Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

231–240 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#231

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

I agree Microsoft is a problem. I just wish you tech guys took an equally critical stance towards Google, a genuine ad company.

And Apple, the upstart ("stealth mode") ad company.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#233
post #221

Earlier quoted context omitted.

> You have completely managed endpoints, strong hardening of the endpoint and complete inventorization of all the resources in the organization. You have certificates installed onto each device. You have an ACL engine that determines whether a user should get access to a particular resource. None of those are “solved” for any mid or large-sized enterprise where tech isn’t their code competency. In fact, I’d say most…

I think I agree with this conclusion. But I work in a Shaw-like enterprise (only the products are more mundane than flooring). What are the hurdles we’d see if we tried it? What processes and practices are we likely using, that would break under the zero trust model?

I think the hard part of trying it isn't using it, it's implementing it.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#234
post #221

Earlier quoted context omitted.

> You have completely managed endpoints, strong hardening of the endpoint and complete inventorization of all the resources in the organization. You have certificates installed onto each device. You have an ACL engine that determines whether a user should get access to a particular resource. None of those are “solved” for any mid or large-sized enterprise where tech isn’t their code competency. In fact, I’d say most…

I think I agree with this conclusion. But I work in a Shaw-like enterprise (only the products are more mundane than flooring). What are the hurdles we’d see if we tried it? What processes and practices are we likely using, that would break under the zero trust model?

For a start, you'll have a bunch of internal applications that are not hardened to be exposed on the public internet, and that you have neither the time nor the money to replace. A "zero trust" product vendor will therefore offer you something exactly like a VPN, but for some reason they'll say it's not a VPN.

You will have "heuristics to detect anomalies" and users won't be allowed to directly see what 'anomalies' are being detected, for security reasons. Instead, if someone plugs their phone into their laptop to charge it, they'll start getting network timeouts when they try to use the ERP system. After waiting 30 minutes for it to come back online, then calling the helpdesk, they'll be told that the charging phone counts as an unencrypted disk and they need to unplug it.

Other heuristics will create a huge backlog of 'maybe' alerts they'll invite you to manually review. Warning, a user who hasn't logged into the holiday booking system in 9 months just logged into the holiday booking system. Finding the real problems will be like looking for a needle in a haystack.

In-house infrastructure - which your team provides - will start appearing flaky, with mysterious outages. Public-internet SaaS products like Github will start looking better and better.

It will turn out the "zero trust" system doesn't work with your office's networked printers, access control system, CCTV cameras, meeting room conferencing system, server BMCs, networked UPSes, networked oscilloscopes, networked 3D printers, networked telephones, and so on.

It will also turn out, once a vendor is giving you "completely managed endpoints, strong hardening of the endpoint" you can't update without going through them first. And they aren't in any hurry to support the latest OS versions. Maybe they'll support Ubuntu 24.04 some time in 2025? Of course you'll pay them the same whether they hit that target or not.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#235

The solution is complete zero trust and distrusting the network in organizations. You should treat the internal network as external -- hostile. Google does this. They were the first ones to widely adopt zero trust with BeyondCorp and there has not been a Google internal organizational breach since Aurora (which made them adopt BeyondCorp, what they call zero trust). You have completely managed endpoints, strong harde…

[dead]

Re: Microsoft Chose Profit over Security, Whistleblower Says

#236

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

Did you buy the more expensive lock for your house? Are your doors fortified, if they are why isn't the steel an inch thicker?

Do you also choose having money over security? Sounds like the government also chose having a more productive work force, etc, over higher costs and lower productivity.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#237
post #154

Earlier quoted context omitted.

What if the company is providing only cybersecurity-related services? Could it be in this case, that everything is on profit side.

Sure, but to the client hiring them, it's a cost. We'll take the basic compliance package please, no need for any of the gold tier high security features.

"...because our executives won't get thrown into prison as long as they check all the compliance boxes. In fact, they won't get thrown into prison even if they don't check the compliance boxes, but that would be a minor nuisance, so we'll take basic compliance."

Re: Microsoft Chose Profit over Security, Whistleblower Says

#238
post #62
post #26

Earlier quoted context omitted.

Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.

Would that be securities fraud, because they're lying to investors? (Going by Matt Levine's "everything is securities fraud" logic here to see if that might actually change behavior…)

I think securities law usually only applies to things you tell investors? I could be wrong here though, I am not a lawyer.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#239
I don't see a future here that doesn't involve significant legislation over network security and include jail time for major offenses. Every time something like this happens, there's always that organizational Cassandra (usually the CISO) that saw it all coming but was ignored. Sooner or later someone will get burned badly enough that the consensus will be that tech cannot regulate itself on security. We've already got this a little bit for the most egregious cases, but it's still about as secure as banks in the 1920s.

A less actionable gripe I have is that we have so few players that even if the US government loses trust in Microsoft's cloud...where else will they go? There aren't a lot of players here that could handle that scale. It's like if there were only 3 banks in the world.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#240

The solution is complete zero trust and distrusting the network in organizations. You should treat the internal network as external -- hostile. Google does this. They were the first ones to widely adopt zero trust with BeyondCorp and there has not been a Google internal organizational breach since Aurora (which made them adopt BeyondCorp, what they call zero trust). You have completely managed endpoints, strong harde…

> Many of these security problems are solved.

I have found that thinking a security problem is "solved" is a big warning that you're at risk. There's no such thing as perfect security in anything. If you adopt the mindset that you're "safe" in some sort of absolute way, you stop looking very hard for security breaches and won't catch the one that will, sooner or later, happen.

Post reply on HN