Earlier quoted context omitted.
> legal team wants everyone to behave ethically at all times do you really believe that? compliance under scrutiny, more like it
The best job is sitting around and doing nothing. So ideally yes. But sure, ethically speaking when things get heated they will exploit every loophole they can find to avoid liability. So, lawful evil?
Microsoft Chose Profit over Security, Whistleblower Says
161–170 of 318 posts
Re: Microsoft Chose Profit over Security, Whistleblower Says
#162Earlier quoted context omitted.
Well the Amazon ads in Ubuntu absolutely did happen, as well as the searches with the super key. [1] I'll admit it's maybe a bit of an extrapolation to assume that they're as bad as Microsoft, which is why I disclosed that I didn't have a ton of evidence for this. [1] https://www.gnu.org/philosophy/ubuntu-spyware.en.html I realize that GNU is sort of conspiratorial in its own right, but at least one entity seemed to…
Well, here are the facts (I was an insider at the time, and this is my testimony). Searches were anonymized and sent through Canonical servers to provide extended search result sets. This was configurable and could be disabled. Canonical of course had your IP address so they could reply, just like any and every HTTP server does. Your search query was not stored anywhere or aggregated, and it was not associated back t…
I guess I'm just always worried about for-profit companies, because their goal isn't necessarily always aligned with the customer's best interest.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#163There's a pretty big caveat in this story which I feel is being looked over: "Disabling seamless SSO would have widespread and unique consequences for government employees, who relied on physical “smart cards” to log onto their devices. Required by federal rules, the cards generated random passwords each time employees signed on. Due to the configuration of the underlying technology, though, removing seamless SSO wou…
Which... is exactly the articles point. They knew there was no secure way to administer it, and yet sold it anyway.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#164Earlier quoted context omitted.
I have no broad evidence of this, but I suspect that the more beginner-friendly Linuxes are guilty of a lot of the sins that you laid out here. I seem to remember some controversy with Canonical recording your searches when hitting the super key, and Ubuntu having Amazon ads built in by default. People who love to geek out about computers can of course install Arch or Gentoo or NixOS Minimal and then audit the packag…
It's not surprising when a linux distribution was taken over by a capitalistic firm, it decided to forgo good values, and instead prioritized profits over everything else. > I really don't know how to fix this problem Stop using software made by companies that do bad things. Improve the software that doesn't.
I guess I don't have to be an engineer, but even if I were to go be a cashier at Taco Bell or something, I would still be stuck using a proprietary POS system.
Unless I want to go live in a unabomber shed off the grid, I'm probably going to be stuck using software made by companies that do bad things. The software world is overwhelmingly run by Microsoft, Apple, Google, and Oracle (and probably a few others I'm missing), all of which do bad stuff all the time.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#165> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…
- I do not see ads in “every nook and corner of Windows” and neither do you.
- I do not have a recorder installed on my Windows machines and neither do you.
- no one qualified to make that statement has said that Microsoft is the most secure platform.
It is so hard to listen to anyone who exaggerates at this level. If anything, it drives interest in Microsoft because these are all obviously false statements and some readers will wonder what your true motive is. You just raise suspicion in yourself.
At least you used a new account to distance yourself from any other identities you may have here. In fact I would say that was the only smart move in your entire comment.
Anyway, this is a damning revelation by the whistleblower and I hope Microsoft feels a good amount of pain because of it. NEVER make any decision with money as your sole input. It will always be a bad decision, and it’s just a matter of time until that decision bites you or someone you care about.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#166Earlier quoted context omitted.
In the profit-center view, everything is either a cost center or a profit center. And it is nearly impossible to get anyone to truly care about a "cost center".
What if the company is providing only cybersecurity-related services? Could it be in this case, that everything is on profit side.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#167Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…
Re: Microsoft Chose Profit over Security, Whistleblower Says
#168Earlier quoted context omitted.
I think that it could be "security as a feature" Usually, a feature is included in a product if the marketing show that it will grow the business more than the cost of the feature. Maybe we can try the same idea ? "We identified this vulnerability, and it will impact X % of our customer and Y % will leave (+ reputation damage) so we will loose BIGNUMBER $. However, we can correct it for SMALLNUMBER $ in Z days. Decis…
They did that in FTA: > In the months and years following the SolarWinds attack, Microsoft took a number of actions to mitigate the SAML risk. One of them was a way to efficiently detect fallout from such a hack. The advancement, however, was available only as part of a paid add-on product known as Sentinel. So you sell me a submarine with screen doors, avoid fixing it for years, cripple internal processes that would…
Re: Microsoft Chose Profit over Security, Whistleblower Says
#169Earlier quoted context omitted.
Yes, massive companies are a nest of conflicting priorities. The sales team wants to do whatever it takes to win the deal, and the legal team wants everyone to behave ethically at all times. The board wants to be shocked(!) when it turns out those goals are in conflict, with the ethical side sometimes losing out, to remove any personal risk to themselves.
> legal team wants everyone to behave ethically at all times do you really believe that? compliance under scrutiny, more like it
The overwhelming goal of a company's legal department is "don't get sued", followed by "if sued, lose as little money/leverage as possible".
In general the lawyer in the room is going to be far more risk-averse than the engineers, product people, sales people, or marketers.
The trick is that outside of some limited circumstances the legal department at companies are not the final say. Many lawyers who "go in house" (i.e., quit a private outside firm and go work directly for a company) find this frustrating. They come into a room, say "don't do that", and then a few weeks/months/years later someone did it and now they have to prepare for a lawsuit.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#170Earlier quoted context omitted.
Fair enough. I haven't used Debian in quite awhile (I think since 2009 or so?), so I can't speak to current stuff, but I do remember it being pretty hard to install then. I'm sure they have refined it considerably since then, and of course I am fifteen years more experienced now than I was. Personally it's hard for me to go back after I accepted the dogma of NixOS, but maybe if I manage to talk my parents into using…
install arch. not even kiding. make a "shutdown" button on the desktop that locks everything and do a full upgrade. any issue is solved with, try tomorrow after a reboot. you'd be surprised how fast fixes arrive at rolling distros
That works great for a geeky dude like me, but I don't think I'll ever be able to convince my parents on the beauty of NixOS, so having a straightforward mypackage.deb thing that they can download and click on to install stuff probably would be an easier sell.
I ran Arch for about a year, and I liked it, but I had to abuse the `snapper` tool because I was constantly breaking things with the video driver and the like. It worked but I personally think that NixOS's model is just more elegant.