Live data from Hacker News

A little-known Microsoft program could expose the Defense Department to hackers

propublica.org

11–20 of 59 posts

Re: A little-known Microsoft program could expose the Defense Department to hackers

#11
The "program" is a logistical one and not a software one in which Microsoft employs Chinese software engineers to be "overseen" by US citizens that have security clearances, but not necessarily the requisite experience for say a code review level of oversight.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#13
post #2

> Pentagon bans foreign citizens from accessing highly sensitive data, but Microsoft bypasses this by using engineers in China ... The fun of using Cloud type systems. I expect AWS, Google and maybe IBM Cloud has the same issue. Save $ now, pay lots more later.

So much bringing manufacturing to America but I see little regarding developing software solely in America.

Not sure if this is a debate the current administration has for the future or even if they are aware of it.

Not trying to give my opinion or deciding whether one thing is better or worse. Just genuine curiosity.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#14
This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc.

The top secret stuff isn’t using this system; it’s using cleared staff.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#17
post #7

Did I miss it, but what do these "digital escorts" actually do. The article doesn't seem to actually explain it. Edit: It's people who watch over what foriegn engineers are doing.

I'm guessing a pair of eyes over your shoulder (or virtually watching a session) as you do work near or with sensitive data or systems.

It's more involved than that - the US national is the person who has control of the keyboard, the non US national views the screen share and instructs them what to do.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#18
post #13
post #2

> Pentagon bans foreign citizens from accessing highly sensitive data, but Microsoft bypasses this by using engineers in China ... The fun of using Cloud type systems. I expect AWS, Google and maybe IBM Cloud has the same issue. Save $ now, pay lots more later.

So much bringing manufacturing to America but I see little regarding developing software solely in America. Not sure if this is a debate the current administration has for the future or even if they are aware of it. Not trying to give my opinion or deciding whether one thing is better or worse. Just genuine curiosity.

Because "manufacturing in America" is to continue having a peasant class to buy goods.

Outsourcing software development is 100% intended to surpress the peasants managing to go up higher on the ladder. Many companies doing "AI layoffs" are in fact just outsourcing to the usual countries overseas even more.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#19

This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…

Secret is still sensitive info and, if released, can cause harm or disruption.

Spying is not based on finding a single discovery of top secret information but a continuous process of pulling various pieces together. A "secret" item by itself may not cause bad things to happen but combined with other information could result in far greater damage.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#20

This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…

[deleted]
Post reply on HN