Live data from Hacker News

A little-known Microsoft program could expose the Defense Department to hackers

propublica.org

31–40 of 59 posts

Re: A little-known Microsoft program could expose the Defense Department to hackers

#31

This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…

This doesn't reflect what the article says. It only includes unclassified systems, not systems up to secret. That means anything from IL2 to IL5 (secret is impact level 6). In practice, IL2 is basically open access anyway, so it's really IL4 and IL5 as those levels actually restrict access. IL5 can include controlled unclassified information, but that's the highest possible. Remote access to IL5 systems also requires…

Thanks for the clarification; I was going off "While the ad said that specific technical skills were “highly preferred” and “nice to have,” the main prerequisite was possessing a valid “secret” level clearance issued by the Defense Department" from the article.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#32

I am flabbergasted that the United States government does not have a requirement that anyone who touches their systems MUST be a vetted US citizen.

I mean what does vetting even mean anymore? Our President is a convicted felon, our head of HHS thinks bad humors cause illness and vaccines cause Autism, our head of Education is dismantling her own organization with the approved sign off of the Supreme Court, of whom a solid percentage are accused sex offenders, and I could keep going with the utter circus our Government is currently. Not only are qualifications no…

The guy who heads up the Defense department was (drunkenly?) texting out secret plans to a journalist.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#33
post #7

Earlier quoted context omitted.

I'm guessing a pair of eyes over your shoulder (or virtually watching a session) as you do work near or with sensitive data or systems.

It's more involved than that - the US national is the person who has control of the keyboard, the non US national views the screen share and instructs them what to do.

That's not really what the article supposes unless I missed something, or do you have a different source? Hilarious if true.

Edit: yes it does, I just didn't read it all the way.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#34
post #7

Earlier quoted context omitted.

I'm guessing a pair of eyes over your shoulder (or virtually watching a session) as you do work near or with sensitive data or systems.

It's more involved than that - the US national is the person who has control of the keyboard, the non US national views the screen share and instructs them what to do.

> “If someone ran a script called ‘fix_servers.sh’ but it actually did something malicious then [escorts] would have no idea,” Matthew Erickson, a former Microsoft engineer who worked on the escort system

It sounds like you may have additional context or perspective, which makes me curious about the scope of "instructs." For example, I can imagine that the deployment sources of the public and Government clouds infrastructure are different, such that a bug fix on the shared base may need to be merged between these two branches. If a foreign national made the fix for the public version and then provided the expertise of resolving merge conflicts when applying it to the Government version, it presents an opportunity for subtle abuse unless the change is either further audited by the keyboard operator or another engineer before the merge result lands or is deployed.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#35

Earlier quoted context omitted.

It's more involved than that - the US national is the person who has control of the keyboard, the non US national views the screen share and instructs them what to do.

That's not really what the article supposes unless I missed something, or do you have a different source? Hilarious if true. Edit: yes it does, I just didn't read it all the way.

Maybe it isn't displaying on mobile or something, but there's a grey box in the article that shows step-by-step what happens.

> A Microsoft engineer in China files an online “ticket” to take on the work.

> A U.S.-based escort picks up the ticket.

> The engineer and the escort meet on the Microsoft Teams conferencing platform.

> The engineer sends computer commands to the U.S. escort, presenting an opportunity to insert malicious code.

> The escort, who may not have advanced technical expertise, inputs the commands into the federal cloud system.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#36
post #7

Earlier quoted context omitted.

I'm guessing a pair of eyes over your shoulder (or virtually watching a session) as you do work near or with sensitive data or systems.

It's more involved than that - the US national is the person who has control of the keyboard, the non US national views the screen share and instructs them what to do.

Makes sense, but it really does seems like a silly way to work around the security policies.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#38

Earlier quoted context omitted.

This doesn't reflect what the article says. It only includes unclassified systems, not systems up to secret. That means anything from IL2 to IL5 (secret is impact level 6). In practice, IL2 is basically open access anyway, so it's really IL4 and IL5 as those levels actually restrict access. IL5 can include controlled unclassified information, but that's the highest possible. Remote access to IL5 systems also requires…

Thanks for the clarification; I was going off "While the ad said that specific technical skills were “highly preferred” and “nice to have,” the main prerequisite was possessing a valid “secret” level clearance issued by the Defense Department" from the article.

Secret because that's generally the lowest level clearance you can get that means something to the DoD. Essentially anyone working in and around the DoD has a secret clearance. Notably a clearance in itself means nothing without need to know.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#39

Earlier quoted context omitted.

How does the vendor make sure you're not doing anything malicious if they don't have the skills to understand the change? It sounds like the issue here isn't that the vendor doing the escort is a Chinese national, it's that the engineer making the change is a Chinese national in China and they're using this escort system to check a box saying that because the changes themselves are being made by US nationals, they wo…

Yep, I totally read the article incorrectly. You’re spot on and honestly I’ve asked myself the same question - though less from a national security perspective and more a “what’s the point of this extra tax to mitigate this incident”

It seems pretty reasonable to consider the national security perspective when it seems like the potential risk is organized, nation state actors, and the potential mitigation is only the actual depth of security practices at play.

To put it another way, if the air gap is the only thing preventing the malicious system from doing its malicious thing, it seems like "defense in depth" is working but there's still a problem to solve. That is, making the malicious system not malicious.

> anything actually requiring clearance is serviced by the airgapped clouds and only folks with clearance are able to operate there

It seems like "operate" may be doing a lot of work here.

Post reply on HN