Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

31–40 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#31
The era of global botnets, worms, and ransomware can be credited to Microsoft, as well.

Lax concern and slow turnaround for CVEs, poor update performance that led to much of the world turning off automatic updates, and updates being blocked on non-activated installs, if they weren't just easily broken gave root (literally) to fleets of vulnerable internet connected Windows systems being leveraged against the world at large for roughly a decade until Windows 10 brought (and forced) endpoint security practices into the 21th century.

It's reassuring that their official stance hasn't changed; "This is how big we are, and it'd be a real tragedy if we couldn't afford to stop something like what we caused before from happening again...", instead of being sued into responsibility by the world at large.

(Uh oh, not 5 minutes in and it looks like Microsoft PR is already here to downvote the trouble away.)

Re: Microsoft is a national security threat: ex-White House cyber policy director

#32

Earlier quoted context omitted.

Even more reason to tackle monopolies and break up 'too big to fail' companies.

Larger ships carry more people and can thus sink with more, let's cut the ships in half? Point being, there's a lot of infrastructure that kinda doesn't make sense split up. If you want resiliency, build a second system in parallel not make management of an existing one times more expensive.

There's really no reason for all sensitive data and email to be stored on the servers of one company which has tens of thousands of employees who might be insider threats not to just one customer, but all of them.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#33
post #28
post #5

Earlier quoted context omitted.

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

This is actually not a bad idea for an international peace treaty. If you make weapons, they must be open source. If the real power in these tools is the secrecy behind their design and implementation, seems like a great way to suck the power out of them.

This strategy would fall apart when you encounter an adversary willing to sacrifice its own people. Nations that care about their own people need to keep a technological advantage on the battlefield.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#34

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

The Pentagon can’t even pass an audit for the past 6 years, but yeah Microsoft is the national security threat.

What does one have to do with the other? It’s possible to have more than one threat.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#35

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

I’d imagine that these proclamations are part of the negotiation.

I wouldn’t want to be a Microsoft account executive on the US govt contract right now; they’re about to have a massive load of additional requirements.

And if they don’t play ball, possibly antitrust to weaken their stranglehold on being the only real enterprise player.

I’m not saying any of this is the right approach, but it’s a tool in the governments toolbox.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#36
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Open-source doesn't mean "not secure" - the nuclear codes would be in the .env obv >.>

Seriously though - the software itself would be separated from secrets architecturally. And because it's open and anyone in the world can contribute it could be superior code than what some private government tech contractor could come up with.

For the equipment use case like jets and missiles, a separate directive component (driver) would likely be necessary anyway, not just for security/privacy but because different nations have different equipment. We use F-16s, M-16s, Autel drones, etc.

This driver/directive component would be the manufacturer's IP - like an nvidia GPU driver. Think of it like we'd all be running/contributing the same OS but because we have different hardware and security needs there are still some private components.

The idea/goal here is that our defense companies would overall benefit from it. Not just because the software is improved, but you can justify funding, build curricula around it - might benefit the defense industry to modernize their tech practices.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#37

Earlier quoted context omitted.

Even more reason to tackle monopolies and break up 'too big to fail' companies.

Larger ships carry more people and can thus sink with more, let's cut the ships in half? Point being, there's a lot of infrastructure that kinda doesn't make sense split up. If you want resiliency, build a second system in parallel not make management of an existing one times more expensive.

Yes?

There is a little bit of wisdom out there: Don't put all your eggs in one basket.

Heterogenous architecture (where you intentionallly mix and match differing parts for increased fault tolerance) has been a thing for decades.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#38

Earlier quoted context omitted.

Larger ships carry more people and can thus sink with more, let's cut the ships in half? Point being, there's a lot of infrastructure that kinda doesn't make sense split up. If you want resiliency, build a second system in parallel not make management of an existing one times more expensive.

There's really no reason for all sensitive data and email to be stored on the servers of one company which has tens of thousands of employees who might be insider threats not to just one customer, but all of them.

Double-edged sword, because few organizations also have the resources to do security at the scale and depth as a MS/goog/Amz

Re: Microsoft is a national security threat: ex-White House cyber policy director

#40
post #39

Maybe it's time to move to open source solutions (*nix), with custom security/audit measures. Might be very expensive initially, but then they'd have complete control.

You’re implicitly assuming they’d be better off with more control; I’m not sure that’s true.
Post reply on HN