Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

51–60 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#51
I call bullshit. Someone, somewhere long ago deep inside of the bowels of the NSA decided to deprioritize actual security, and the use of the capability security model. They knowingly did this, because actually secure computing (which they already had at the time[1,2,3]) represented a threat to the NSA, or so they thought at the time. The trade-offs seemed acceptable, because there were systemic approaches at the time that could keep things secure via other means, such as air-gapping, TEMPEST screening, etc.

Much like the consumer decision on the other side of that secrecy barrier, when it was decided the MULTICS was too complex, and you really didn't need all of that complexity (to allow mutli-level security), the easing of hardware requirements, and systems design time all seemed worth it.

Here we are 50 years later, and both decisions have proven to be disastrous. We've swiss-cheesed our infrastructure in a manner that can only be hinted at metaphorically. The closest analogies I know are:

  Imagine the power grid and modern society, with absolutely zero circuit breakers or fuses.
  
  Imagine running an economy without being able to divide wealth into uniform small amounts, dollars, cents, etc.
In both cases, everything becomes all or nothing. This is what we have with computers, all or nothing. You have to trust software you run, or you simply can't run it. It's the same with the "License Agreement", nobody actually reads them, and nobody tries to enforce them, yet there they are.

It's possible to have secure computing, we had it in the 1980s, but we didn't realize it. It was crude, but effective, because we had systems with no persistent internal storage, and we could write protect the storage we had. Thus it was possible to manage data, and the side effects allowed, in a simple, powerful way by simply not putting data at risk, making copies, and using those instead.

Until we reverse the bad decisions of the 1970s, we're going to keep up the deranged behavior, blaming everything and everyone, and ignoring the one way out of this.

You shouldn't ever have to trust a program you execute to behave in the manner you expect. Your computer should enforce the limits you expect, and the program should have zero ways around those limits.

[1] https://csrc.nist.rip/publications/history/ande72.pdf

[2] https://en.wikipedia.org/wiki/Capability-based_security

[3] https://web.archive.org/web/20120919111301/http://www.albany...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#52
post #24
post #5

Earlier quoted context omitted.

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Open Source != GPL. Nor on Github. I don't know what the parent fully meant, but I do know that some agencies have full access to some Microsoft source code. From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers. You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law. I don't want my missiles…

> I do know that some agencies have full access to some Microsoft source code.

Access does not mean open source. Open source = OSI and what I think GP meant. And I hold the sentiment that government funded development should be open source.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#53

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

"& up-level your IT department to be able to execute multi-year projects competently."

Cheaper just to pay up.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#54
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Closed source is a recipe for disaster. Many attacks on important infrastructure have been because of closed source/proprietary software.

- Stuxnet (developed to attack PLCs which control nuclear centrifuges)

- Petya (targeted Microsoft developed systems and software and brought governments and states to their knees. Notably Ukraine)

Re: Microsoft is a national security threat: ex-White House cyber policy director

#55

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

> The US government is 10% of Microsoft's annual revenue just on security services

How are you able to conclude that?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#57

The era of global botnets, worms, and ransomware can be credited to Microsoft, as well. Lax concern and slow turnaround for CVEs, poor update performance that led to much of the world turning off automatic updates, and updates being blocked on non-activated installs, if they weren't just easily broken gave root (literally) to fleets of vulnerable internet connected Windows systems being leveraged against the world at…

Not sure why this is downvoted.

“NotPetya” and StuxNet were sophisticated worms/viruses which leveraged flaws in Microsoft products to ultimately bring down infra (ie, Iran nuclear program) or bring down countries (ie, Ukraine suffered attacks to energy sector)

Re: Microsoft is a national security threat: ex-White House cyber policy director

#58

all tax payer funded software should be open source

I don't know how it works in the US, but this is very much the default when building public software in the UK, https://www.gov.uk/service-manual/service-standard/point-12-...

> Public services are built with public money. So unless there’s a good reason not to do so, the code they’re based should be made available for people to reuse and build on.

> Open source code can be reused by developers working in government, avoiding duplication of work and reducing costs for government as a whole. And publishing source code under an open licence means that you’re less likely to get locked in to working with a single supplier.

Obviously there are exceptions made, but you have to explain why the exception is necessary. An auth library would be an example of where you might not want the code pubic.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#59
post #13

Microsoft’s security failures are a threat to national security. Microsoft itself is not.

Anything used will become a target. How the hell is MS a bigger threat than the rest? If anything a lot of the industry is a way bigger threat and spends less on security.

I don’t understand your comment. Microsofts failures are a threat precisely because it is so used, especially by the US govt. And they may spend a lot on security, but their recent failures have been pretty amateurish. A recent breach they had was due to an old, non-2fa service account with a weak password and privileged access. See also the CISA report about last years breach.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#60
post #49

Earlier quoted context omitted.

How are you equating a "code review" to open source, the difference is the difference between asking a couple dudes for advice and asking the entire world for advice. I'm sure the argument sounded really good in your head, but let's be adults here when it comes to the United States military

Because auditable does not mean the same thing as audited. It is silly that people keep pushing that dead argument after Heartbleed pounded a stake through its heart. Audits are time consuming, challenging, and boring. Experience shows even critical, high profile projects hardly get any review at all by the "world", let alone actual audits by competent domain experts. Quality verification depends on auditing and audi…

the market will determine what should and should not be audited, according to supply and demand. thinking that a couple employees that were not paid for with profit but with printed and taxed government dollars is not and never will be a substitute for the free market, which is a synonym for humanity. not respecting that fact will always result in loss and inefficiency. and no amount of paragraphs can undo that.
Post reply on HN