> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…
I agree Microsoft is a problem. I just wish you tech guys took an equally critical stance towards Google, a genuine ad company.
Microsoft Chose Profit over Security, Whistleblower Says
231–240 of 318 posts
Re: Microsoft Chose Profit over Security, Whistleblower Says
#232Re: Microsoft Chose Profit over Security, Whistleblower Says
#233Earlier quoted context omitted.
> You have completely managed endpoints, strong hardening of the endpoint and complete inventorization of all the resources in the organization. You have certificates installed onto each device. You have an ACL engine that determines whether a user should get access to a particular resource. None of those are “solved” for any mid or large-sized enterprise where tech isn’t their code competency. In fact, I’d say most…
I think I agree with this conclusion. But I work in a Shaw-like enterprise (only the products are more mundane than flooring). What are the hurdles we’d see if we tried it? What processes and practices are we likely using, that would break under the zero trust model?
Re: Microsoft Chose Profit over Security, Whistleblower Says
#234Earlier quoted context omitted.
> You have completely managed endpoints, strong hardening of the endpoint and complete inventorization of all the resources in the organization. You have certificates installed onto each device. You have an ACL engine that determines whether a user should get access to a particular resource. None of those are “solved” for any mid or large-sized enterprise where tech isn’t their code competency. In fact, I’d say most…
I think I agree with this conclusion. But I work in a Shaw-like enterprise (only the products are more mundane than flooring). What are the hurdles we’d see if we tried it? What processes and practices are we likely using, that would break under the zero trust model?
You will have "heuristics to detect anomalies" and users won't be allowed to directly see what 'anomalies' are being detected, for security reasons. Instead, if someone plugs their phone into their laptop to charge it, they'll start getting network timeouts when they try to use the ERP system. After waiting 30 minutes for it to come back online, then calling the helpdesk, they'll be told that the charging phone counts as an unencrypted disk and they need to unplug it.
Other heuristics will create a huge backlog of 'maybe' alerts they'll invite you to manually review. Warning, a user who hasn't logged into the holiday booking system in 9 months just logged into the holiday booking system. Finding the real problems will be like looking for a needle in a haystack.
In-house infrastructure - which your team provides - will start appearing flaky, with mysterious outages. Public-internet SaaS products like Github will start looking better and better.
It will turn out the "zero trust" system doesn't work with your office's networked printers, access control system, CCTV cameras, meeting room conferencing system, server BMCs, networked UPSes, networked oscilloscopes, networked 3D printers, networked telephones, and so on.
It will also turn out, once a vendor is giving you "completely managed endpoints, strong hardening of the endpoint" you can't update without going through them first. And they aren't in any hurry to support the latest OS versions. Maybe they'll support Ubuntu 24.04 some time in 2025? Of course you'll pay them the same whether they hit that target or not.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#235The solution is complete zero trust and distrusting the network in organizations. You should treat the internal network as external -- hostile. Google does this. They were the first ones to widely adopt zero trust with BeyondCorp and there has not been a Google internal organizational breach since Aurora (which made them adopt BeyondCorp, what they call zero trust). You have completely managed endpoints, strong harde…
Re: Microsoft Chose Profit over Security, Whistleblower Says
#236The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…
Do you also choose having money over security? Sounds like the government also chose having a more productive work force, etc, over higher costs and lower productivity.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#237Earlier quoted context omitted.
What if the company is providing only cybersecurity-related services? Could it be in this case, that everything is on profit side.
Sure, but to the client hiring them, it's a cost. We'll take the basic compliance package please, no need for any of the gold tier high security features.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#238Earlier quoted context omitted.
Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.
Would that be securities fraud, because they're lying to investors? (Going by Matt Levine's "everything is securities fraud" logic here to see if that might actually change behavior…)
Re: Microsoft Chose Profit over Security, Whistleblower Says
#239A less actionable gripe I have is that we have so few players that even if the US government loses trust in Microsoft's cloud...where else will they go? There aren't a lot of players here that could handle that scale. It's like if there were only 3 banks in the world.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#240The solution is complete zero trust and distrusting the network in organizations. You should treat the internal network as external -- hostile. Google does this. They were the first ones to widely adopt zero trust with BeyondCorp and there has not been a Google internal organizational breach since Aurora (which made them adopt BeyondCorp, what they call zero trust). You have completely managed endpoints, strong harde…
I have found that thinking a security problem is "solved" is a big warning that you're at risk. There's no such thing as perfect security in anything. If you adopt the mindset that you're "safe" in some sort of absolute way, you stop looking very hard for security breaches and won't catch the one that will, sooner or later, happen.