Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

181–190 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#181
post #92

Earlier quoted context omitted.

I have no broad evidence of this, but I suspect that the more beginner-friendly Linuxes are guilty of a lot of the sins that you laid out here. I seem to remember some controversy with Canonical recording your searches when hitting the super key, and Ubuntu having Amazon ads built in by default. People who love to geek out about computers can of course install Arch or Gentoo or NixOS Minimal and then audit the packag…

> can of course install Arch or Gentoo or NixOS Minimal and then audit the packages that they're installing to see that there's no obvious security violations, but it's unrealistic to think that most non-software-engineer people are going to do that. It's a fantasy to think that random devs can audit kernel/security code. No single person can. Too many lines of code to audit (that you didn't write yourself). Even if…

Sorry, I guess I didn't really mean to imply I was going to dissect everything line by line, but I can at least look to see if every package in there is directly open-source and if there are any packages that are being pulled in that are frequent security concerns.

ETA: I know I can technically do that with Ubuntu or Fedora or OpenSUSE as well, it's not like it's a secret which packages they include, but what I like about NixOS Minimal or Arch is that I have to explicitly add every package I want. There are transitive dependencies obviously, so there of course can still be stuff on my machine I'm not happy with, but I still think it's better.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#182

Earlier quoted context omitted.

The Microsoft bribes scandal broke not too long after I had to take the "hey don't do bribes" training at Microsoft. That event really drove home for me the fact that all of the trainings, emails, processes, etc. are mostly plausible deniability. There are people who care about security at MS. I know, I've met them, but for the most part all of this exists so that Satya can plausibly say in court or in front of congr…

Microsoft has for over two decades been one of the largest and most sophisticated employers of security talent in the industry, and for a run of about 8 years probably singlehandedly created the market for vulnerability research by contracting out to vulnerability research vendors. Leadership at Microsoft is different today than when the process of Microsoft's security maturation took place, but I'll note that throug…

It would help if there weren't all these employees and ex-employees stepping forward to talk about how Microsoft is performative and naive about security. I won't go as far as to say that, but I will say I don't think my incentives as an IC lined up with the security-focused mindset that company execs tout publicly.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#183

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

About an ad missed. Are I'm the only one who would rewatch an ad on Youtube? There is no easy way to do it

Re: Microsoft Chose Profit over Security, Whistleblower Says

#184

Earlier quoted context omitted.

they sell market protection. to google. it makes crawlers much more expensive. makes everyone depend on their CDNs etc.

Are you referring to google trust services? I don't see how that applies to let's encrypt otherwise.

go make a cost analysis of crawling the entire internet once or twice a day on http vs https and report back

Re: Microsoft Chose Profit over Security, Whistleblower Says

#185

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

Sheesh you guys are annoying. - I do not see ads in “every nook and corner of Windows” and neither do you. - I do not have a recorder installed on my Windows machines and neither do you. - no one qualified to make that statement has said that Microsoft is the most secure platform. It is so hard to listen to anyone who exaggerates at this level. If anything, it drives interest in Microsoft because these are all obviou…

Hey Jer, please review the CELA policy about disclosing your employment connection to Microsoft.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#186

Earlier quoted context omitted.

install arch. not even kiding. make a "shutdown" button on the desktop that locks everything and do a full upgrade. any issue is solved with, try tomorrow after a reboot. you'd be surprised how fast fixes arrive at rolling distros

I do NixOS-minimal. As far as I'm aware it doesn't really add any runtime overhead in comparison to Arch, the package manager is generally quite good at figuring out which changes are going to break your system, and everything is snapshotted on every rebuild so for the most part I can be fearless. Doing a full upgrade is generally as straightforward as pointing to the latest version's repo and doing something like `s…

you still need a os. and i fail to see how nix would make video driver problem any better.

the problem with running debian is that fixes are often not backported, specifically for things end users will care about, like libre office

Re: Microsoft Chose Profit over Security, Whistleblower Says

#187

Earlier quoted context omitted.

> legal team wants everyone to behave ethically at all times do you really believe that? compliance under scrutiny, more like it

The best job is sitting around and doing nothing. So ideally yes. But sure, ethically speaking when things get heated they will exploit every loophole they can find to avoid liability. So, lawful evil?

[deleted]

Re: Microsoft Chose Profit over Security, Whistleblower Says

#188

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

Sheesh you guys are annoying. - I do not see ads in “every nook and corner of Windows” and neither do you. - I do not have a recorder installed on my Windows machines and neither do you. - no one qualified to make that statement has said that Microsoft is the most secure platform. It is so hard to listen to anyone who exaggerates at this level. If anything, it drives interest in Microsoft because these are all obviou…

You're getting downvoted for your tone most likely, but I agree with this statement:

> - I do not see ads in “every nook and corner of Windows” and neither do you.

As a professional "Windows user" logging 8+ hours a day on my PC, I see no ads. Unless you count "OneDrive" ads which in that case, would mean I see iCloud ads on my iPhone too. I'm fine with classifying these as ads, but I'm certainly not seeing them "in every nook".

Are these ads only bundled with a certain versions of Windows?

Disclaimer: I do not work for Microsoft or Apple.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#189

Earlier quoted context omitted.

Debian is a perfectly reasonable choice for casual linux users. Ubuntu's supposed usability improvements over Debian are greatly exaggerated. It's mostly just marketting.

Fair enough. I haven't used Debian in quite awhile (I think since 2009 or so?), so I can't speak to current stuff, but I do remember it being pretty hard to install then. I'm sure they have refined it considerably since then, and of course I am fifteen years more experienced now than I was. Personally it's hard for me to go back after I accepted the dogma of NixOS, but maybe if I manage to talk my parents into using…

> do remember it being pretty hard to install then.

It has always been easier than windows, which has never stopped the millions of people who used to format their drive and reinstall every few years after suffering from slowdowns.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#190

Earlier quoted context omitted.

Microsoft has for over two decades been one of the largest and most sophisticated employers of security talent in the industry, and for a run of about 8 years probably singlehandedly created the market for vulnerability research by contracting out to vulnerability research vendors. Leadership at Microsoft is different today than when the process of Microsoft's security maturation took place, but I'll note that throug…

It would help if there weren't all these employees and ex-employees stepping forward to talk about how Microsoft is performative and naive about security. I won't go as far as to say that, but I will say I don't think my incentives as an IC lined up with the security-focused mindset that company execs tout publicly.

I don't think anything is going to help here; it's just a message board fixity that companies like Microsoft are unserious about security.
Post reply on HN