Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

131–140 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#131
post #66

Earlier quoted context omitted.

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

The US government isn't in need of a thousand high-skilled hackers. They are in need of a million normal employees with some basic security awareness. Anyone with a modicum of skill can find thousands of areas to improve. The issue is that almost nobody is in a position to get anything changed. Even basic software choices are a multi-year epic.

The NSA isn't actually supposed to be a massive Statsi-like bureaucracy, it's meant to crack codes used in wartime so that our troops know what the enemy will do next.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#132
post #59

Earlier quoted context omitted.

Anything used will become a target. How the hell is MS a bigger threat than the rest? If anything a lot of the industry is a way bigger threat and spends less on security.

I don’t understand your comment. Microsofts failures are a threat precisely because it is so used, especially by the US govt. And they may spend a lot on security, but their recent failures have been pretty amateurish. A recent breach they had was due to an old, non-2fa service account with a weak password and privileged access. See also the CISA report about last years breach.

> but their recent failures have been pretty amateurish

> See also the CISA report about last years breach

The same CISA who just recently got hacked in an even more amateurish way?

https://news.ycombinator.com/item?id=40107675

https://securityintelligence.com/news/cisa-hackers-key-syste...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#133
post #72
post #52

Earlier quoted context omitted.

> I do know that some agencies have full access to some Microsoft source code. Access does not mean open source. Open source = OSI and what I think GP meant. And I hold the sentiment that government funded development should be open source.

Open source goes back almost a century, and does mean access to the source code. GPL was created, and other licenses, to allow more than personal use.

GPL is one kind of open source, not all. That’s why I specified OSI.

For government work, I care about OSI, not if people can just see and not legally change, contribute, and redistribute.

I think government should fund global goods and want to be precise in my language. So when I say “open source” I specifically mean OSI-licensed stuff.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#134
post #53

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

"& up-level your IT department to be able to execute multi-year projects competently." Cheaper just to pay up.

IME, paying up is HOW you level up.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#135
post #92

Earlier quoted context omitted.

> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…

> The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries because that allows them both to say they’re saving money at the time and later to cite the struggling/failed project as proof that they were right Why is it a surprise that employees who are essentially unfirable don't perform well? Aside from a…

> Why is it a surprise that employees who are essentially unfirable don't perform well?

This is a great example of that political dogma: notice that you’ve accepted as an article of faith the trope that government employees can’t be fired or disciplined or that this is not true of contractors, despite neither of those being true?

If your goal is successful projects, what you’re looking for is accountability and managerial discretion. The managers you think can’t direct civil servants directly aren’t magically more capable of selecting and overseeing contracts, either, and without technical staff they won’t have someone they can turn to for advice who doesn’t have a financial conflict of interest.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#136

CSRB's report on the Exchange Online breach that dropped a couple weeks ago was pretty damning. Microsoft had a situation where a threat actor had access to the entirety of Exchange Online, and possibly their entire cloud. CSRB describes the entire incident as completely avoidable, and resulting from Microsoft's inadequate security culture, and it calls Microsoft out for making public statements about the breach and…

Maybe the CSRB should look at their own agency, CISA, and get things fixed, since CISA has more power over CISA than it has over Microsoft.

https://securityintelligence.com/news/cisa-hackers-key-syste...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#137
post #59

Earlier quoted context omitted.

I don’t understand your comment. Microsofts failures are a threat precisely because it is so used, especially by the US govt. And they may spend a lot on security, but their recent failures have been pretty amateurish. A recent breach they had was due to an old, non-2fa service account with a weak password and privileged access. See also the CISA report about last years breach.

> but their recent failures have been pretty amateurish > See also the CISA report about last years breach The same CISA who just recently got hacked in an even more amateurish way? https://news.ycombinator.com/item?id=40107675 https://securityintelligence.com/news/cisa-hackers-key-syste...

Knowing and doing are separate skills.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#138
post #47

Earlier quoted context omitted.

Certainly. It’s not like giving them the source code would increase risk significantly, if the software is designed well. I think it would actually strengthen as more researchers would study and submit contribs. I think Linux is as or more secure than windows and it’s open source. There’s tons of sensitive systems that are open source. It’s a design fallacy that security through obscurity is good.

>It’s a design fallacy that security through obscurity is good. Yet, still obscurity increases security. Reverse engineering is not trivial and raises the bar.

> Yet, still obscurity increases security.

I disagree and think obscurity decreases security. It just gives the false belief of security.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#139
I'd guess that, before the US ever does anything about its Microsoft Achilles heel, other countries will realize that they face even more threats from depending on Microsoft.

(This applies to a number of reckless tech companies upon which countries and other companies create dependencies. But MS is one of the most concerning to me.)

Re: Microsoft is a national security threat: ex-White House cyber policy director

#140

Earlier quoted context omitted.

That's all fine and good but I don't want missiles with code you can edit. I didn't vote for you, nor do I trust you.

Nobody said random users should be able to edit. FOSS means the code is available, not that they're going to take patches. (See sqlite for an extreme case - code is public domain, but they more or less don't take contributions)

Code available means everyone else has a leg up developing their own weapon system or finding flaws in yours. You don't really want adversaries looking through the source code of your targeting and guidance systems.
Post reply on HN