Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

101–110 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#101
post #66

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

  because gov payscale limits do not match market reality
The same people and corporations who leach off govt contracts and subsidies speak often about how govt spending is wasteful.

State/federal govts receive 10-20% of every single citizens salary on top of being able to literally create money. They aren't hurting for money.

This is entirely caused by corruption and incompetence.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#102

CSRB's report on the Exchange Online breach that dropped a couple weeks ago was pretty damning. Microsoft had a situation where a threat actor had access to the entirety of Exchange Online, and possibly their entire cloud. CSRB describes the entire incident as completely avoidable, and resulting from Microsoft's inadequate security culture, and it calls Microsoft out for making public statements about the breach and…

Why does government use cloud for general public? Why don't they use government cloud with high security?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#103

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

> The right answer here is if the situation is that bad, make a very public long-term commitment to shift to something else & up-level your IT department to be able to execute multi-year projects competently. The problem is that there isn't much in terms of alternatives, especially not if you prefer to have one software / vendor / tech stack. - In groupware, there used to be Lotus Notes, but that went down the drain…

If you want to use Windows outside of an air gapped environment, it’s reckless to use anything less than Windows 10, and even for that you have only about a year left unless you pay for extended support.

Also, as someone who actually uses Windows 11 Professional all day, every working day, I honestly haven’t encountered these adverts everyone is always referring to (maybe it’s because I’m not in the US).

As for the UI, initial release didn’t allow ungrouping of Windows on taskbar and context menus hid most things behind an extra click. This was crap, but a major update a while back has resolved these.

I’ve tried Linux, I occasionally need to use it or macOS for development of our cross platform Electron based product, and I would still choose Windows as it really has consistently “just worked” for me since around Windows 2000.

But if macOS or Linux works well for you, I’m happy you’re happy and perhaps you in turn could be happy for people who are happy with Windows (and ideally without thinking they must be deluded or something).

Re: Microsoft is a national security threat: ex-White House cyber policy director

#104

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

we have a company that has a monopoly that is honestly unimaginable (how does someone monopolize computation of all things...) and we know that all monopolies require government enforcement to prevent others from competing... then we know that there's no such thing as a conflict between Microsoft and the us government the us govt is to serve Microsoft and that's that. any conversation like this about the merits of Mi…

it's ok, they said they're "not a fan of microsoft", clearly that means they're not corrupted.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#105

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

we have a company that has a monopoly that is honestly unimaginable (how does someone monopolize computation of all things...) and we know that all monopolies require government enforcement to prevent others from competing... then we know that there's no such thing as a conflict between Microsoft and the us government the us govt is to serve Microsoft and that's that. any conversation like this about the merits of Mi…

[dead]

Re: Microsoft is a national security threat: ex-White House cyber policy director

#106
post #91
post #64

Earlier quoted context omitted.

Believe it or not, USA government cares at least a little. USA did not institute the draft even when fighting on two fronts (Afghanistan and Iraq). USA made up for the lack in manpower with technology: Reaper drones, cluster munitions, night vision, precise artillery, overwhelming air power.

Don't you find it a bit frightening that this tech is daily giving a smaller and smaller subset of people in the world the unilateral ability to project their will onto the world? At least if they tried to draft in an unjust war, the people could withhold their physical support. This was pretty effective during the Vietnam area, but it's a bargaining chip we've lost. As we saw with 702, we really have very little lev…

Well if the history in the past 3 years is relevant I would say that the power of elites to project their will onto the rest of the world is small. In both sides: Russia is still grinding through a war that may be their second Afghanistan; and on the western side it took US Congress half a year to approve some funds so someone else (Ukraine) would to fight China’s gas station.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#107

Maybe the NSA should help protect all Federal government systems. According to Wikipedia... >The NSA is also tasked with the protection of U.S. communications networks and information systems.

How I imagine conversations going in the NSA:

"Hey guys, we should fix this vulnerability ASAP."

"No can do, it has to wait and be stealth-patched indirectly, otherwise we'll lose the advantage of using it ourselves."

Re: Microsoft is a national security threat: ex-White House cyber policy director

#108

Earlier quoted context omitted.

That's all fine and good but I don't want missiles with code you can edit. I didn't vote for you, nor do I trust you.

Nobody said random users should be able to edit. FOSS means the code is available, not that they're going to take patches. (See sqlite for an extreme case - code is public domain, but they more or less don't take contributions)

Parent literally said "I don't want my missiles to not have code I cannot edit"

Re: Microsoft is a national security threat: ex-White House cyber policy director

#109

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

> The right answer here is if the situation is that bad, make a very public long-term commitment to shift to something else & up-level your IT department to be able to execute multi-year projects competently. The problem is that there isn't much in terms of alternatives, especially not if you prefer to have one software / vendor / tech stack. - In groupware, there used to be Lotus Notes, but that went down the drain…

I used to think the way I’d try to tackle a challenge like that would be essentially embracing the ChromeOS model by going web-first for everything so you’d avoid accumulating new accidental dependencies on proprietary software, and trying to shift legacy apps to WINE, terminal servers, etc. Obviously you’d need thousands of exceptions but the important part would be removing the inertia which means that new code starts out being non-portable.

Unfortunately, these days the browser engine market is pretty lopsided so that strategy would need to be paired with something like a requirement to test in Gecko and WebKit because I trust Google’s long-term management even less than Microsoft.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#110
post #92

Earlier quoted context omitted.

Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.

> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…

> The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries because that allows them both to say they’re saving money at the time and later to cite the struggling/failed project as proof that they were right

Why is it a surprise that employees who are essentially unfirable don't perform well? Aside from a very small percentage where the hiring culture is exceptional, it's almost universal. This is a problem with governments across at all levels in almost all countries.

How many times do we have to match this movie before realizing that just increasing the salaries won't make a difference, and instead will be wasteful.

Post reply on HN