Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

181–190 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#181

I've been told by current military folks that they are forced to use outdated windows (the ones without security updates) on official military computers on base. So this is where they access emails, surf the web, and all of that. They had to use IE instead of the evergreen edge browser. It's well known among the people who serve that it's a joke.

Not just on base. I had a conversation with a three star general. He remarked that while our warships had separate software and hardware for systems and fire control, the rest of of the ship’s IT ran on Windows. Supposedly, there was no connection between the two, but LOL.

Why LOL? These are separate systems/networks. Even warships need boring admin things like email, internet, identity management, etc. Plus the systems that go on these ships are heavily customized not just straight out of the box.

Source: was IT on a destroyer

Re: Microsoft is a national security threat: ex-White House cyber policy director

#182
post #114

Earlier quoted context omitted.

Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.

This is a straw man. Even if the top richest people paid an additional 16 billion in taxes that would run the gov for like a day. Our problem is with spending.

I’m not sure where that 16 billion figure came from, but what about the top 100 businesses?

The ones that have been gaming the tax system for 3 decades?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#183
post #114

Earlier quoted context omitted.

This is a straw man. Even if the top richest people paid an additional 16 billion in taxes that would run the gov for like a day. Our problem is with spending.

I agree. We don't spend enough money on everything, most notably housing.

The top earners only need so many houses and places to live, even including corporate housing.

The median population doesn’t have the money to spend.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#184
post #127

Earlier quoted context omitted.

Yes, the GS scale is a problem. My point was that it’s not a problem because we’re trying to save money – if that were the case, someone would notice that raising the cap to allow a $300k civil service job is cheaper than allowing the same job to be performed by a $500k contractor who takes home less and is replaced more frequently. Politics enters the picture because the pay cap is derived from the salaries for poli…

Yes, but “saving money” is your point and strawman; I never said anything about saving money, nor did I imply it. GS in general cannot grow when the market pay was distorted by both lack of tax funds; and when those driving market pay has a disproportionate amount of wealth to corner the labor market, in order to prevent the hiring of engineers by other industries.

I think you misunderstood: I agree that lack of tax funds is a problem in other areas but in this specific case it isn’t because the same or greater amount of money is already being spent.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#185

Earlier quoted context omitted.

Yup. When a VC-backed company goes bankrupt, no one bats an eye. When Solyndra's loans go bad, even though it was a tiny fraction of the government's green energy portfolio, you get headlines and congressional hearings.

How many middle class workers were robbed through income tax to pay for the $524million dollars lost on solindra? Government money totally ruins any private business, to the tune of a huge party where everyone takes as much as possible with no accountability

How many orders of magnitude more money is “robbed” by Comcast/Verizon/Charter, the medical industry, manufacturers who hiked prices up during the pandemic, etc.? Large organizations of all persuasion need oversight but that doesn’t mean we should give up on the concept any more than Enron meant we should give up on the stock market or private energy companies.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#186

To be more accurate, the leadership of Microsoft's lack of prioritizing security, aka basic quality of product, is a national security threat. A similar claim could obviously be made of Boeing. Just imagine what is happening in their military contracts which we are not allowed to hear about. Looking at the projects which we are allowed to know about, airliners and Boeing's Starliner, clearly Boeing management needs t…

[deleted]

Re: Microsoft is a national security threat: ex-White House cyber policy director

#187
post #47

Earlier quoted context omitted.

Certainly. It’s not like giving them the source code would increase risk significantly, if the software is designed well. I think it would actually strengthen as more researchers would study and submit contribs. I think Linux is as or more secure than windows and it’s open source. There’s tons of sensitive systems that are open source. It’s a design fallacy that security through obscurity is good.

>It’s a design fallacy that security through obscurity is good. Yet, still obscurity increases security. Reverse engineering is not trivial and raises the bar.

Any relevant links? I can share this: https://blog.invisiblethings.org/2008/09/02/three-approaches...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#188
post #66

Earlier quoted context omitted.

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

The US government isn't in need of a thousand high-skilled hackers. They are in need of a million normal employees with some basic security awareness. Anyone with a modicum of skill can find thousands of areas to improve. The issue is that almost nobody is in a position to get anything changed. Even basic software choices are a multi-year epic.

Well I obviously have no clue what the numbers are on the offensive side doubt they are smaller than a thousand. But there are def thousands of cyber security professionals working for government through myriad of contractors purely because of caps.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#189
post #66

Earlier quoted context omitted.

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

Um, NASA? The government is able to employ tons of smart people that could be making way more money elsewhere. They might not get the absolute best security people in the world, but they could get good enough - as good as they're getting from MS for a fraction of the price. Additionally, government salaries aren't terrible when you factor in the pension. Most people want the money now. But if you want financial secur…

> Additionally, government salaries aren't terrible when you factor in the pension. Most people want the money now. But if you want financial security in the future - that's a reason a lot of people chose to work for the Fed.

This varies by agency and field. The older pension system was replaced with a newer model a while back so a prospective federal employee is looking at the combination of effectively a 401k, a pension of 1% top salary per year of service, and social security. That’s not bad but your salary is capped at under $200k so you're not getting anyone with IT skills turning down FAANG positions unless it’s for a cause they support (NASA, the VA, etc. can do that a lot more effectively than Agriculture, etc.). In other professions, of course, that can be pretty different – if you’re an academic who isn’t able to/interested in switching careers to ad-tech, that might be a great job compared to getting in a cage fight for a handful of tenure-track positions.

This matters a lot for security because the defense needs to be everywhere. NASA will never run out of people who want to work on robots because rovers are cool; the IRS needs people who can modernize internal business systems and that’s not only not cool but will get mockery from the more clueless people they know.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#190
post #162

Earlier quoted context omitted.

> Nice strawman. It is harder to fire govt employees than to fire private employees. Disagree? Let’s see, so it’s not a straw man when you say government employees are “essentially unfirable” but it is when someone corrects you?

Lets ignore the personal back and forth, and get back to the argument. It is harder to fire govt employees than to fire private employees. Disagree? At-will employment law doesn't apply to government entities. A very consequential law is different for private vs govt employees. > The managers you think can’t direct civil servants directly aren’t magically more capable of selecting and overseeing contracts, either. Ne…

> Lets ignore the personal back and forth, and get back to the argument.

I mean, were you not attempting to make an argument when you said that government employees were “essentially unfirable”? Your argument just sucked/was factually incorrect and you want to steer away from the “interpersonal” aspect of someone pointing that out.

It’s gauche to point this out on HN but you aren’t engaging in good faith here - wnd when someone else engages you in actual good-faith you fall back to juvenile debate-club attempts to frame them as the wrongdoer.

That’s highly rude and a bad attitude and approach to bring to this community. Act better and take some accountability for your own misbehavior.

Post reply on HN