Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

161–170 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#161

Earlier quoted context omitted.

> legal team wants everyone to behave ethically at all times do you really believe that? compliance under scrutiny, more like it

The best job is sitting around and doing nothing. So ideally yes. But sure, ethically speaking when things get heated they will exploit every loophole they can find to avoid liability. So, lawful evil?

Even if everyone in the company magically complied with the wishes of the legal department, they would still have work to do. Defending the company against frivolous lawsuits and incoming regulations, suing competitors and other bad actors outside of the company, writing and evaluating contracts, and any internal legal consultation needed.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#162
post #157

Earlier quoted context omitted.

Well the Amazon ads in Ubuntu absolutely did happen, as well as the searches with the super key. [1] I'll admit it's maybe a bit of an extrapolation to assume that they're as bad as Microsoft, which is why I disclosed that I didn't have a ton of evidence for this. [1] https://www.gnu.org/philosophy/ubuntu-spyware.en.html I realize that GNU is sort of conspiratorial in its own right, but at least one entity seemed to…

Well, here are the facts (I was an insider at the time, and this is my testimony). Searches were anonymized and sent through Canonical servers to provide extended search result sets. This was configurable and could be disabled. Canonical of course had your IP address so they could reply, just like any and every HTTP server does. Your search query was not stored anywhere or aggregated, and it was not associated back t…

Yeah, fair enough, I'll admit what I said was probably reductive, and if you worked on it you certainly know a lot more than I do; obviously the engineers at Canonical aren't idiots and they're not mustache-twirling supervillains. Just to be clear, I did run Ubuntu on my laptop for quite awhile (for about two years starting immediately after ZFS got integrated support), and I did like it, so I don't mean to suggest it was a terrible product.

I guess I'm just always worried about for-profit companies, because their goal isn't necessarily always aligned with the customer's best interest.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#163

There's a pretty big caveat in this story which I feel is being looked over: "Disabling seamless SSO would have widespread and unique consequences for government employees, who relied on physical “smart cards” to log onto their devices. Required by federal rules, the cards generated random passwords each time employees signed on. Due to the configuration of the underlying technology, though, removing seamless SSO wou…

I mean... I guess the issue here is more that Microsoft didn't make customers aware of this flaw, and continued to sell the service.

Which... is exactly the articles point. They knew there was no secure way to administer it, and yet sold it anyway.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#164
post #92

Earlier quoted context omitted.

I have no broad evidence of this, but I suspect that the more beginner-friendly Linuxes are guilty of a lot of the sins that you laid out here. I seem to remember some controversy with Canonical recording your searches when hitting the super key, and Ubuntu having Amazon ads built in by default. People who love to geek out about computers can of course install Arch or Gentoo or NixOS Minimal and then audit the packag…

It's not surprising when a linux distribution was taken over by a capitalistic firm, it decided to forgo good values, and instead prioritized profits over everything else. > I really don't know how to fix this problem Stop using software made by companies that do bad things. Improve the software that doesn't.

I don't really think that's realistic. I can of course use software from non-profits or something at home, but we all work for a living, and every single job I've had has relied on software from a for-profit company in one way or another.

I guess I don't have to be an engineer, but even if I were to go be a cashier at Taco Bell or something, I would still be stuck using a proprietary POS system.

Unless I want to go live in a unabomber shed off the grid, I'm probably going to be stuck using software made by companies that do bad things. The software world is overwhelmingly run by Microsoft, Apple, Google, and Oracle (and probably a few others I'm missing), all of which do bad stuff all the time.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#165

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

Sheesh you guys are annoying.

- I do not see ads in “every nook and corner of Windows” and neither do you.

- I do not have a recorder installed on my Windows machines and neither do you.

- no one qualified to make that statement has said that Microsoft is the most secure platform.

It is so hard to listen to anyone who exaggerates at this level. If anything, it drives interest in Microsoft because these are all obviously false statements and some readers will wonder what your true motive is. You just raise suspicion in yourself.

At least you used a new account to distance yourself from any other identities you may have here. In fact I would say that was the only smart move in your entire comment.

Anyway, this is a damning revelation by the whistleblower and I hope Microsoft feels a good amount of pain because of it. NEVER make any decision with money as your sole input. It will always be a bad decision, and it’s just a matter of time until that decision bites you or someone you care about.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#166
post #154

Earlier quoted context omitted.

In the profit-center view, everything is either a cost center or a profit center. And it is nearly impossible to get anyone to truly care about a "cost center".

What if the company is providing only cybersecurity-related services? Could it be in this case, that everything is on profit side.

Sure, but to the client hiring them, it's a cost. We'll take the basic compliance package please, no need for any of the gold tier high security features.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#167
post #47

Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…

So software developers should be criminally liable for introducing security bugs?

Re: Microsoft Chose Profit over Security, Whistleblower Says

#168

Earlier quoted context omitted.

I think that it could be "security as a feature" Usually, a feature is included in a product if the marketing show that it will grow the business more than the cost of the feature. Maybe we can try the same idea ? "We identified this vulnerability, and it will impact X % of our customer and Y % will leave (+ reputation damage) so we will loose BIGNUMBER $. However, we can correct it for SMALLNUMBER $ in Z days. Decis…

They did that in FTA: > In the months and years following the SolarWinds attack, Microsoft took a number of actions to mitigate the SAML risk. One of them was a way to efficiently detect fallout from such a hack. The advancement, however, was available only as part of a paid add-on product known as Sentinel. So you sell me a submarine with screen doors, avoid fixing it for years, cripple internal processes that would…

I didn't think that it would be a feature to be charged for the consumer... only that it's a way to present it to top management

Re: Microsoft Chose Profit over Security, Whistleblower Says

#169
post #74

Earlier quoted context omitted.

Yes, massive companies are a nest of conflicting priorities. The sales team wants to do whatever it takes to win the deal, and the legal team wants everyone to behave ethically at all times. The board wants to be shocked(!) when it turns out those goals are in conflict, with the ethical side sometimes losing out, to remove any personal risk to themselves.

> legal team wants everyone to behave ethically at all times do you really believe that? compliance under scrutiny, more like it

Having worked with many lawyers... for the most part, yeah. Legal wants you to behave ethically at all times, not because they necessarily have some ideological commitment to ethics (though some do), but because it keeps the company out of lawsuits.

The overwhelming goal of a company's legal department is "don't get sued", followed by "if sued, lose as little money/leverage as possible".

In general the lawyer in the room is going to be far more risk-averse than the engineers, product people, sales people, or marketers.

The trick is that outside of some limited circumstances the legal department at companies are not the final say. Many lawyers who "go in house" (i.e., quit a private outside firm and go work directly for a company) find this frustrating. They come into a room, say "don't do that", and then a few weeks/months/years later someone did it and now they have to prepare for a lawsuit.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#170

Earlier quoted context omitted.

Fair enough. I haven't used Debian in quite awhile (I think since 2009 or so?), so I can't speak to current stuff, but I do remember it being pretty hard to install then. I'm sure they have refined it considerably since then, and of course I am fifteen years more experienced now than I was. Personally it's hard for me to go back after I accepted the dogma of NixOS, but maybe if I manage to talk my parents into using…

install arch. not even kiding. make a "shutdown" button on the desktop that locks everything and do a full upgrade. any issue is solved with, try tomorrow after a reboot. you'd be surprised how fast fixes arrive at rolling distros

I do NixOS-minimal. As far as I'm aware it doesn't really add any runtime overhead in comparison to Arch, the package manager is generally quite good at figuring out which changes are going to break your system, and everything is snapshotted on every rebuild so for the most part I can be fearless. Doing a full upgrade is generally as straightforward as pointing to the latest version's repo and doing something like `sudo nixos-rebuild switch --upgrade`.

That works great for a geeky dude like me, but I don't think I'll ever be able to convince my parents on the beauty of NixOS, so having a straightforward mypackage.deb thing that they can download and click on to install stuff probably would be an easier sell.

I ran Arch for about a year, and I liked it, but I had to abuse the `snapper` tool because I was constantly breaking things with the video driver and the like. It worked but I personally think that NixOS's model is just more elegant.

Post reply on HN