Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

51–60 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#51
post #47

Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…

[deleted]

Re: Microsoft Chose Profit over Security, Whistleblower Says

#52

Earlier quoted context omitted.

This comment sounds hyperbolic, but it really isn't. It's really bad. This has been my experience with Microsoft employees also. In my experience, what makes for bad software is PM and engineering hubris. You definitely need some vision and confidence as just following user feedback is a recipe for terrible software as well. The key is to find the right balance and straddle that line. If it's been long enough for ins…

Just wanted to say that I thought the Windows Phone (the last version of such) was relatively nice. It had a decent developer experience, but was pretty much an also ran and didn't have enough market share to overcome mindshare for first party apps. When so many first apps were iOS first and Android later, throwing a third option in the mix just missed the mark more often than not. I was already in the Android ecosys…

I didn't get a Windows phone because i don't trust Microsoft. A friend had one and it was really ok, but no way for me.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#53
post #47

Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…

Wasn't there something a bit like that with the Morandi bridge that collapsed in Italy?

(There was definitely something like that with the Mottarone cable car that had been running for years with the safety catch disabled. When the tow-rope snapped, wiht no catch, the cabin rushed down and killed everyone on board.)

Re: Microsoft Chose Profit over Security, Whistleblower Says

#54
post #38

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

Isn’t there a point when a company becomes so big and so impactful to multiple layers of our life, that it should be impossible for them to continue focusing on profit alone? I’m not talking about regulation per se, but holding humans in charge of such corps more accountable.

I don't think it's going to happen unless we decide to nationalize private services that are vital to people.

Why don't we have a public maps system, or a content sharing platform? Services like google maps/search or youtube by now are part of the infrastructure of our society.

The same way as roads/railways or energy production are publicly owned in many countries the same should happen for digital services. In good parts of Europe railways are publicly built and maintained while the trains are privately owned.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#55
post #44

As per usual, executive platitudes around "security first" don't matter. If you pay and promote people for features, and don't reward security culture, people are not dumb: they and the management layers will optimize for that. I don't know how to design incentives to solve for this, but this is always going to be the way it is.

I think that it could be "security as a feature"

Usually, a feature is included in a product if the marketing show that it will grow the business more than the cost of the feature. Maybe we can try the same idea ?

"We identified this vulnerability, and it will impact X % of our customer and Y % will leave (+ reputation damage) so we will loose BIGNUMBER $. However, we can correct it for SMALLNUMBER $ in Z days. Decision ?"

Re: Microsoft Chose Profit over Security, Whistleblower Says

#56
I worked at Microsoft the entire time period covered in this article. I've interacted with MSRC on multiple issues with the product team I'm on. My experience inside Microsoft is not at all consistent with what the whisteblower is saying, for what it's worth. It's completely unrecognizable, in fact - and I'm having a hard time reconciling what I'm seeing with what I'm reading here.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#57
post #48

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

You might want to read the actual article. My understanding is that it was a two-part exploit: 1) The Solarwinds product was hacked to allow backdoor access to organizations' on-prem networks. 2) The hackers then took advantage of the "Golden SAML" vulnerability in Microsoft's Active Directory Federation Service (AD FS) to leapfrog via "seamless SSO" from the on-prem network into the organization's cloud resources ho…

> You might want to read the actual article.

ProPublica articles in general are structured in a way that makes them a pita to extract actual useful information from.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#59

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

>What is "the product" ?

Human attention sink where you can throw ads and other propaganda, what else?

Re: Microsoft Chose Profit over Security, Whistleblower Says

#60
I work in infosec, and this sounds like a communication failure on the whistleblower's part.

Contrary to what many people believe, the profits should be prioritized over security for the most companies, that's only natural (after all, they don't generate any profits themselves, typically). The key is finding the right balance for this tradeoff.

Business leaders are the ones that are responsible for figuring out the acceptable risk level. They already deal with that every day, so it's nonsensical to claim they aren't capable of understanding risk. InfoSec's role for the most part is being a good translator, by identifying the technical issues (vulnerabilities, threats, missing best practices) that go beyond the acceptable risk profile and to present these findings to the business stakeholders, using the language they understand.

Either the guy wasn't convincing enough, or he failed to figure out the things business cares about & present the identified risk in these terms.

Post reply on HN