Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

81–90 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#81

I call bullshit. Someone, somewhere long ago deep inside of the bowels of the NSA decided to deprioritize actual security, and the use of the capability security model. They knowingly did this, because actually secure computing (which they already had at the time[1,2,3]) represented a threat to the NSA , or so they thought at the time. The trade-offs seemed acceptable, because there were systemic approaches at the ti…

Your assessment of the current state of affairs is spot on. However, there are a few additions.

A. It is not metaphorically swiss-cheesed, the swiss-cheese model [1] of software security is officially endorsed. Just stack enough trash and maybe it will be okay is now accepted policy.

B. It was not driven by the NSA. It was actually driven by commercial software vendors like Microsoft and Cisco who could not meet minimum security standards, so demanded the standards be lowered to allow them to make sales. Any time the NSA gets the drivers seat in setting government security procurement standards they almost always push for actual security since the NSA is the government; they are protecting themselves. It is reasonable to distrust them for commercial and external systems, but you can trust their standards for their own and government systems are not meaningfully compromised.

[1] https://en.wikipedia.org/wiki/Swiss_cheese_model

Re: Microsoft is a national security threat: ex-White House cyber policy director

#82
post #40
post #39

Maybe it's time to move to open source solutions (*nix), with custom security/audit measures. Might be very expensive initially, but then they'd have complete control.

You’re implicitly assuming they’d be better off with more control; I’m not sure that’s true.

It would definitely be possible for government to be good at things ... in the olden days of tech development, very good people were employed and empowered at government positions with technology roles. I'm thinking back to later 90s when I filled out my financial student aid application. That was an _extremly_ complicated web product for the time, built entirely by the government, and it completely worked and was easy to use. Commercial products like turbotax on the web didn't get parity of complexity and robustness for a good decade more than that.

The 'outsource everything' 'not allowed to compete with private industry' mentalities are what has the made the government unable to function in a quality manner ... Its virtually impossible for the government to just hire some people to a team to build some shit -- instead they are _required_ to create bids for contractors to bid on and then incredibly formal contract management processes that are just incredibly disfunctional by design ...

It doesn't have to be this way -- its a political result going back to the 'small government' movement which was ultimately about proving that government has to be bad at everything by imposing rules to ensure that result in as many places as possible ...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#83
To be more accurate, the leadership of Microsoft's lack of prioritizing security, aka basic quality of product, is a national security threat.

A similar claim could obviously be made of Boeing. Just imagine what is happening in their military contracts which we are not allowed to hear about. Looking at the projects which we are allowed to know about, airliners and Boeing's Starliner, clearly Boeing management needs to be put out to pasture.

The core issue is cutting corners, for profit. This is not an issue which is easy to handle in our system. It seems that the best we can do is name and shame. Let's do that at least.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#84
post #40
post #39

Maybe it's time to move to open source solutions (*nix), with custom security/audit measures. Might be very expensive initially, but then they'd have complete control.

You’re implicitly assuming they’d be better off with more control; I’m not sure that’s true.

More control yes but also: more transparency, more vendor choices across the lifecyle. Also more control over telemetry: the current MS stack uploads far more than necessary to only keep things running; government users should not be surveilled, their data should not be sold, etc.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#86

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

Negotiate? They even can regulate.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#87

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

we have a company that has a monopoly that is honestly unimaginable (how does someone monopolize computation of all things...)

and we know that all monopolies require government enforcement to prevent others from competing...

then we know that there's no such thing as a conflict between Microsoft and the us government

the us govt is to serve Microsoft and that's that. any conversation like this about the merits of Microsoft as a market participant are laughable and disingenuous

theres no programmer alive that knows the history of Microsoft that would speak about them as you have just done, as an honest company trying to make a product

actually sick to see how HN has been corrupted

Re: Microsoft is a national security threat: ex-White House cyber policy director

#89
post #57

The era of global botnets, worms, and ransomware can be credited to Microsoft, as well. Lax concern and slow turnaround for CVEs, poor update performance that led to much of the world turning off automatic updates, and updates being blocked on non-activated installs, if they weren't just easily broken gave root (literally) to fleets of vulnerable internet connected Windows systems being leveraged against the world at…

Not sure why this is downvoted. “NotPetya” and StuxNet were sophisticated worms/viruses which leveraged flaws in Microsoft products to ultimately bring down infra (ie, Iran nuclear program) or bring down countries (ie, Ukraine suffered attacks to energy sector)

Part of the reason it is downvoted is the snide insult at the end about downvotes. It took conscious decision and effort to edit a snide insult into the post where there was none before. As one of the people being derogatorily called "Microsoft PR", this is unnecessarily antagonistic of GP towards me on HN, especially when I did nothing to GP.

Commenting on your downvotes is off-topic, against the rules, and when done as a snide insult like above: rude. GP might experience better results if they edited their post to remove the snide, insulting comments about downvoters.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#90

CSRB's report on the Exchange Online breach that dropped a couple weeks ago was pretty damning. Microsoft had a situation where a threat actor had access to the entirety of Exchange Online, and possibly their entire cloud. CSRB describes the entire incident as completely avoidable, and resulting from Microsoft's inadequate security culture, and it calls Microsoft out for making public statements about the breach and…

Its Microsoft. So here are some examples for the children on how they solve their problems -

https://www.theverge.com/2022/3/25/22995144/microsoft-foreig...

https://en.wikipedia.org/wiki/Microsoft_licensing_corruption...

https://www.wsj.com/articles/BL-CJB-17439

Post reply on HN