Live data from Hacker News

A little-known Microsoft program could expose the Defense Department to hackers

propublica.org

21–30 of 59 posts

Re: A little-known Microsoft program could expose the Defense Department to hackers

#21

This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…

This doesn't reflect what the article says. It only includes unclassified systems, not systems up to secret. That means anything from IL2 to IL5 (secret is impact level 6). In practice, IL2 is basically open access anyway, so it's really IL4 and IL5 as those levels actually restrict access. IL5 can include controlled unclassified information, but that's the highest possible. Remote access to IL5 systems also requires either a common access card issued by the DoD or personal PKI issued by an approved CA that still has to verify your background and identity in person before issuing you a certificate pair.

Along with everyone else they interviewed apparently, I had no idea this program even existed, but there have always been similar programs for other kinds of maintenance and support personnel. The people who repair the toilets and refrigerators in a SCIF don't have clearances. They get an escort, and everyone else in the building gets a warning before anyone needing an escort comes in, telling them to put away any sensitive data and either work on something unclassified or turn off your monitors and stop working completely until these people are done and leave again.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#22
post #2

> Pentagon bans foreign citizens from accessing highly sensitive data, but Microsoft bypasses this by using engineers in China ... The fun of using Cloud type systems. I expect AWS, Google and maybe IBM Cloud has the same issue. Save $ now, pay lots more later.

[deleted]

Re: A little-known Microsoft program could expose the Defense Department to hackers

#23
I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds.

I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing anything malicious. I assume the article is implying that these vendors for the US Gov cloud may be Chinese nationals.

As Jason mentions in another comment, anything actually requiring clearance is serviced by the airgapped clouds and only folks with clearance are able to operate there.

Edit: misread the article but the third paragraph stands. The government is totally aware of where the operator boundary lies and this is still wildly mischaracterized.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#25

I am flabbergasted that the United States government does not have a requirement that anyone who touches their systems MUST be a vetted US citizen.

I mean what does vetting even mean anymore? Our President is a convicted felon, our head of HHS thinks bad humors cause illness and vaccines cause Autism, our head of Education is dismantling her own organization with the approved sign off of the Supreme Court, of whom a solid percentage are accused sex offenders, and I could keep going with the utter circus our Government is currently.

Not only are qualifications not required they are apparently actively discouraged in favor of nepotism and connections.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#26
post #11

The "program" is a logistical one and not a software one in which Microsoft employs Chinese software engineers to be "overseen" by US citizens that have security clearances, but not necessarily the requisite experience for say a code review level of oversight.

>not a software

Appears the program has unfixed bugs and security holes anyway :\

Re: A little-known Microsoft program could expose the Defense Department to hackers

#27
post #13

Earlier quoted context omitted.

So much bringing manufacturing to America but I see little regarding developing software solely in America. Not sure if this is a debate the current administration has for the future or even if they are aware of it. Not trying to give my opinion or deciding whether one thing is better or worse. Just genuine curiosity.

Because "manufacturing in America" is to continue having a peasant class to buy goods. Outsourcing software development is 100% intended to surpress the peasants managing to go up higher on the ladder. Many companies doing "AI layoffs" are in fact just outsourcing to the usual countries overseas even more.

"AI layoffs" is mostly just media spin + a useful excuse by execs when the company isn't performing well. Looking through the list few mention anything about laying off engineers because of AI https://www.forbes.com/sites/martineparis/2025/07/09/sweepin...

> IBM CEO Says AI Has Replaced Hundreds of Workers but Created New Programming, Sales Jobs

(laying off mostly administrative/HR people)

https://www.wsj.com/articles/ibm-ceo-says-ai-has-replaced-hu...

> Intel plans to lay off up to a fifth of its factory workers, an enormous cutback that will have a profound effect on one of the chipmaker’s core businesses.

https://www.oregonlive.com/silicon-forest/2025/06/intel-will...

Microsoft laid off mostly gaming from failed acquisitions + sales/marketing (one of which I know personally)

Re: A little-known Microsoft program could expose the Defense Department to hackers

#28

I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds. I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing…

How does the vendor make sure you're not doing anything malicious if they don't have the skills to understand the change?

It sounds like the issue here isn't that the vendor doing the escort is a Chinese national, it's that the engineer making the change is a Chinese national in China and they're using this escort system to check a box saying that because the changes themselves are being made by US nationals, they won't send PII or passwords back to China. But fundamentally a system where an untrusted person gets a less technical person to make a change for them seems inherently extremely high-risk.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#30

I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds. I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing…

How does the vendor make sure you're not doing anything malicious if they don't have the skills to understand the change? It sounds like the issue here isn't that the vendor doing the escort is a Chinese national, it's that the engineer making the change is a Chinese national in China and they're using this escort system to check a box saying that because the changes themselves are being made by US nationals, they wo…

Yep, I totally read the article incorrectly. You’re spot on and honestly I’ve asked myself the same question - though less from a national security perspective and more a “what’s the point of this extra tax to mitigate this incident”
Post reply on HN