• UnderpantsWeevil@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    6
    ·
    edit-2
    3 days ago

    U.S. personnel with security clearances supervise foreign engineers, including those in China

    Again, working on a codebase doesn’t give you access to the production systems. Neither does being Chinese affect whether you are a reliable third party contractor.

    If the workers were supervised and the supervisors were competent, there was no real security risk. Both of those are the big “Ifs” though. And that’s why doing layers of outsourcing creates risks regardless of who you’re outsourcing to.

    • Feyd@programming.dev
      link
      fedilink
      English
      arrow-up
      11
      ·
      3 days ago

      The supervisors did not have the expertise to know what the foreign workers were doing, otherwise there would not have had to be 2 workers in the first place. And the foreign workers were not just writing code - they were doing sysadmin. On DoD systems.

      I don’t know how to make any more clear to you but it’s completely obvious to anyone that actually understands these things that this was terrible opsec, and obviously not how any reasonable person would expect a DoD contract to be managed.

      • UnderpantsWeevil@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        The supervisors did not have the expertise to know what the foreign workers were doing

        If that’s the case, then the work should be in house