Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

41–50 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#42

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

> However, all things have bugs.

There are bugs and there are critical flaws you’ve been warned about. This is the latter.

The fact that this was known by Microsoft but not fixed is the story.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#43

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

> Harris said he pleaded with the company for several years to address the flaw in the product, a ProPublica investigation has found. But at every turn, Microsoft dismissed his warnings, telling him they would work on a long-term alternative — leaving cloud services around the globe vulnerable to attack in the meantime.

That is not a screw-up, that is a deliberate decision.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#44
As per usual, executive platitudes around "security first" don't matter.

If you pay and promote people for features, and don't reward security culture, people are not dumb: they and the management layers will optimize for that.

I don't know how to design incentives to solve for this, but this is always going to be the way it is.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#45

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

Microsoft had a known, high consequence, security flaw that they did not acknowledge or fix, they had evidence that indicated it had already been exploited and they knew they had limited to no ability monitor for exploitation. This choice lead directly to the SolarWinds hack that happened in 2019 was discovered in late 2020 and acknowledged by the USG in early 2021.

Many companies make bad choices around security for profit, however that factors I listed above make this extremely egregious.

I would seriously question any use of Microsoft products in any security conscious organization after this reveal. I also hope that anyone negatively effected by the Solar Winds sue Microsoft for knowing about the vulnerability for years without fixing it or disclosing it.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#46
post #26
post #13

Earlier quoted context omitted.

I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…

Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.

then the laws need to change so bad security costs companies money.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#47
Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue because it didn‘t want to loose contracts selling more flawed bridges. The public would justifiably go nuts, and there would be legal consequences for everyone involved.

What is different in our industry that companies (and managers) get away with such malice?

Re: Microsoft Chose Profit over Security, Whistleblower Says

#48

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

You might want to read the actual article.

My understanding is that it was a two-part exploit:

1) The Solarwinds product was hacked to allow backdoor access to organizations' on-prem networks.

2) The hackers then took advantage of the "Golden SAML" vulnerability in Microsoft's Active Directory Federation Service (AD FS) to leapfrog via "seamless SSO" from the on-prem network into the organization's cloud resources hosted by Microsoft.

The article is all about how various Microsoft leaders and staff did not fix #2, because many said it would never be an actual issue exposed to the world.

This is extra damning because Microsoft is selling components at the core of both governments' on-prem and cloud systems, so if they don't take security extra seriously, their systems can present passive vulnerabilities.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#49

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

The Microsoft bribes scandal broke not too long after I had to take the "hey don't do bribes" training at Microsoft.

That event really drove home for me the fact that all of the trainings, emails, processes, etc. are mostly plausible deniability. There are people who care about security at MS. I know, I've met them, but for the most part all of this exists so that Satya can plausibly say in court or in front of congress, "well we told them to do security better. This is clearly the fault of product teams or individual contributors, not Microsoft policy and incentives."

Re: Microsoft Chose Profit over Security, Whistleblower Says

#50
> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,”

corporate morality is a Potemkin village. It's all about the profit and appeasing the shareholder, baby!

is anybody honestly surprised at this point? The abbreviation of "M$" is well deserved despite small OSS contributions and attempts to PR their way out of previous history (ie, United States v. Microsoft Corp. [2001])

Post reply on HN