate by gmhowell · · Score: 1

      Wrong.

      DoD: military
      DHS: civilian

      --
      Jesus was all right but his disciples were thick and ordinary. -John Lennon
  13. What a waste by LessThanObvious · · Score: 1

    "Senator arguing that DHSâ(TM)s $700 million cybersecurity budget could better be spent elsewhere."

    A $700 million budget alone is evidence that they are way off target. The mission should be fairly narrow and focused and require only relatively small staff. The private sector does fine in most security area's. They just need to fill the gaps that are outside the scope of the private sector. Pick 8-10 real priorities do those really well and just cut everything else. Considering the FBI/NSA isn't even part of their budget, $700 million is just obscene. What exactly do they need to do that couldn't be done with a staff of two or three hundred good people and a $150-$200 million budget? WTF

    1. Re:What a waste by TheCarp · · Score: 1

      > What exactly do they need to do that couldn't be done with a staff of two or
      > three hundred good people and a $150-$200 million budget? WTF

      create jobs. That is really all it has been about for a while. Shit go all the way back to prohibition and we got beginings of the drug war partially from efforts made by people who were basically looking to lose their jobs with nothing to do now that alcohol was legal.

      Their role is to create jobs and use as much budget as possible because the more they spread around the cake, the more support they will get from the people they spend that money on.

      You have to realize, that for every few people who took Eisenhower's speech as a warning, there were others writing it down as a proven strategy that is working and should be used elsewhere. The more jobs you create, the more cake you hand out, the more secure your job is.

      It doesn't even hardly matter if what you do works, its almost better if it doesn't because that will just be because you need to do more of it.

      --
      "I opened my eyes, and everything went dark again"
  14. As the saying goes... by langelgjm · · Score: 1

    Even a stopped clock is right twice a day.

    --
    "Anyone who [rips a CD] is probably engaging in copyright infringement." - David O. Carson
    1. Re:As the saying goes... by Opportunist · · Score: 1

      And a stopped brain has a bright idea twice a day?

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  15. Its all about talent by Anonymous Coward · · Score: 0

    What talented coder in his right mind would want to work for the government ? Its not that the government is bad, but the working environment the government mentality creates would be utterly soul-crushing.

    1. Re:Its all about talent by Opportunist · · Score: 1

      I tried. I failed. Bureaucracy and "hacking" does not mix. It just does not work out. And for the same reason it is fairly nontrivial to establish good IT security in a corporate environment, for they are also weighed down by bureaucracy.

      It's asymmetric warfare at its finest. On the plus side you have lots of funds, highest technology available, even to some degree the ability to change laws in your favor and law enforcement on your side, sometimes to the point where you may direct them. On the downside you have a reaction speed of a snail, a ton of dead weight to lug about no matter what you want to do and people in command who have zero idea what's going on but demand to have a say. That's you, the corporation, or the government.

      On the other hand you have the attacker. Usually far less well funded, using whatever tech he can get his hands on, with laws and law enforcement working against him. On the plus side he can react instantly without any overhead and without any interference from idiots.

      Frankly, my money would be on the second guy. Funding means little if most of the tools you need to attack are free (or you don't care that you don't pay for them). It matters little if law enforcement is working against you if they don't care too much about (or cannot care about it altogether due to a lack of knowledge/equipment) "cyber threats". So what's left for them is all the goodies with little to hold them back.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  16. You Have To Apply Yourself, DHS by Anonymous Coward · · Score: 0

    DHS follows the FISMA model, which means they utilize the NIST Special Publications 800 series for IT governance and security. In particular, the NIST SP800-53 controls are the best I've ever seen in my 15+ year cybersecurity career. If you put the time and effort into assuring your systems and policies meets these controls, and follow the additional guidelines for continuous monitoring, you're going to be about as safe as anyone can be.

    The operative phrase is "put the time and effort into assuring your systems and policies meet these controls."

    That seems to be where DHS is falling short, according to the cited reports. The tools and knowledge are there, but they're useless if not applied & overseen.

    1. Re:You Have To Apply Yourself, DHS by Anonymous Coward · · Score: 0

      So far, yours is the only post on this topic that is both informative and correct. Bravo!

  17. Everytime the word "Homeland" is used by 7-Vodka · · Score: 1

    Everytime the word "Homeland" is used, we should post reminders of how eerily familiar these Sophistries are to Hitler's own:

    Motherland, homeland, fatherland terrorism, terror cells. None of this shit is new. The communists did it too.

    --

    Liberty.

    1. Re:Everytime the word "Homeland" is used by sconeu · · Score: 1

      Remember, KGB stood for "Ministry for State Security".
      Sounds a hell of a lot like DHS, doesn't it?

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
  18. Security Offsets by Anonymous Coward · · Score: 0

    I wonder if this $700million helps float the IT budgets of some corporations...

    It's not hard to imagine a company firing most of its IT staff because it can claim "Security Stamps" from the DHS.

  19. stopped clock right twice a day by Anonymous Coward · · Score: 0

    So DHS pretty much exemplifies all that is wrong with our government. And I think Sen Coburn is dead on on because DHS can do little to protect us from sophisticated cyber attacks. But he's right to the sense of a stopped clock is correct every so many hours sort of way.

    Vulnerability mitigation is part of a successful hardening of our IT infrastructure. Replacing Windows with Linux on workstations, telnet with ssh, wireless with wire... this stuff does make cyber crime harder and thus does have a preventative effect. Not sure what $700million buys anymore after government porking up, probably a fancy presentation or two on using good passwords from MBAs at a long time defense contractor... but it is not going to stop state sponsered cyber attacks. The only way to stop cyber attacks is to unplug from the rest of the world. But the hardening thing it does make a difference just like replacing hardware, patching system, running backups and testing backups. Deterrence on the other hand won't stop anything.

  20. DUH! by frovingslosh · · Score: 1

    In it, the outgoing Senator said that DHS's strategy and programs "are unlikely to protect us from the adversaries that pose the greatest cybersecurity threat."

    DUH! DHS and the NSA are the greatest threats to American cybersecurity.

    --
    I'm an American. I love this country and the freedoms that we used to have.
  21. Am I being paranoid? by WaffleMonster · · Score: 1

    Every time I hear bureaucrats rumbling about "cyber security" only thing that comes to mind are schemes to legalize spying "for our own good" ... Still seeing politicians getting airtime rambling about legislation to indemnify corporations for "sharing" information with the government not letting the Sony opportunity go to waste.

    The military industrial complex has countless billions of dollars at its disposal and the only constructive thing I've seen out if it is US-CERT mailing list which for the most part delivers very little we didn't hear somewhere else first.

    Most everything from what I have heard and seen from DHSs own website is structured for defense after the fact or screwing around with ridiculous hacker wargames as if cyberspace was somehow meaningfully analogous to meatspace.

    They have all of the open source code, they have Microsoft source code, they can probably get source code from others if they asked nicely enough... They could use some of their money to find and plug holes before everyone gets owned or fund R&D efforts to improve the state of security technology... instead it is all reactionary masturbation.

  22. Re:they are doing some things right, like free cla by Anonymous Coward · · Score: 0

    You fail my test, everytime, "Forrest" -> http://slashdot.org/comments.p...

    APK

  23. yeah by markhahn · · Score: 1

    obscure, poorly-defined, well-funded, with no vested constituency. what could possibly go wrong.

  24. He meant us right? by phazemstr · · Score: 0

    "the outgoing Senator said that DHS's strategy and programs "are unlikely to protect us from the adversaries that pose the greatest cybersecurity threat." By that he means American civilians pose the greatest threat, right?

    --
    Nothing to see.
  25. Wait, what... $700M? by sigmabody · · Score: 1

    Hold on... I work in the private sector in info sec. DHS is nominally spending $700M annually on trying to provide value for the private sector? Huh? DHS doesn't provide value for anyone, as far as I know, much less the private sector. What kind of hallucinatory BS is this?

    1. Re:Wait, what... $700M? by l0n3s0m3phr34k · · Score: 1

      "What kind of hallucinatory BS is this?" don't know, but I'll bet that's where the $700M went. LSD isn't $4 a hit these days, even shrooms are at $15-$25 per gram. Hallucination-inducing pharmaceuticals aren't cheap.

    2. Re:Wait, what... $700M? by Anonymous Coward · · Score: 0

      The kind you get when you support either of the two dominant political parties.

  26. No surprise by gweihir · · Score: 1

    The thing is, the task of the Department for State Security (their true designation) is not tasked with protecting any citizens or cooperations. Their task is to protect the state and its bureaucracy, by funneling billions of dollars to people with the "right" beliefs. And, as the budget numbers show, they are not failing at that at all.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.