Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

141–150 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#141
post #92

Earlier quoted context omitted.

Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.

> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…

I think it's more about greasy palms than political ideologies. No proof though.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#142
post #66

Earlier quoted context omitted.

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

Um, NASA? The government is able to employ tons of smart people that could be making way more money elsewhere. They might not get the absolute best security people in the world, but they could get good enough - as good as they're getting from MS for a fraction of the price. Additionally, government salaries aren't terrible when you factor in the pension. Most people want the money now. But if you want financial secur…

Almost all the work done at NASA is done by contractors that work in better conditions than allowed for by the federal payscale.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#143
post #36

Earlier quoted context omitted.

Open-source doesn't mean "not secure" - the nuclear codes would be in the .env obv >.> Seriously though - the software itself would be separated from secrets architecturally. And because it's open and anyone in the world can contribute it could be superior code than what some private government tech contractor could come up with. For the equipment use case like jets and missiles, a separate directive component (drive…

The problem is that not all the secrets are so easily extracted - sometimes the design/software is the secret. If you put all the design up for nuclear weapons but just kept the nuclear codes secret it's great that no one can fire ours, but people could implement the design on their own with different codes. To use a more realistic example, consider air defence missile systems use to shoot down incoming missiles and…

> sometimes the design/software is the secret

Decreasingly the case, and we might be at the point I can say "poorly architected" if that's the case. A random 19 year old developer in the military with access to the secrets would be a big security hole too.

That's what we should be comparing with regards to open-source vs not open-source - in either case access to weaponry would of course be heavily gated.

Some of the other arguments you make here are no different than conventional arguments against open-source:

> the real code would still be private

Precisely the point, get the crowd to optimize the low-risk parts, build communities around those libraries and frameworks and recruit from it

> opponents might catch up

To remain an industry leader it's actually better to get everyone playing your game rather than trying to compete and stay ahead in a wild west scenario. You want to capture it really, so you can control it and be the leader in it. Open-source is one great way to do that (browser vendors come to mind).

Re: Microsoft is a national security threat: ex-White House cyber policy director

#144

Earlier quoted context omitted.

The US government isn't in need of a thousand high-skilled hackers. They are in need of a million normal employees with some basic security awareness. Anyone with a modicum of skill can find thousands of areas to improve. The issue is that almost nobody is in a position to get anything changed. Even basic software choices are a multi-year epic.

The NSA isn't actually supposed to be a massive Statsi-like bureaucracy, it's meant to crack codes used in wartime so that our troops know what the enemy will do next.

You're thinking of the CIA. The NSA's job is to spy on citizens.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#145
The federal government is merely experiencing what everyone else does: The IT industry has very low standards:

Look at the vast amount of fraud, theft, slander, cons, mis/disinformation, etc. on the Internet, not to mention consumers and small businesses getting run over by legal corporate behavior such as not providing customer service, locking accounts, holding money, holding data, surveillance and selling data, etc.

It's been said before, but IT needs professional standards that provide actual, real-life security, privacy, etc., just like professional standards for building developers provide actual, safe buildings - imagine a fraud equivalent to cryptocurrency in building architecture and engineering; imagine an SBF. SBF was celebrated and still is by some. Lawyers have professional standards, doctors, accountants, scientists, engineers in most fields, ... the list goes on in every field of human endeavor but IT.

And with standards comes liability. Microsoft shouldn't be able to just say, 'sorry about those hackers'.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#146
post #44

Earlier quoted context omitted.

The Pentagon can’t even pass an audit for the past 6 years, but yeah Microsoft is the national security threat.

What do you think 'can't pass an audit' means in the context of the DoD?

At best, incompetence. At worst, corruption.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#147
post #92

Earlier quoted context omitted.

> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…

> The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries because that allows them both to say they’re saving money at the time and later to cite the struggling/failed project as proof that they were right Why is it a surprise that employees who are essentially unfirable don't perform well? Aside from a…

> Why is it a surprise that employees who are essentially unfirable.

A government needs employees right? One way to attract and retain employees is to offer competitive wages, another is to offer a relatively low workload and high job stability. Government worker salaries are easy targets and the people who set them are elected officials, so its not a surprise most governments today lean on job security over wages.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#148

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

> The right answer here is if the situation is that bad, make a very public long-term commitment to shift to something else & up-level your IT department to be able to execute multi-year projects competently. The problem is that there isn't much in terms of alternatives, especially not if you prefer to have one software / vendor / tech stack. - In groupware, there used to be Lotus Notes, but that went down the drain…

Wine can run apps that access hardware without issues.

The main problem is the catch-22: there's not much point in developing competitors to Microsoft's stack if businesses aren't going to ever consider them, and government departments won't consider alternatives if they can't get everything from a single vendor in a 100% risk free manner thanks to the "nobody ever got fired for buying Microsoft" and "one throat to choke" mentality you get there.

Governments do this to themselves. The USG doesn't even have to pick Microsoft. They could potentially sign contracts with Apple for workstation hardware and services, that would encourage and feed the alternative ecosystem based around Apple, or they could fund Linux, etc. They don't though. It's just soooo much easier to sign one giant contract, because that minimizes work for them and it's not really important to get value for money if you're in the public sector. Signing a great deal won't get you a big bonus or anything like that, but taking risks can get you blocked from promotions. So, why risk anything?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#149
post #135

Earlier quoted context omitted.

> The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries because that allows them both to say they’re saving money at the time and later to cite the struggling/failed project as proof that they were right Why is it a surprise that employees who are essentially unfirable don't perform well? Aside from a…

> Why is it a surprise that employees who are essentially unfirable don't perform well? This is a great example of that political dogma: notice that you’ve accepted as an article of faith the trope that government employees can’t be fired or disciplined or that this is not true of contractors, despite neither of those being true? If your goal is successful projects, what you’re looking for is accountability and manag…

> This is a great example of that political dogma: notice that you’ve accepted as an article of faith the trope that government employees can’t be fired or disciplined or that this is not true of contractors, despite neither of those being true

Nice strawman. It is harder to fire govt employees than to fire private employees. Disagree?

Just look up at-will employment law that doesn't apply to government entities. Looks like you're the one following political dogma and accepting articles of faith and tropes.

Otherwise why would ignore that a very consequential law is different for private vs govt employees?

> The managers you think can’t direct civil servants directly aren’t magically more capable of selecting and overseeing contracts, either.

Where did I say they cannot? Please stop with the strawmen. They just don't have enough incentive because it's very hard to fire them, unlike managers in the private sector.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#150

Earlier quoted context omitted.

The NSA isn't actually supposed to be a massive Statsi-like bureaucracy, it's meant to crack codes used in wartime so that our troops know what the enemy will do next.

You're thinking of the CIA. The NSA's job is to spy on citizens.

>The NSA's job is to spy on [US] citizens

They're not supposed to (according to for example the Foreign Intelligence Surveillance Act of 1978).

If a US citizen needs to be spied on by the US government, the FBI is supposed to do that.

Post reply on HN