Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

41–50 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#41

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

The Pentagon can’t even pass an audit for the past 6 years, but yeah Microsoft is the national security threat.

That's not just a 6 years thing. The Pentagon has never passed an audit (the first Defense Department audit in its history was in 2017).

Re: Microsoft is a national security threat: ex-White House cyber policy director

#42
post #24

Earlier quoted context omitted.

Open Source != GPL. Nor on Github. I don't know what the parent fully meant, but I do know that some agencies have full access to some Microsoft source code. From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers. You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law. I don't want my missiles…

That's all fine and good but I don't want missiles with code you can edit. I didn't vote for you, nor do I trust you.

Nobody said random users should be able to edit. FOSS means the code is available, not that they're going to take patches. (See sqlite for an extreme case - code is public domain, but they more or less don't take contributions)

Re: Microsoft is a national security threat: ex-White House cyber policy director

#43

Earlier quoted context omitted.

The Pentagon can’t even pass an audit for the past 6 years, but yeah Microsoft is the national security threat.

What does one have to do with the other? It’s possible to have more than one threat.

Security is frequently only as strong as the weakest link. If you’re an adversary, would you spend more time on an org’a poor security practices (pentagon failing audits) or a more difficult software vendor?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#44

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

The Pentagon can’t even pass an audit for the past 6 years, but yeah Microsoft is the national security threat.

What do you think 'can't pass an audit' means in the context of the DoD?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#45
post #33
post #28

Earlier quoted context omitted.

This is actually not a bad idea for an international peace treaty. If you make weapons, they must be open source. If the real power in these tools is the secrecy behind their design and implementation, seems like a great way to suck the power out of them.

This strategy would fall apart when you encounter an adversary willing to sacrifice its own people. Nations that care about their own people need to keep a technological advantage on the battlefield.

States don't care.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#46
post #13

Microsoft’s security failures are a threat to national security. Microsoft itself is not.

As much as I like ragging on the softies--and lol my good sir--it's the existence of power that is a threat. The current captain, or their whims, or our belief in them, they are a sense only and no guarantee.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#47
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Certainly. It’s not like giving them the source code would increase risk significantly, if the software is designed well. I think it would actually strengthen as more researchers would study and submit contribs.

I think Linux is as or more secure than windows and it’s open source. There’s tons of sensitive systems that are open source.

It’s a design fallacy that security through obscurity is good.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#48
post #37

Earlier quoted context omitted.

Larger ships carry more people and can thus sink with more, let's cut the ships in half? Point being, there's a lot of infrastructure that kinda doesn't make sense split up. If you want resiliency, build a second system in parallel not make management of an existing one times more expensive.

Yes? There is a little bit of wisdom out there: Don't put all your eggs in one basket. Heterogenous architecture (where you intentionallly mix and match differing parts for increased fault tolerance) has been a thing for decades.

You do realise you'll have half a ship, not two ships then?

Defence in depth is expensive, infrastructure at scale is expensive, it would be difficult and more expensive to have a bunch of small operators reach the same level considering the initial cost and overhead.

I'm sure though that such equally viable alternatives could be built, but not by splitting existing ones.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#49

Earlier quoted context omitted.

Every time I’ve been involved with selling software in any way adjacent to national security they’ve required source code review.

How are you equating a "code review" to open source, the difference is the difference between asking a couple dudes for advice and asking the entire world for advice. I'm sure the argument sounded really good in your head, but let's be adults here when it comes to the United States military

Because auditable does not mean the same thing as audited. It is silly that people keep pushing that dead argument after Heartbleed pounded a stake through its heart. Audits are time consuming, challenging, and boring. Experience shows even critical, high profile projects hardly get any review at all by the "world", let alone actual audits by competent domain experts.

Quality verification depends on auditing and auditing depends on competent, trusted review and testing. Global transparency is not a substitute for auditing except when discussing absolute rock-bottom standards. Reviewable is significantly better than unreviewed and unreviewable, but that is the lowest possible bar. Unfortunately, software does, as a general rule, have rock-bottom auditing standards, so FOSS does provide meaningful assurance increases in many use cases. But, that is a artifact of the abysmal quality standards rather than any sort of inherent auditing advantage that FOSS provides. That is not to say that global transparency is not valuable for other reasons, but it provides no meaningful quality verification or auditing advantage in serious applications versus local transparency (to the trusted reviewer).

If you want to see how this works in practice, look at literally every other industry.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#50
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Why not?
Post reply on HN