Earlier quoted context omitted.
I mean what does vetting even mean anymore? Our President is a convicted felon, our head of HHS thinks bad humors cause illness and vaccines cause Autism, our head of Education is dismantling her own organization with the approved sign off of the Supreme Court, of whom a solid percentage are accused sex offenders, and I could keep going with the utter circus our Government is currently. Not only are qualifications no…
The guy who heads up the Defense department was (drunkenly?) texting out secret plans to a journalist.
A little-known Microsoft program could expose the Defense Department to hackers
41–50 of 59 posts
Re: A little-known Microsoft program could expose the Defense Department to hackers
#42This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…
They can do everything that the escort's account can, I don't think you can know what that is.
Since it's to solve technical issues, there's a high chance that low-level access will be required, often.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#43Earlier quoted context omitted.
That's not really what the article supposes unless I missed something, or do you have a different source? Hilarious if true. Edit: yes it does, I just didn't read it all the way.
Maybe it isn't displaying on mobile or something, but there's a grey box in the article that shows step-by-step what happens. > A Microsoft engineer in China files an online “ticket” to take on the work. > A U.S.-based escort picks up the ticket. > The engineer and the escort meet on the Microsoft Teams conferencing platform. > The engineer sends computer commands to the U.S. escort, presenting an opportunity to inse…
Re: A little-known Microsoft program could expose the Defense Department to hackers
#44Earlier quoted context omitted.
It's more involved than that - the US national is the person who has control of the keyboard, the non US national views the screen share and instructs them what to do.
> “If someone ran a script called ‘fix_servers.sh’ but it actually did something malicious then [escorts] would have no idea,” Matthew Erickson, a former Microsoft engineer who worked on the escort system It sounds like you may have additional context or perspective, which makes me curious about the scope of "instructs." For example, I can imagine that the deployment sources of the public and Government clouds infras…
As far at I'm aware, there isn't a separate code base.
In general, you can't share scripts / executables via this mechanism - that's done via code review and deployment.
You could get an operator to run a script in a malicious way, but it'd need pre-written to include the malicious behaviour.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#45This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…
Re: A little-known Microsoft program could expose the Defense Department to hackers
#46I am flabbergasted that the United States government does not have a requirement that anyone who touches their systems MUST be a vetted US citizen.
I mean what does vetting even mean anymore? Our President is a convicted felon, our head of HHS thinks bad humors cause illness and vaccines cause Autism, our head of Education is dismantling her own organization with the approved sign off of the Supreme Court, of whom a solid percentage are accused sex offenders, and I could keep going with the utter circus our Government is currently. Not only are qualifications no…
Dude would run his mouth about stuff he shouldn't tell people under normal circumstances. There's no way he didn't tell the sex worker secret stuff.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#47I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds. I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing…
Regardless of the program’s actual risk, it doesn’t seem that the government is fully aware of the program’s very existence. The article quotes the former CIO of the Pentagon as being surprised:
> John Sherman, who was chief information officer for the Department of Defense during the Biden administration, said he was surprised and concerned to learn of ProPublica’s findings. “I probably should have known about this,” he said. He told the news organization that the situation warrants a “thorough review by DISA, Cyber Command and other stakeholders that are involved in this.”
Re: A little-known Microsoft program could expose the Defense Department to hackers
#48Earlier quoted context omitted.
How does the vendor make sure you're not doing anything malicious if they don't have the skills to understand the change? It sounds like the issue here isn't that the vendor doing the escort is a Chinese national, it's that the engineer making the change is a Chinese national in China and they're using this escort system to check a box saying that because the changes themselves are being made by US nationals, they wo…
Yep, I totally read the article incorrectly. You’re spot on and honestly I’ve asked myself the same question - though less from a national security perspective and more a “what’s the point of this extra tax to mitigate this incident”
My guess is ATO requires that only US Citizens make changes to the system. However, Microsoft did not want to hire skilled US citizens for pay reasons so they hire unskilled US citizens and get trained Chinese nationals to direct US citizens to make changes they require.
So stockholders get another yacht because GovCloud is expensive but overhead is peanuts and national security be damned.
US Government should announce that their ATO has been revoked but we don't do that.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#49Earlier quoted context omitted.
It's more involved than that - the US national is the person who has control of the keyboard, the non US national views the screen share and instructs them what to do.
Makes sense, but it really does seems like a silly way to work around the security policies.
Basically, stockholders get another yacht, national security gets screwed.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#50This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…
These aren’t SECRET systems. If they were, that would be catastrophically bad and someone would go to jail.