Pentagon Contractors Openly Post Job Listings For Offensive Hackers 149
Sparrowvsrevolution writes "In the wake of confirmation that the U.S. government was involved in the creation of Stuxnet and likely Flame, a look over job listings on defense contractor sites shows just how explicitly the Pentagon and the firms that service it are recruiting offense-oriented hackers. Northrop Grumman, Raytheon, Lockheed Martin, SAIC, and Booz Allen have all posted job ads that require skills like 'exploit development,' have titles like 'Windows Attack Developer,' or asks them to 'plan, execute, and assess an Offensive Cyberspace Operation.'"
Who better? (Score:5, Insightful)
Offensive (Score:3, Insightful)
Aren't all hackers offensive?
Re:Who better? (Score:5, Insightful)
What makes you think they're being hired for defense?
Re:day in the life of a govt hacker (Score:3, Insightful)
the only downside... can't smoke weed at work
http://www.youtube.com/watch?v=BBMtl79atFs [youtube.com]
Problem with that stuff is it doesn't make you smarter or more creative, it just makes you think you are.
Re:Microsoft must be so pleased.... (Score:2, Insightful)
And if the Linux community wants Linux to be used, they only have to make it usable.
Waiting for more than a decade...
Re:Who better? (Score:5, Insightful)
With America's preemptive warfare policy; what's the difference?
Afghanistan mujahideen (Score:5, Insightful)
I don't need to explain why training terrorists might not be the best idea for our long term interest, right?
Re:day in the life of a govt hacker (Score:5, Insightful)
Re:Who better? (Score:4, Insightful)
You don't think "defense contractors" means they only defend, do you?
Re:Who better? (Score:4, Insightful)
The overall problem with "cyber war" is that it seems like the new excuse, now that kiddie porn has kind of fizzled out and piracy is widely accepted, to lock down the internet. The only real answer is to stop having vital systems programmed by idiots connected to the internet. When most bank and government systems are less secure than a site running PHPBB (for example, using unencrypted passwords), there is a serious problem that can't be fixed by plastering it over with censorship and playing war.
Re:Who better? (Score:5, Insightful)
Who would better know how to defend against these attacks than someone who knows how to develop and implement them?
Almost anybody. Attackers are highly specialized and do not need to cover the whole or even significant parts of the protection angle. If the attacker gets in, the goal is reached. It does not matter at all that if a lot of potential other attack venues were not even touched.
For this reason, black-hats make terrible security experts for the defender side. The myth that a good attacker is a good defender is patently false in IT security (and likely in other areas as well). What a good defender needs first is to find all possible attack venues. That is complicated and requires understanding the whole system, the organization using it, the cultural environment, etc. The black-hat, on the other side, can experiment and does not really need to understand any of these, except for the tony fragment where the attack is to be launched. Even there, the black-hat can afford to fail frequently. This is fundamentally different for the defender.
Re:Microsoft must be so pleased.... (Score:2, Insightful)
After all this time, you still seem ignorant of the fact that the Siemens controllers for the centrifuges are supported only on Windows.
The choice of Windows was pushed by the contractors and the hardware selection, not Iran.