Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

211–220 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#211

Earlier quoted context omitted.

> Those "mediocre H1Bs" work their ass off compared to non-H1Bs because they get laid off/fired and deported on short notice with barely enough or sometimes no time to sell their belongings if they don't perform [1] H1Bs wouldn’t be so easy to fire if the skillset were rare or difficult to fill. Instead, companies are gaming the H1B lottery to create much lower-paid indentured servants while a sliver of the business…

> H1Bs wouldn’t be so easy to fire if the skillset were rare or difficult to fill. By the same token a good chunk of government employees would be paid higher if their skillset were rare or difficult to fill, and they worked hard. The good ones that work hard switch to the private sector, even if the pay isn't much higher, so that they can get stuff done and not be surrounded by folks just existing while collecting a…

Within your disdain for government workers is a small sliver of truth. One problem with the Federal government--and why contractors are preferred--is that Government Schedule pay is decent for some jobs and insufficient for others.

For software engineers--and the reason contracting is better--is that government schedule pay is far below market. But you see the same problem even in private industries like Lockheed Martin, where the brightest engineers (with security clearances) are really doubling/moonlighting with other jobs and the managers look the other way.

Also: The private sector is extremely inefficient, when it's handling areas of high upfront costs/high risk. Private military companies

If you want to defund government, start by tearing down the TSA which nobody in any party believes is anything but a job-creating sham. Of course, the loudest calls for defunding or non-growth are for deparatments that provide real value--like the FDA or the IRS.

So while you're happy the government is being defunded, most US citizens don't feel like promoting a national security problem for short-term gains.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#212
post #204

Earlier quoted context omitted.

The top earners only need so many houses and places to live, even including corporate housing. The median population doesn’t have the money to spend.

Isn't that a problem caused by inflation which is driven (right now) by gov spending.

No. Artificial inflation where the median wage doesn't adjust is from a handful of key industries and it's rippled across.

Focusing on government spending is a distraction.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#213

Earlier quoted context omitted.

You're thinking of the CIA. The NSA's job is to spy on citizens.

>The NSA's job is to spy on [US] citizens They're not supposed to (according to for example the Foreign Intelligence Surveillance Act of 1978). If a US citizen needs to be spied on by the US government, the FBI is supposed to do that.

> If a US citizen needs to be spied on by the US government, the FBI is supposed to do that.

Semi-autonomous collections systems generally aren't capable of determining citizenship.

Once the data is at rest, much of it is made available to a surprisingly large number of federal and state agencies - and even local agencies via fusion centers, etc.

The system is built for dissemination. Within that, some checks on citizenship could be possible for some data. But even then, once a foreign person is part of the data/comms transaction, all the related data is available - citizenship of the other participants is no barrier.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#215
post #196

Earlier quoted context omitted.

If so, you don't seem to understand why the DoD is failing to pass one, but are very well versed in the outrage you're supposed to feel when it does.

Care to enlighten me?

It's an enormous organization (one of the largest in the world) that is largely getting audited on physical objects that either spend 99% of their life sitting in stockpiles, or getting actively used and discarded.

Passing an audit isn't having its checkbook balanced. Passing an audit is like your employer delivering a full and accurate account of how many chairs it owns, as well as providing all the necessary paper trail for how all of them were acquired, moved, and discarded.

Doable in a 5-person company, or a 50-person company, next to impossible in a 5,000-person company, actually impossible in a 500,000 person company.

And the DoD has hundreds of thousands of different types of such items to keep track of, all of which were tracked by disparate physical-fingers-counting-stuff accounting systems, that were historically not up to the expected standards. Updating them and reconciling all of them is a long process, which the DoD is working through.

I hate war departments as much as the next liberal, but I also recognize that this is an incredibly difficult ask.

And that the failures are generally not caused by Lt. Billy Bob filching Stinger missiles to sell to some warlord in East Oblastan.

The grift in the DoD comes from contracts for buying more crap that it doesn't need, or for paying good money for contract work that doesn't get done (Iraq, Afghanistan), not from having stuff that was bought 'fall off the back of the truck'. The organization "has* an audit problem, but it's main issue is one of procurement.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#216

Earlier quoted context omitted.

I think that's maybe more due to lack of demand/effort than any fundamental technical limitation. You can run USB drivers in user mode on both Linux and Windows. If someone paid enough for such support to be added, it'd appear. A lot of the software getting hacked isn't even truly Windows-specific stuff to begin with though. VPN appliances, firewalls, they're probably all running out of date Linux distros. Active Dir…

> You can run USB drivers in user mode on both Linux and Windows. Yeah, but you'd need to rewrite the whole Windows app for a native Linux or macOS port because WINE to my knowledge can't access devices even if there were a Linux/macOS driver. > Active Directory servers could have some open source competitor too, aren't they mostly Kerberos? AD is so much more than just LDAP+Kerberos. You have a fully integrated file…

https://wiki.winehq.org/Hardware

"Wine includes some limited support for direct hardware access, including running native Windows drivers. This comes with several restrictions, but we still have been able to successfully access some native devices."

"For example, the SteelSeries USB mouse driver offers the ability to modify the mouse's LED settings as well as simply driving the mouse, and in this case Wine is able to pass through the LED settings"

Re: Microsoft is a national security threat: ex-White House cyber policy director

#217

Earlier quoted context omitted.

Almost all the work done at NASA is done by contractors that work in better conditions than allowed for by the federal payscale.

I mean this is categorically not true, but definitely makes for a pithy comeback.

At least in the Shuttle era, I once heard it said in a way that was something along the lines of “contracted support is basically working to rule; NASA employee components are working to solve problems.”

Referring here to contractors as the body of private sector contract organizations that had outsourcing contracts for various support roles, not the individual people. Speaking to working environment.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#218

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

The Pentagon can’t even pass an audit for the past 6 years, but yeah Microsoft is the national security threat.

The Marine Corp actually just became the first military branch to pass an audit:

https://www.military.com/daily-news/2024/02/24/marine-corps-...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#219
post #215

Earlier quoted context omitted.

Care to enlighten me?

It's an enormous organization (one of the largest in the world) that is largely getting audited on physical objects that either spend 99% of their life sitting in stockpiles, or getting actively used and discarded. Passing an audit isn't having its checkbook balanced. Passing an audit is like your employer delivering a full and accurate account of how many chairs it owns, as well as providing all the necessary paper…

Wow, thank you for the detailed write-up. Your points make a lot of sense and I do think the general hate for the military industrial complex makes people look at these failed audits as malicious, probably prematurely.

Do you think the Pentagon will be able to pass that audit anytime soon (within the decade)?

Re: Microsoft is a national security threat: ex-White House cyber policy director

#220

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

we have a company that has a monopoly that is honestly unimaginable (how does someone monopolize computation of all things...) and we know that all monopolies require government enforcement to prevent others from competing... then we know that there's no such thing as a conflict between Microsoft and the us government the us govt is to serve Microsoft and that's that. any conversation like this about the merits of Mi…

Then go after them for monopolistic abuses. Arguably Lina Khan is the first FTC chair to be making noise about it yet the only thing about Microsoft has been their OpenAI partnership because it's sexy & nothing about their traditional marketplace participation. The EU is going after them a bit more aggressively & having some success. Ultimately this would still be the US government's failings - claiming that makes Microsoft a national security threat is a joke & disingenous.

I know the history of MS anti-trust fairly well having grown up during the core part of their monopolist years - now they're part of the familiar oligopaly that's strangling tech.

> and we know that all monopolies require government enforcement to prevent others from competing...

Do we know that? That may be true of government run monopologies, but I'm pretty sure most marketplace monopolies rely on lack of government enforcement. For example, here's some analysis showing how US case law makes the government wary of going after Amazon for driving Quidsi out of business & forcing an acquisition by Amazon: https://cei.org/blog/amazons-private-labels-dont-threaten-co.... Ironically US does enforce rules against dumping from international players which shows that it realizes the harm that such activity can have, it just chooses to allow it for domestic players abusing smaller domestic players.

Post reply on HN