News: 1630692840

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

US Air Force chief software officer quits after launching Hellfire missile of a LinkedIn post at his former bosses

(2021/09/03)


The US Air Force's first ever chief software officer has quit the job after branding it "probably the most challenging and infuriating of my entire career" in a remarkably candid blog post.

Nicolas Chaillan's impressively blunt leaving note, which he posted to his LinkedIn profile, castigated USAF senior hierarchy for failing to prioritise basic IT issues, saying: "A lack of response and alignment is certainly a contributor to my accelerated exit."

Chaillan took on his chief software officer role in May 2019, having previously worked at the US Department of Defense rolling out DevSecOps practices to the American military. Before that he founded two companies.

[1]

In his [2]missive , Chaillan also singled out a part of military culture that features in both the US and the UK: the practice of appointing mid-ranking generalist officers to run specialist projects.

[3]

[4]

"Please," he implored, "stop putting a Major or Lt Col (despite their devotion, exceptional attitude, and culture) in charge of ICAM, Zero Trust or Cloud for 1 to 4 million users when they have no previous experience in that field – we are setting up critical infrastructure to fail."

The former chief software officer continued:

We would not put a pilot in the cockpit without extensive flight training; why would we expect someone with no IT experience to be close to successful? They do not know what to execute on or what to prioritize which leads to endless risk reduction efforts and diluted focus. IT is a highly skilled and trained job; staff it as such.

In the British armed forces mid-ranking officers are posted, regardless of qualifications or professional experience, to manage equipment-purchasing projects for the Ministry of Defence. These postings are of fixed length and last for two years, meaning any project that takes more than two years has the potential to end up [5]turning into a hugely expensive and unproductive mess . The origin of this policy was a 1980s corruption scandal where a civil servant overseeing a long-term MoD contract was caught accepting bribes; to prevent it happening again, senior personnel decided to implement the two-year-posting policy.

Chaillan went on to complain that while he had managed to roll out DevSecOps practices within his corner of US DoD, his ability to achieve larger scale projects was being hampered by institutional inertia.

[6]

"I told my leadership that I could have fixed Enterprise IT in 6 months if empowered," he wrote.

Among the USAF's sins-according-to-Chaillan? The service is still using "outdated water-agile-fall acquisition principles to procure services and talent", while he lamented the failure of the Joint All-Domain Command and Control (JADC2) to secure its required $20m funding in the USAF's FY22 budget.

[7]US Navy starts an earthquake to see how its newest carrier withstands combat conditions

[8]US Air Force announces plan to assassinate molluscs with hypersonic missile

[9]Chuck Yeager, sound barrier pioneer pilot, dies at 97

[10]Talk about a control plane... US Air Force says upcoming B-21 stealth bomber will use Kubernetes

He was also quite scathing about the USAF's adoption – or lack thereof – of DevSecOps, the trendy name for efforts to make developers include security-related decisions at the same time as product-related decisions when writing new software. It appears the service wasn't quite as open-minded as its overseers in the wider DoD.

"There is absolutely no valid reason not to use and mandate DevSecOps in 2021 for custom software," wrote Chaillan. "It is borderline criminal not to do so. It is effectively guaranteeing a tremendous waste of taxpayer money and creates massive cybersecurity threats but also prevents us from delivering capabilities at the pace of relevance, putting lives at risk, and potentially preventing capabilities to be made available when needed whenever world events demand, many times overnight."

Doubtless his full post will chime with anyone else in a senior post at a tech company who eventually becomes fed-up enough not only to quit but also to tell the wider world exactly why.

[11]

So far the USAF hasn't publicly responded to its former chief software officer. ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YTKbI5-g3mp08uefu7Dg3wAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.linkedin.com/pulse/time-say-goodbye-nicolas-m-chaillan/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTKbI5-g3mp08uefu7Dg3wAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTKbI5-g3mp08uefu7Dg3wAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.bbc.co.uk/news/uk-57348573

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTKbI5-g3mp08uefu7Dg3wAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/06/22/us_navy_creates_earthquake/

[8] https://www.theregister.com/2021/06/22/usaf_snail_clam_missile_plan/

[9] https://www.theregister.com/2020/12/08/chuck_yeager_dies/

[10] https://www.theregister.com/2020/06/03/kubernetes_b_21_bomber/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTKbI5-g3mp08uefu7Dg3wAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



Do I hear a deafening chorus?

Will Godfrey

Has anyone here not been in similar a situation?

So true...

Anonymous Coward

Sadly, I have encountered this issue SO MANY times (in the UK)...putting unsuitable (but highly thought of), people into jobs, where they have control over projects that they know absolutely nothing about....even if previously, they had done well in their specific original role (for which they might have been trained).

But that doesn't help, if they switch roles into a different sector, where they have no experience. (I think this is also known as "jobs for the boys" or "cronyism").

And it doesn't just happen in the public sector...it happens in the private sector too - as I know 2 experienced people who were overlooked for roles in companies, as the boss wanted to "reward" a "personal friend" in one job and a "relative" in another. (And both of them screwed up big-time...but kept their jobs :-( )

Re: So true...

Paul Herber

It's one thing to know all about DevSecOps. But what if your speciality is SecDevOps or DevOpsSec. It's all OpsSecDevSec to me.

Re: So true...

Duncan Macdonald

I was once in the opposite position - along with my normal technical job I was put in charge of the group of contractors running an ICL mainframe. This mainframe was being wound down as its workload was transferred to a group of Unix systems.

As my knowledge of the mainframe and its software was minimal and had no chance of getting up to a competent level in any reasonable time, I took the decision to leave all the technical matters to the contractors and told them to see me if they needed administrative cover beyond their own authority level. This arrangement worked well until the company finally disposed of the ICL mainframe. (If I remember correctly it took me about 10 minutes a month to approve timesheets and that was about it.)

Re: So true...

Anonymous Coward

Yes, compounded by the fact that said officer has to get something into his OJAR (yearly report) and just running something competently doesn’t cut it, so cue the ‘identification of things that are wrong and must be changed’ and then you run straight into project variation and increased costs… I could be wrong of course but MoD procurement history would suggest not…

Cybersaber

Good boss > skilled or informed boss any day because a good boss knows when to lead and when to defer to the expertise of their subordinates. Skilled bad boss is worse.

I mean that's not the only two choices, I was just saying that a good, but clueless boss isn't an automatic fail. There are worse combinations.

This article comes off as sour grapes to me, regardless of whether it has merit because it basically reads "I know best, and they didn't listen to me, so of course their decisions must be faulty, and I'm going to shame them because I'm mad."

doublelayer

I'm not sure about that. Sour grapes to me would be if he was fired and sent this, but he was unhappy enough to quit of his own accord. That implies that, whatever the reasons, it's not something done to fire back at the person who took his job.

As for a good boss or an informed one, a bad informed boss is certainly a problem, but in many ways an uninformed good boss is too. A good boss who doesn't know how things work might, in good faith, make promises about things that can't get done. They might pass every decision down to someone who knows what they're doing and harm organization. While a somewhat informed good boss will definitely beat a bad one, good management requires some basic level of knowledge of what the people below you are doing. Someone who lacks that knowledge is likely to be ineffective or problematic without needing managerial incompetence as well.

Water-agile-fail

Eclectic Man

Seems like he speaks for most people involved in large government IT procurements. The bosses seem to think that actually understanding the nature of IT and procurement is almost a disqualification for the job.

To be fair, how would you like it if your underlings understood their jobs better than you did and you had to let them get on with it? I mean they might actually get stuff done for which you could not claim the credit.

Re: Water-agile-fail

Will Godfrey

My last boss (before retiring) was quite comfortable knowing that most of the engineers knew more about their specialty, and would let us do whatever was needed to get the job done. He trusted us, and we never let him down.

I'll never forget one meeting with a company were were doing a major refit for, where our boss took their boss to one side and let us techies thrash it out between us - one of the smoothest installs we ever did.

Re: Water-agile-fail

Will Godfrey

Oops. double post - sorry

Re: Water-agile-fail

A.P. Veening

To be fair, how would you like it if your underlings understood their jobs better than you did and you had to let them get on with it?

The real fun starts when the underlings understand their boss's job better than the boss himself.

This just in

fidodogbreath

"Large bureaucracy is slow, risk-averse, and prioritizes ass-covering over organizational goals."

Cybersaber

Also, this comment here makes me think he doesn't really understand balancing security with other operational needs "...potentially preventing capabilities to be made available when needed whenever world events demand, many times overnight."

Security NEVER made anything more performant, available, or reliable. It can at best have no impact, but usually involves a compromise. It makes me think maybe he's the one in the wrong. The military _does_ get security, believe you me. If they were prioritizing something else, despite knowing how critical security is, maybe they're not the ones that are blind?

Or maybe it's one of the 'Agile is the messaiah' types that worship it as the savior of software development, and anyone who says there's a messy corner case (which is common in enterprises that deal with life and death) is a benighted heathen who must be made to see the light.

You don't deliver 3/4ths of a rifle and get to the trigger in the next sprint. Or accept that there will be bugs and maybe 1/1000 rounds will explode in the barrel and that's okay, because they can lodge a Bugzilla ticket if they live and we'll write a user story about it. Agile concepts help nearly every process, but not every process can go full Scrum or some type of crystal.

Doctor Syntax

One of the characteristics of the military has been that it is liable to being physically attacked as it does its job. It needs to be able to defend itself.

Now it's liable to be electronically attacked as well. IT security is a significant part of the defence it needs.

Anonymous Coward

Seems to me this guy has more than made his bones in the industry - someone you listen to whether you agree with everything he says or not, because he's been right more than he has been wrong.

The Pillorying of Good Men.

Anonymous Coward

https://enterpriseirregulars.com/69091/pillorying-marklogic-selling-disruptive-technology-government-hard-risky/

Sadly, this isn't new. Do not suffer fools quietly.

Unix weanies are as bad at this as anyone.
-- Larry Wall in <199702111730.JAA28598@wall.org>