Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

61–70 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#61
post #36
post #5

Earlier quoted context omitted.

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Open-source doesn't mean "not secure" - the nuclear codes would be in the .env obv >.> Seriously though - the software itself would be separated from secrets architecturally. And because it's open and anyone in the world can contribute it could be superior code than what some private government tech contractor could come up with. For the equipment use case like jets and missiles, a separate directive component (drive…

The problem is that not all the secrets are so easily extracted - sometimes the design/software is the secret.

If you put all the design up for nuclear weapons but just kept the nuclear codes secret it's great that no one can fire ours, but people could implement the design on their own with different codes.

To use a more realistic example, consider air defence missile systems use to shoot down incoming missiles and drones. The secrets here aren't keys, it's software-driven behaviours including the approach to identify radar tracks as hostile or noise, identify when to commit a missile and how to target it, the code implicitly contains the vulnerabilities where the radar tracking is less effective and more evadable and how the system tries to mitigate this, etc.

When you take away all the secret behaviours, you quickly end up with not much more than just the drivers connecting the hardware to the logic, which isn't a lot of code that's driving the funding. How you set a missile tubes tilt and direction is trivial stuff and is mostly reused from old platforms that were funded decades ago.

Additionally, there is some talk about how this is kind of like security through obscurity. When it comes to things like weapons and other high-tech capabilities, security isn't only security against being owned, it's security against your opponent closing the technological gap. Unfair wars, where you have a significant tech lead on your opponent, means your population bleeds less.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#62
CSRB's report on the Exchange Online breach that dropped a couple weeks ago was pretty damning. Microsoft had a situation where a threat actor had access to the entirety of Exchange Online, and possibly their entire cloud. CSRB describes the entire incident as completely avoidable, and resulting from Microsoft's inadequate security culture, and it calls Microsoft out for making public statements about the breach and its response that it knew to be inaccurate.

The ONLY way that breach got detected was because the State department bought the premium package with extra logging that let them see when mailboxes get opened. It turned out, Microsoft had a signing key that could create access tokens for anything in their cloud, and it was stolen by Storm-0558. (More precisely, the key was only supposed to be useful for a portion of their services, but a bug allowed Storm-0558 to bypass that scope limitation.) And they used that to go read the e-mails of the State department and a bunch of other organizations, and private individuals. There was nothing customers could do to prevent the attack, and apparently no other indication in their logs that it was taking place, besides this category of entry that was gatekept behind a premium subscription package.

Microsoft generated the key in 2016 and discontinued it years prior to the incident, but it was never revoked. Microsoft didn't even bother with key rotations anymore after 2021 because one time they fucked it up and it caused an outage, so they decided to just not do that anymore. Also, Microsoft apparently didn't have any means of detecting the obvious use of a zombie key.

Also, Microsoft still doesn't really know how they got the key. They made a blog post about their theory, representing it as something they were highly confident in based on the evidence. After 6 months of pressure from the government, Microsoft finally updated the post to admit that they had no evidence of critical parts of what they claimed, and several key points in their narrative were factually incorrect.

Then earlier this year, Microsoft got hacked AGAIN because they had an unused-but-active test account with a guessable password and no MFA, and it was authorized for access to e-mail boxes of (at a minimum) numerous members of Microsoft senior leadership.

Microsoft has got serious problems.

edit: I keep futzing with my phrasing. Those wanting a much better account should just read the report, since it has a great deal more nuance and information. https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#63
post #47
post #5

Earlier quoted context omitted.

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Certainly. It’s not like giving them the source code would increase risk significantly, if the software is designed well. I think it would actually strengthen as more researchers would study and submit contribs. I think Linux is as or more secure than windows and it’s open source. There’s tons of sensitive systems that are open source. It’s a design fallacy that security through obscurity is good.

> It’s not like giving them the source code would increase risk significantly

I like free software a lot, and do not know much about weapon development, but would not the software reveal a lot about capabilities of the weapon platform? The argument to keep the software private might not be motivated just by attempt to hide security holes, but also by desire to hide what the weapon can do, what are the operational limits, etc.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#64
post #45
post #33

Earlier quoted context omitted.

This strategy would fall apart when you encounter an adversary willing to sacrifice its own people. Nations that care about their own people need to keep a technological advantage on the battlefield.

States don't care.

Believe it or not, USA government cares at least a little. USA did not institute the draft even when fighting on two fronts (Afghanistan and Iraq). USA made up for the lack in manpower with technology: Reaper drones, cluster munitions, night vision, precise artillery, overwhelming air power.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#65
post #59

Earlier quoted context omitted.

Anything used will become a target. How the hell is MS a bigger threat than the rest? If anything a lot of the industry is a way bigger threat and spends less on security.

I don’t understand your comment. Microsofts failures are a threat precisely because it is so used, especially by the US govt. And they may spend a lot on security, but their recent failures have been pretty amateurish. A recent breach they had was due to an old, non-2fa service account with a weak password and privileged access. See also the CISA report about last years breach.

And if it were ten open-source projects then they'd have to defend themselves against nation-state attackers. They're not ready for it. The researchers that demonstrated an attack on Linux got vilified instead of the maintainers that had misplaced their trust. *Researchers* not a truly sophisticated and a well-funded threat actor. Do you see the issue?

Do you really think the alternatives are more diligent with their defense, 2FA, have spent as much time and effort on security?

I truly don't like Microsoft but this seems like shitting on them but I really don't see the point. Anything they use is going to be a "national security threat." I'd gladly see other vendors stepping up, but it's enormously difficult and we're not really there yet.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#66

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#68

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

> The US government is 10% of Microsoft's annual revenue just on security services How are you able to conclude that?

I assume it's the $20 billion in security services statement compared against their ~$200 billion yearly revenue. I'm not sure those security services are all for the U.S. govt though.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#69
I've been told by current military folks that they are forced to use outdated windows (the ones without security updates) on official military computers on base. So this is where they access emails, surf the web, and all of that. They had to use IE instead of the evergreen edge browser.

It's well known among the people who serve that it's a joke.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#70
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

> Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems

They likely already do. Between exploiting remote vulnerabilites (a nation-state intrusion will never even be noticed -- they aren't going to encrypt all the files and ask for ransom) and old-fashioned spycraft, it would be really amazing if all the contractors involved on those projects had perfect security.

Post reply on HN