this post was submitted on 07 May 2025
40 points (100.0% liked)

United States | News & Politics

3111 readers
547 users here now

Welcome to !usa@midwest.social, where you can share and converse about the different things happening all over/about the United States.

If you’re interested in participating, please subscribe.

Rules

Be respectful and civil. No racism/bigotry/hateful speech.

Post anything related to the United States.

founded 2 years ago
MODERATORS
all 8 comments
sorted by: hot top controversial new old
[–] thebardingreen@lemmy.starlightkel.xyz 35 points 2 months ago (1 children)

Having done cyber security consulting for space startups (which are ALL DoD adjacent), the worst perpetrators of bad security practices, shadow IT and poor data hygiene are... drum roll...

The business guys in senior management.

What happened with Hegseth and Signal wasn't a shock to me. If you put someone like Hegseth in charge of something like the DoD, it's exactly what I would expect to happen.

[–] Eat_Your_Paisley@lemm.ee 6 points 2 months ago

I agree but DoD needs to bring the FOSS software out of the server room.

[–] Semi_Hemi_Demigod@lemmy.world 11 points 2 months ago

"The fact that the department currently lacks visibility into the origins and security of software code hampers software security assurance."

These idiots don’t know what an SBOM is

[–] Ascrod@midwest.social 8 points 2 months ago (2 children)

If anything, I would think DoD has a vested interedt in protecting and supporting open source software so shit like xzutils doesn't happen again.

They can’t secretly compel the devs to add backdoors to their FOSS.

I mean, they could try. But that dead canary would be discovered as soon as anyone bothered to check the merge history.

[–] Eldritch@lemmy.world 4 points 2 months ago

They don't bribe or give kickbacks. So there is no value in them for corrupt fascists.

[–] miguel@fedia.io 1 points 2 months ago