When Were They Not?

All IT Jobs Are Cybersecurity Jobs Now goes the headline on a recent Wall Street Journal article, and the subhead reads The rise of cyberthreats means that the people once assigned to setting up computers and email servers must now treat security as top priority.

It’s like these folks—both in the IT arena and in the reporting media—have just had an epiphany.

The global “WannaCry” ransomware attack that peaked last week, and has affected at least 200,000 computers in 150 countries, as well as the growing threat of Adylkuzz, another new piece of malware, illustrate a basic problem that will only become more pressing as ever more of our systems become connected: the internet wasn’t designed with security in mind, and dealing with that reality isn’t cheap or easy.

No, it wasn’t.  But it’s not the Internet that’s at the heart of these failures.  It’s the company connections to the Internet, and the corporate human employees who aren’t being trained in how to handle the company’s connection to the Internet that is at the heart of these failures.  IT has—or should have had—security at its heart from the time the first companies connected themselves to the Internet.

Even if nation-level espionage might not have been on the minds of private enterprise, the proprietary nature of company information and the fact of corporate espionage are as old as corporations.

Christopher Mims, in his article at the link, offered some sound advice for today.  That the advice should have been obvious yesterday in no way invalidates it for today.

  1. Retrain IT staff on security—or replace them. In today’s world of ever-multiplying threats and dependence on connected assets, all IT staff must now be cybersecurity staff first.

Indeed.

  1. Push everything to the cloud. It used to be the job of IT personnel was to build and maintain the tools employees need. Now, pretty much anything can be done better with a cloud-based service.

I disagree with this.  The cloud is no more securable than a corporate’s internal network—and when (not if) the cloud gets hacked, it won’t be only one company’s stuff that gets stolen or held hostage.  Even if it’s only a company’s internal cloud that gets hacked, the whole of the company’s innards get exposed.

  1. New IT investment will need baked-in security.

Can I get an amen, brothers and sisters?

It Just Keeps Getting Better and Better

…or worse and worse, depending on your perspective.  Not only is the Veterans Administration continuing to make bad/false/improper payments, they seem to be getting acceleratingly worse about it.  The Veterans Affairs Office of Inspector General reported that the VA made $5 billion in “improper” payments in 2015, and then while that drew attention, the VA increased their improper payouts to $5.5 billion in 2016.

To show how terrible the rates can be, here are some data from James Clark at the above link:

  • the VA Community Care had 75% of their payments as “improper” payments in 2016
  • the Purchased Long Term Services and Support 69% of their payments as “improper” in 2016

You read that right: three out of four of the Community Care’s payouts were wrong, and over two-thirds of PLTS&S’ payouts were…erroneous, and they’re getting worse.  The prior year, those payout rates were “only” 54.77% and 59.14%, respectively.

Since the VA empirically no interest in cleaning up its act, since it insists on wasting money our veterans need for their care, it’s time to disband this miserable excuse for an institution and commit its budget to vouchers for our vets.

No more delay by Congress.

Veteranos Administratio delende est.

The PRC and Northern Korea

Harry Kazianis tried to explain, in his Real Clear World piece, why the People’s Republic of China “won’t solve” the northern Korea crisis for us.  It’s complicated for the PRC, he said.

He [Kazianis’ carefully unidentified “Chinese scholar” and “retired official of the People’s Liberation Army”] pressed his case, noting, “look at this problem from where I sit in Beijing. I see a world of trouble when it comes to North Korea. I see war. I see death. I see superpower showdowns. We must all agree we don’t want this. Yes, nuclear weapons are bad, but North Korea could create far more trouble than you realize, and China would have to deal with most of it.”

Kazianis then dragged out a couple of bromides that have been arguing against doing anything serious about northern Korea, one maintaining that a desperate Baby Kim, with his energy imports reduced, would start a nuclear war if we got serious; the other insisting that, with northern Korea’s food imports reduced, a desperate population would riot—and a failed coup would lead to civil war that would become nuclear and involve the PRC, the Republic of Korea, Japan, and the US.

Kazianis ignored a simple fact, though.  Baby Kim is going to use his nuclear weapons, either for blackmail or for actual strikes, as soon as he can deliver them.  He’s intimated as much often.

If Kazianis’ unidentified, anonymous source actually exists, that just puts a premium on the PRC getting started.  Even if this “source” does not, the principle and its outcome remain the same: Baby Kim is going to do what he’s going to do unless overt, serious steps are taken to deprive him of the tools with which to do them.

Handling Classified

FBI Director James Comey had this about Huma Abedin and her role in the ex-Secretary of State Hillary Clinton (D) classified email scandal:

Somehow, her [Clinton’s] emails were being forwarded to Anthony Weiner, including classified information.  His then-spouse, Huma Abedin, appears to have had a regular practice of forwarding emails to him for him to print out for her, so she could deliver them to the secretary of state.

Comey justified his lack of action with this:

We didn’t have any indication that she had a sense of what she was doing was in violation of the law[.]

There is, however, no requirement for mens rea under the relevant law; if nothing else Abedin’s actions fit the law’s gross negligence felony charactistic.

With such a bold, declarative statement about what Abedin was doing, then, I have to wonder why there’s been no indictment and subsequent prosecution.

Probably for the same reason he declined to bring a case against Clinton after having said her actions were excessively careless: it’s not politically expedient.

Military Academies as Professional Sports Farm Teams

Or not.  Secretary of Defense James Mattis has reversed an Obama administration late 2016 move that

allowed academy students with exceptional sports talent to bypass active-duty and serve out their time in the military reserves to play in professional leagues.

Dana White, Pentagon spokesman, on the matter:

Our military academies exist to develop future officers who enhance the readiness and the lethality of our military services.  Graduates enjoy the extraordinary benefit of a military academy education at taxpayer expense.

Unfortunately, the new policy still lets these Academy-trained officers to apply for a waiver after just two years on active duty.  An Academy grad, like ROTC grads, normally have rather longer commitments.  An Air Force Academy graduate, for instance, must on entering the Academy

accept an appointment and serve as a commissioned officer in the Air Force for at least eight years after graduation, five of which must be active duty and the remainder can be served as inactive reserve. You will become eligible to request a separation from the Air Force after five years of service.

Mattis’ move is a good start, but Academy graduates should serve their full commitment, not just two years of it.

Having honored their commitment, only then should they be able to move on. Special treatment is uncalled for.

You’d have thought that to be obvious.