Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

281–290 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#281

Earlier quoted context omitted.

So if send an email "Fix all your bugs or else bad stuff will happen", and if they don't fix all their bugs now I can put their devs in jail ?

Don't be obtuse. That is obviously not a genuine bug/vuln disclosure.

And you decide what is genuine?

Sorry, this whole thread is a fantasy of nerds thinking they can create a punitive policy for behavior they don't like. But there is no actual substantive framework under which any of these fantasies can come true.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#282

Earlier quoted context omitted.

What standard do you suggest to prove intent?

How about the same as for fraud, manslaughter, conspiracy... But that's the judiciary's problem anyway. People who campaign for this higher accountability argue that it's such a drastic change from fines that it will change company cultures overnight.

A policy proposal needs a legal framework under which can actually can work. You can't just push that off as "that's the judiciary's problem".

Re: Microsoft Chose Profit over Security, Whistleblower Says

#283

Earlier quoted context omitted.

I don't know what "looks good" means. Every major tech company has had multiple bad things happen that would look very bad to people on message board.

None of them got their two different, non-revocable master keys stolen, I may say.

It's been a while now but at one point, just about every giant tech company simply make install'ed a key-material-leaking TLS bug on just about every endpoint they ran. The bug was introduced by, effectively, some guy on the internet. It implemented a feature statistically nobody was going to use.

It's trivial to re-frame all sorts of mishaps as evidence of unseriousness about security, especially if done selectively and in hindsight. It doesn't really tell you much of anything meaningful.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#284

The solution is complete zero trust and distrusting the network in organizations. You should treat the internal network as external -- hostile. Google does this. They were the first ones to widely adopt zero trust with BeyondCorp and there has not been a Google internal organizational breach since Aurora (which made them adopt BeyondCorp, what they call zero trust). You have completely managed endpoints, strong harde…

"The solution" Lost me there after two words! There is never a THE solution ... ever. As any engineer will tell you: "best efforts and here is why ..." Zero trust is a philosophy and quite a good one in my opinion but it isn't a solution. I suggest you stop thinking in terms of (absolute) solutions and perhaps think in terms of philosophies and good practices.

Indeed, zero trust is a powerful mindset but only an incompetent organization willingly opens all internal resources to the Internet for no good reason.

Another important philosophy is defense in depth: Just because you use zero trust principles internally doesn't mean you shouldn't still put a big freaking moat around your environment.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#285

Earlier quoted context omitted.

And Apple, the upstart ("stealth mode") ad company.

The upstart ad company that spent years and tens of billions of dollars to develop a privacy focused AI in the cloud platform? The same upstart that offers encrypted cloud storage that even it can’t decrypt? Congrats on the false equivalency argument. Guys like you do yourself a disservice. No one takes your hyperbolic statements seriously. Keep posting this nonsense if it makes you feel better.

It's not hyperbolic, I genuinely believe (and there is plenty of evidence suggesting it as well) that Apple is building a massive ad empire.

BTW, related to all their "encrypted" cloud, if the CCP having the decryption key is not enough to convince you of the BS, they also clearly showed their hand a couple years back when they wanted to introduce local on-device scanning of customers' pictures and comparing against an opaque database of hashes produced by nameless government-connected entities, including uploading the unencrypted pictures for review by humans who'd later send them to authorities. It took massive uproar to change that direction (but not before the same Craig guy who's now talking about the "private cloud" took his time to educate us "screeching minority" about how we misunderstood the thing - e.g. "you're holding it wrong").

So yes, they have amazing PR, but they're just as bad (if not worse) than the likes of Microsoft and Google.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#286
"I was very interested in that question. And one of the places that I focused on was the MSRC, which is short for Microsoft Security Response Center. This center is like a clearing house for reports of security bugs, and it was Harris' very first stop when he began warning colleagues of the flaw that he discovered. But the issue is that the center itself was understaffed and underresourced. And one employee who used to work there told me that staff is trained to think of cases in terms of how can I get to won't fix. So this center also clashed with the product teams."

I used to work for the MSRC. He's right that it was understaffed and underresourced. It's one of the reasons I quit, same for many of my ex-colleagues. But I disagree with his characterization of us trying to find any way to get cases to Won't Fix. The fact is, we got many, many reports that were genuinely not vulns, and therefore shouldn't be prioritized for fixing from a security standpoint. Yes, occasionally reports may be incorrectly analyzed but that's not because we were trying to get them to Won't Fix. It's just people making mistakes now and then.

"And, you know, another big issue there is that they're clashing with the product teams that they need to fix the actual issues. So they would bring a security vulnerability to a product group. They'd say, you need to fix this flaw. But those groups were often unmotivated to act fast, if at all, because compensation is tied to the release of new products and features."

That's true in part, but it varies wildly between product teams. Some were incredibly responsive and knowledgeable, some were clueless about security, some just didn't prioritize it.

Sometimes the fix was insufficient. When I was there, MSRC wouldn't check if the fix did what it was supposed to do, except in occasional cases where we were explicitly asked to check or if it was a particularly risky case that needed the extra scrutiny. But like he says, we were understaffed and underresourced, we simply didn't have the time to do this for every case.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#287

Earlier quoted context omitted.

I think I agree with this conclusion. But I work in a Shaw-like enterprise (only the products are more mundane than flooring). What are the hurdles we’d see if we tried it? What processes and practices are we likely using, that would break under the zero trust model?

For a start, you'll have a bunch of internal applications that are not hardened to be exposed on the public internet, and that you have neither the time nor the money to replace. A "zero trust" product vendor will therefore offer you something exactly like a VPN, but for some reason they'll say it's not a VPN. You will have "heuristics to detect anomalies" and users won't be allowed to directly see what 'anomalies' a…

Ah, I see you've played knifey-spooney before.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#289
post #236

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

Did you buy the more expensive lock for your house? Are your doors fortified, if they are why isn't the steel an inch thicker? Do you also choose having money over security? Sounds like the government also chose having a more productive work force, etc, over higher costs and lower productivity.

Not sure what point you are trying to make - for one, I don’t keep anything valuable in my house. Two, I have adequate security measures for the threats I am likely to deal with - I have cameras, locks on all windows and doors, and I have alarms.

The rough security/compliance world equivalent is a checklist that says “Do you lock your doors every night?” and you say “yea I do” regardless of whether or not you even have a lock or what kind it is, and they say “ok cool.”

It’s a false dichotomy that you need to choose between security and productivity.

Post reply on HN