Live data from Hacker News

A little-known Microsoft program could expose the Defense Department to hackers

propublica.org

51–59 of 59 posts

Re: A little-known Microsoft program could expose the Defense Department to hackers

#51

I am flabbergasted that the United States government does not have a requirement that anyone who touches their systems MUST be a vetted US citizen.

There’s no single overarching federal requirement when it comes to citizenship etc, but I would’ve assumed that ITAR requirements at the very least would’ve made this work US citizen on US soil only.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#52

I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds. I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing…

Yeah it seems like there are two issues here being conflated. The first is that non-US-persons are operating, by proxy, Azure assets that serve US Gov missions. The second is that those persons may be operating assets used in sensitive missions. Say IL4 and up.

The first is a little embarrassing for Microsoft, but a venal sin, not a mortal one. Makes them look like cheapskates offshoring work, instead of training local workers, but Ok, fine.

The second would be a mortal sin, assuming ( its not clear from the article whether) these non-US people are really operating at IL4 and up. Those assets really need US people especially at the higher impact levels. All of the above is public info described in FedRAMP standards.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#53

I am flabbergasted that the United States government does not have a requirement that anyone who touches their systems MUST be a vetted US citizen.

There’s no single overarching federal requirement when it comes to citizenship etc, but I would’ve assumed that ITAR requirements at the very least would’ve made this work US citizen on US soil only.

Permanent residents are US Persons for ITAR purposes

Re: A little-known Microsoft program could expose the Defense Department to hackers

#54

Earlier quoted context omitted.

There’s no single overarching federal requirement when it comes to citizenship etc, but I would’ve assumed that ITAR requirements at the very least would’ve made this work US citizen on US soil only.

Permanent residents are US Persons for ITAR purposes

Which is a rule that needs to be changed.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#55

This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…

Chinese engineers are operating US government cloud computers by proxy. The Chinese just don't see the computer screen--a proxy copies & pastes their commands and reads back the results.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#56

I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds. I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing…

I think you mis-read the article. Chinese engineers are operating US government cloud computers by proxy. The Chinese just don't see the computer screen. A US grunt copies & pastes the Chinese's commands into the system during a Teams call.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#57

Did I miss it, but what do these "digital escorts" actually do. The article doesn't seem to actually explain it. Edit: It's people who watch over what foriegn engineers are doing.

Chinese engineers call the US escorts on Teams and tell them what to copy & paste into US government cloud terminals. The Chinese don't see the screen or touch the keyboard attached to the government cloud so they "don't" break the letter of the law.

Re: A little-known Microsoft program could expose the Defense Department to hackers

#58
i don't really understand why folks are downplaying this in the comments:

some engineers who write the code for production US systems that contain controlled unclassified information live in china. the US government was unaware that this was happening because MSFT hid it from them. as a result, govt stakeholders are/were unable to assess the risk.

all MSFT ATO's should be revoked.

some of the comments point out that foreign workers will help maintain facilities overseas, but govt stakeholders are aware of this, assess the risk, and implement risk controls.

but shady M$FT hid this from govt, and that amplifies the problem!

disclaimer: am google

Post reply on HN