Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

31–40 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#31

Sounds like the same Microsoft culture as has always been. Like a cult. It can do no wrong. The conversation with Microsoft businesspeople at conferences was always the same: Microsoft has no deficiencies, there is nothing it isn't working on and it has a solution for every possible problem. Other sources of software do not exist. There is only Microsoft. Total illusion put forth by delusional employees. The outside…

I'll give you a 4-letter word... Zune /s

Re: Microsoft Chose Profit over Security, Whistleblower Says

#32
post #21

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

Let's Encrypt Google Trust Services Disclaimer: I've worked in both of these :)

What products do those two companies sell?

Re: Microsoft Chose Profit over Security, Whistleblower Says

#33

Sounds like the same Microsoft culture as has always been. Like a cult. It can do no wrong. The conversation with Microsoft businesspeople at conferences was always the same: Microsoft has no deficiencies, there is nothing it isn't working on and it has a solution for every possible problem. Other sources of software do not exist. There is only Microsoft. Total illusion put forth by delusional employees. The outside…

This comment sounds hyperbolic, but it really isn't. It's really bad. This has been my experience with Microsoft employees also. In my experience, what makes for bad software is PM and engineering hubris. You definitely need some vision and confidence as just following user feedback is a recipe for terrible software as well. The key is to find the right balance and straddle that line. If it's been long enough for ins…

Just wanted to say that I thought the Windows Phone (the last version of such) was relatively nice. It had a decent developer experience, but was pretty much an also ran and didn't have enough market share to overcome mindshare for first party apps. When so many first apps were iOS first and Android later, throwing a third option in the mix just missed the mark more often than not.

I was already in the Android ecosystem and far less cynical at that point about Google.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#34
post #21

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

Let's Encrypt Google Trust Services Disclaimer: I've worked in both of these :)

Any company with sufficient size will fail to incentivise the things they claim at the top, unfortunately the impacts of decisions (especially during austerity) are poorly understood, so even the supposedly best intending will fail once you reach a size

Re: Microsoft Chose Profit over Security, Whistleblower Says

#36
post #17

Earlier quoted context omitted.

Obviously, nobody is going to outright admit they put profits above security; indeed, they will often state the opposite. But their closely-held beliefs will shine through when it comes time to make decisions and the outcomes of those decisions are exposed to their customers and to the public.

Does Bill or Satya write code anymore? It could very well be that they consider security the top priority but it's a moot point because they're so removed from operations. Although I would suspect that you're effectively right in that they either don't have it as a top priority or think they do but have a reveal preference of they don't. For example, an engineer that does rigorous security testing and finds nothing a…

[deleted]

Re: Microsoft Chose Profit over Security, Whistleblower Says

#37
post #19
post #13

Earlier quoted context omitted.

I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…

Profit is an implicitly assumed first priority for basically every business, otherwise the business wouldn't be around. I don't know of any company that has profit in their slogan, or in the core values statement, etc.

I don’t put “breathe” at the top of my TODO list, either.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#38

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

Isn’t there a point when a company becomes so big and so impactful to multiple layers of our life, that it should be impossible for them to continue focusing on profit alone?

I’m not talking about regulation per se, but holding humans in charge of such corps more accountable.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#39
> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees.

Satya's model of making security a priority at Microsoft:

- Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for?

- Install a recorder which records everything you do. For the benefit of users of course - you know, what if a user missed an ad and wants to go back and see what they missed.

- Send a mail to your employees and tell them "Do security". Mission accomplished - Microsoft is now the most secure platform.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#40

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

It is true that nothing is 100% secure. Sitting on a major security vulnerability internally with a motivated employee pushing to fix it and doing nothing for business reasons is not negligence, but malice. People in the chain of command need to be held accountable for this.
Post reply on HN