Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

21–30 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#22
Execs should absolutely be held responsible, but the human factor is always there. Many times people will take the easy route and get worn down by security practices or roadblocks.

I think it's too easy to go "alright focus on security" and then expect it trickle down and figure itself out.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#25

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

This isn't about Microsoft, per se. This is about the fact that there's no risk for companies who do, even if they're bidding for government work. Hopefully whistleblowers making these things public will lead to the public putting pressure on their elected officials to actually make some regulations with teeth in this area. I'm not holding my breath, but it is something I consider in the voting booth.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#26
post #13

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…

Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#27
post #17
post #13

Earlier quoted context omitted.

I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…

Obviously, nobody is going to outright admit they put profits above security; indeed, they will often state the opposite. But their closely-held beliefs will shine through when it comes time to make decisions and the outcomes of those decisions are exposed to their customers and to the public.

Does Bill or Satya write code anymore? It could very well be that they consider security the top priority but it's a moot point because they're so removed from operations.

Although I would suspect that you're effectively right in that they either don't have it as a top priority or think they do but have a reveal preference of they don't. For example, an engineer that does rigorous security testing and finds nothing as well as launches one project gets promoted less often than an engineer that launches two projects and doesn't do rigorous security testing.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#28
post #13

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…

Unless you care about your review and promotion, in which case do features.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#29
This whole article seems a bit odd to me. What is "the product" ?

Presumably this is not related to earlier problems with SolarWinds.

Did MS screw up. Yes.

However, all things have bugs.

I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one.

I am sure the NSA is sitting on a pile of them.

Whereas the developers have to think about everything that can happen and protect against it.

Does this make Microsoft different from its competitors?

I think Microsofts strategy is somewhat similar to Linus:

Where security patches are often not part of new releases due to the burden of establishing what the consequences of bigger changes would be, and the fact that security people dont do sane things.

(But you can of course pull them and make it part of an in-house distro.

https://lkml.iu.edu/hypermail/linux/kernel/1711.2/01357.html

Post reply on HN