Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

161–170 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#161
post #156

Earlier quoted context omitted.

You can say "poorly architected" all you want, but it's true. Military capability is frequently determined by software-implemented behaviours, not data you can plug into a generic public framework. >19 year old developer with access would be a big security hole It's true, they are. That's why militaries and defence companies go to great lengths to vet their staff and why even within vetted staff, sensitive material i…

> That's why militaries and defence companies go to great lengths to vet their staff What a joke, no they don't. They establish security internally by gating access, not trusting everyone because they've been "pre-vetted".

Gating access is compartmentalisation. If you're being brought onto, say, missile development, you absolutely will have to submit to both vetting (knowing who you are prior to access) and compartmentalisation (permitting access only to your relevant secrets throughout).

I'm not saying that just because you have some kind of clearance you will get access to everything, but it's part of the preconditions to your own relevant access.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#162
post #135

Earlier quoted context omitted.

> Why is it a surprise that employees who are essentially unfirable don't perform well? This is a great example of that political dogma: notice that you’ve accepted as an article of faith the trope that government employees can’t be fired or disciplined or that this is not true of contractors, despite neither of those being true? If your goal is successful projects, what you’re looking for is accountability and manag…

> This is a great example of that political dogma: notice that you’ve accepted as an article of faith the trope that government employees can’t be fired or disciplined or that this is not true of contractors, despite neither of those being true Nice strawman. It is harder to fire govt employees than to fire private employees. Disagree? Just look up at-will employment law that doesn't apply to government entities. Loo…

> Nice strawman. It is harder to fire govt employees than to fire private employees. Disagree?

Let’s see, so it’s not a straw man when you say government employees are “essentially unfirable” but it is when someone corrects you?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#163
post #72

Earlier quoted context omitted.

Open source goes back almost a century, and does mean access to the source code. GPL was created, and other licenses, to allow more than personal use.

GPL is one kind of open source, not all. That’s why I specified OSI. For government work, I care about OSI, not if people can just see and not legally change, contribute, and redistribute. I think government should fund global goods and want to be precise in my language. So when I say “open source” I specifically mean OSI-licensed stuff.

I specifically said "and other licenses", so why would you respond, as if I acted as if GPL was the only license?

No matter. One entity doesn't get to unilaterally redefine a century old term. You claim you want precision, well then specify OSI, a subset of open source.

(And yes, the licenses it approves are indeed a subset.)

Re: Microsoft is a national security threat: ex-White House cyber policy director

#164
post #98

Earlier quoted context omitted.

And if it were ten open-source projects then they'd have to defend themselves against nation-state attackers. They're not ready for it. The researchers that demonstrated an attack on Linux got vilified instead of the maintainers that had misplaced their trust. *Researchers* not a truly sophisticated and a well-funded threat actor. Do you see the issue? Do you really think the alternatives are more diligent with their…

> And if it were ten open-source projects […] The alternative wouldn’t be to use a smattering of open-source stuff, it would be to go with a different cloud provider like AWS or Google. > Do you really think the alternatives are more diligent […] That’s what the CISA report suggested. I’m not shitting on MS, I just don’t want foreign adversaries to be able to pick apart our IT systems like vultures.

But AWS alternatives ARE just a smattering of open source stuff.

Getting everything into AWS doesn't solve anything by itself, either. Then they'd still need to get everything off of windows, office, exchange, AD, etc. etc. Which is a ridiculous amount of work and they'd be fighting bugs and issues for years and years at their scale.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#165

Earlier quoted context omitted.

Nobody said random users should be able to edit. FOSS means the code is available, not that they're going to take patches. (See sqlite for an extreme case - code is public domain, but they more or less don't take contributions)

Parent literally said "I don't want my missiles to not have code I cannot edit"

Since the line was

> I don't want my missiles to not have code I cannot edit, and stepping back from the top secret sphere, tangential I am appalled at how crappy car firmwares are closed source.

I read that as that whoever's missiles they are should have full visibility and control of their code; I am assuming that "my missiles" means the government, not that the poster personally owns missiles.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#166
post #162

Earlier quoted context omitted.

> This is a great example of that political dogma: notice that you’ve accepted as an article of faith the trope that government employees can’t be fired or disciplined or that this is not true of contractors, despite neither of those being true Nice strawman. It is harder to fire govt employees than to fire private employees. Disagree? Just look up at-will employment law that doesn't apply to government entities. Loo…

> Nice strawman. It is harder to fire govt employees than to fire private employees. Disagree? Let’s see, so it’s not a straw man when you say government employees are “essentially unfirable” but it is when someone corrects you?

Lets ignore the personal back and forth, and get back to the argument.

It is harder to fire govt employees than to fire private employees. Disagree?

At-will employment law doesn't apply to government entities.

A very consequential law is different for private vs govt employees.

> The managers you think can’t direct civil servants directly aren’t magically more capable of selecting and overseeing contracts, either.

Never said in my comment they cannot direct civil servants. They just don't have enough incentive because it's very hard to fire them, unlike managers in the private sector.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#167

Earlier quoted context omitted.

> The right answer here is if the situation is that bad, make a very public long-term commitment to shift to something else & up-level your IT department to be able to execute multi-year projects competently. The problem is that there isn't much in terms of alternatives, especially not if you prefer to have one software / vendor / tech stack. - In groupware, there used to be Lotus Notes, but that went down the drain…

Wine can run apps that access hardware without issues. The main problem is the catch-22: there's not much point in developing competitors to Microsoft's stack if businesses aren't going to ever consider them, and government departments won't consider alternatives if they can't get everything from a single vendor in a 100% risk free manner thanks to the "nobody ever got fired for buying Microsoft" and "one throat to c…

> Wine can run apps that access hardware without issues.

Depends on the hardware. Stuff like mice, keyboards or game controllers yes, as long as they're supported by the host OS stack (don't get me started on bluez and the clusterfuck that's Linux audio in general). But anything dealing with user-mode USB drivers (looking at you Samsung ODIN or a truckload of webcams) or more exotic hardware is out of luck.

> Governments do this to themselves. The USG doesn't even have to pick Microsoft. They could potentially sign contracts with Apple for workstation hardware and services, that would encourage and feed the alternative ecosystem based around Apple, or they could fund Linux, etc. They don't though.

Apple shot themselves into their own foot here by completely discontinuing their Intel x86 lineup. You can run Windows stuff on the M series SoCs but performance is atrocious (unless it's ARM Windows, but good luck finding software compatible with that oddity, no thanks to Qualcomm here who couldn't be arsed to put out actually usable chips for years).

As for Linux, there is already a huge amount of government funding into Linux because of servers and their support contracts. That's how RH, SuSE and the other commercial Linux distributions are surviving. The problem is the desktop software stuff, here the chicken-egg problem comes into force - and made worse by the fact that unlike Microsoft who can just decree whatever they want and the rest of the world has to accept it, FOSS projects are mostly driven-by-consensus, and if you're a commercial or government entity needing a feature you have to either fork off with all the cost that entails or herding cats and playing petty politics with people from all around the world (who might just block your idea out of principle after finding out you're working on behalf of the government/Monsanto/whoever is problematic these days, on top).

Re: Microsoft is a national security threat: ex-White House cyber policy director

#168

Earlier quoted context omitted.

You're thinking of the CIA. The NSA's job is to spy on citizens.

>The NSA's job is to spy on [US] citizens They're not supposed to (according to for example the Foreign Intelligence Surveillance Act of 1978). If a US citizen needs to be spied on by the US government, the FBI is supposed to do that.

What the spook box says and what's inside are two completely different things, by design.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#169
post #64
post #45

Earlier quoted context omitted.

States don't care.

Believe it or not, USA government cares at least a little. USA did not institute the draft even when fighting on two fronts (Afghanistan and Iraq). USA made up for the lack in manpower with technology: Reaper drones, cluster munitions, night vision, precise artillery, overwhelming air power.

I find the threat of policing and misery used for recruitment a tad bit worse than drafting.

Not that it matters, the state still doesn't care. It can't, it's not that kind of being.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#170
post #126

Earlier quoted context omitted.

Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.

The US government spent $6.1 TRILLION dollars in 2023. I don't think raising taxes is the solution to the government offering a more competitive wage.

Is your entire argument that it's a really big number? Are we afraid of big numbers? How much do you think it should spend? It's the federal government, they do a lot of stuff. Stuff costs money. We can complain about how they spend the money, or that the money is being wasted or stolen, but pointing out that it's a big number isn't a very convincing argument.
Post reply on HN