“the one thing government seldom gets is honest advice from consultants. Let’s face it, many consultants will say anything they have to in order to be called back.”
Gene Woolsey, from Real World Operations Research.
(←)
Fighting the automation paradox || Deployment θα κάνουμε φωνάζοντας "αέρα"
“the one thing government seldom gets is honest advice from consultants. Let’s face it, many consultants will say anything they have to in order to be called back.”
Gene Woolsey, from Real World Operations Research.
(←)
“Figure it out, Cliff, and you’ll amaze everyone”, Dave said.
Or, how a $0.75 imbalance can markedly change your life.
The Cuckoo’s Egg, page 5
Amazing advice from Bob Metcalfe advice on public speaking. I shamelessly copy it here:
[via]
Θυμάμαι ήμουν στο Υπουργείο Μεταφορών και αναβάθμιζα δύο μηχανήματα FreeBSD. Ένας φύλακας ήρθε τρέχοντας και είπε στο διευθυντή:
– Έπεσε ένα αεροπλάνο σε ουρανοξύστη στη Νέα Υόρκη!
– Περίεργο, είπε.
Μετά από λίγο ξαναήρθε ο φύλακας για το δεύτερο πύργο.
– Ε, αυτό μοιάζει με τρομοκρατική ενέργεια.
Θυμήθηκα τη διαφήμιση του CNN χρόνια πριν για μια συνέντευξή του Μπιν Λάντεν: America’s public enemy number one.
– Εγώ λέω να πάω προς το σπίτι.
– Να πας.
Στο λεωφορείο υπήρχαν δύο κατηγορίες ανθρώπων: Αυτοί που ήξεραν τι είχε γίνει και οι άλλοι. Τους ξεχώριζες αμέσως. Στο ραδιόφωνο άκουγα για τα υπόλοιπα αεροπλάνα και με συγκεχυμένες πληροφορίες που τα ανέβαζαν σε δέκα. Και κάπου εκεί και η συνειδητοποίηση πως ένας από τους καλύτερους φίλους μου μπορεί να ήταν εκεί. Το mail έφτασε την άλλη μέρα:
– Ela re George, eimai kala
“Strategic Cyber Security” (which is available for download) is a book that states from the very beginning that computer security has evolved from a technical discipline to a strategic concept. To this end the author tries to examine four strategic choices: IPv6, Sun Tzu‘s “Art of War“, Cyber Attack Deterrence and Cyber Arms Control. The book is written for those people who read executive summaries. As such it can be seen as a long (very long) executive summary that often repeats itself. I cannot count the times Eligible Receiver is mentioned in the book, but it is now imprinted in my brain.
There is no technical coverage of IPv6 in the book. As such, discussion of IPv6 is limited to the vast address space that it offers which will give the opportunity to eliminate NAT, thus having better attribution capabilities on unauthorized connections. It also shows big faith on IPSec deployment as a means of stopping cyber attacks. The concerns about privacy invasion with the deployment of IPv6 are also mentioned, but not specifically. In fact most such concerns can easily be debunked by now. As a purely technical solution, I feel that IPv6 does not mix well with the three other choices that are examined in the book, given the fact (that the author also notes) that IPv4 will be with us for a long (very long) period of time.
I had thought of drawing parallels between the “Art of War” and cyber security a number of times, the last being when von Clausewitz was mentioned in Daily Dave. Ten specific points are discussed which do not fit to the cyber domain.
Thanks to the book I got to learn a few things about Deterrence Theory. Deterrence is based on two axis: Denial and Punishment. Denial means that those who control the strategic technology will deny you access to it, while punishment means that should you develop said strategic advantage countermeasures for other strategic players will be enforced.
The final choice discussed in the book, is the examination of whether a Cyber Arms Treaty can have some positive results (It so happens that there’s a wikileak relevant to the matter. If others exist, a more systematic treatment of these should take place). To examine the possible success or failure of such an agreement, the highly successful Chemical Weapons Convention is used. From the comparison there seems to be little room for success for limiting the development and use of “cyber arms”.
I found chapter 10 of the book the most interesting. It makes use of the Decision Making Trial and Evaluation Laboratory (DEMATEL) method in order to compare rank the four strategic choices. Unfortunately it is not very easy to locate online material about the original DEMATEL method, however there’s lots of available literature (and a lot of it by the Chinese) on DEMATEL variations used in health, agriculture and other areas.
To me learning about DEMATEL was the one thing I got from the book. The rest of it while interesting, was not equally appealing.
I recently observed while discussing a harmless incident related to someone I know, that how breaches are dealt with may be viewed through the five stages of grief model.
I was planning on writing more on my thoughts on this, but it seems that Jeremiah Grossman beat me to it since 2007. My version would be slightly different:
| Denial | “We never got hacked.” |
| Anger | “How the heck did this get so bad?!?!?” |
| Bargaining | “Is it possible that it is not a hack?” |
| Depression | “We do not have time to rebuild; keep it running as it is.” |
| Acceptance | “We got hacked.”, spoken in pubic. |
I copy from “Cyberwar: a Whole New Quagmire” written by Markus J. Ranum (emphasis mine):
“The best defense against something like Stuxnet could not possibly be a strong offense – how can you pre-empt something unknown that was released without attribution? Stuxnet was exactly adequate for its job. How do you prevent such a thing from working on you? You do exactly the opposite of what we’re doing everyplace: you in-house security, in-house IT, and begin to build your infrastructure so that there are unpredictable and unknown barriers within it, including critical sections that are air-gapped and closely monitored. Yes, that is expensive and inconvenient. The question is whether the alternative is even more expensive and inconvenient.”
And that is why outsourced government clouds will not work. We only have to wait until the first major event to see this. The lean behavior is to build people so as to control the infrastructure. Short term cost cutting practices are for bonus hunters who will be long gone (disclaiming any responsibility) when disaster strikes.
Won’t “free market” advocates love this, I wonder.
Well, having responsibility without authority is stressful enough to cause that. It has been written before, but this graph from TimeBack Management says it better:

It also happens that 3/4 of this graph explain typical Public Sector employee behavior.
Comments from both users and fellow system administrators are welcome.