Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

81–90 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#81

Earlier quoted context omitted.

> Everything feels evolutionary. That's total "normal" for Microsoft at least from 2018, the year I started working with some of their products (Power BI mostly). They adopted a development model that is early release, fast iteration, and users as testers. No wonder everything feels experimental until much later. Back then I just couldn't use Power BI. But fast forward a few years, I think it got a lot better since m…

> You just have to stick with it for a few years. So, you have to be a paying tester? Incredible that MS can keep enough businesses as hostage to be able to operate like that.

a LOT of stuff comes for free or marginal (10-100$ a month) so yes, you do pay but it's already 'baked into' the contracts people generally carry with microsoft, or something for IT to worry about when the yearly renewals show up

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#82
Azure is bad. But to be fair, every security summary of IT services I’ve ever read — or written! — for over 25 years has also been a “pile of shit”. It seems to be inherent to the cybersecurity game that everything is judged based on meaningless check boxes and nonsensical explanations. Meanwhile the actual security posture is obscured and ignored.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#83

Earlier quoted context omitted.

> Everything feels evolutionary. That's total "normal" for Microsoft at least from 2018, the year I started working with some of their products (Power BI mostly). They adopted a development model that is early release, fast iteration, and users as testers. No wonder everything feels experimental until much later. Back then I just couldn't use Power BI. But fast forward a few years, I think it got a lot better since m…

> You just have to stick with it for a few years. So, you have to be a paying tester? Incredible that MS can keep enough businesses as hostage to be able to operate like that.

Most of the time it's just part of the bundle. If you are heavy into SQL Server, Office 365 and Power BI then there is a BIG chance you are going to use Azure for whatever the reason.

People who take Azure up without previous MS product experience...not sure about those.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#84
post #54
post #40

Earlier quoted context omitted.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?

It is also the only SSO flow I have ever seen that fundamentally cannot work if you have more than one account remembered on your device. So far the only way I’ve found to get it to let you log out of account A and then log into account B is to clear all cookies otherwise it gives you permission denied errors. Have no idea how it can be this horrible

Yeah I have had this experience too. Woe betide ye if your company gets bought by another company with pre-existing Azure AD.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#85

The sheer amount of conflict of interest with folk involved in this later getting employed by Microsoft is a bit crazy.

To be fair, it's not always out of maliciousness. A lot of gov workers/contractors join the supplier company because they know the product and how to fix it better than the people currently at the company. Similar to the guy who infamously got hired at Apple just to fix a bug.

You're just forced to use vendors and if you actually care about the mission, it's just a different team on the same mission.

Of course you know you're being taken advantage of, and long-term maybe you should have gone to the non-technical side to fight it, but at the end of the day you just want to keep the young boys being shipped off to war safe, and you're much better suited to achieve that by remaining on the technical side.

...or so I've heard.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#86

Azure is bad. But to be fair, every security summary of IT services I’ve ever read — or written! — for over 25 years has also been a “pile of shit”. It seems to be inherent to the cybersecurity game that everything is judged based on meaningless check boxes and nonsensical explanations. Meanwhile the actual security posture is obscured and ignored.

Staying afloat on cyber compliance takes so much time and energy there's no room for actual cybersecurity analysis.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#87

The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't…

As a Microsoftie of more than a decade... Yeah, I see this.

We have an internal system called Cosmos[0] that does a great job of processing huge quantities of data very fast. And we sat on it for years while the rest of the industry moved to Spark and its derivatives. We finally released it as Azure Data Lake Analytics (ADLA) but did a shit job of supporting/promoting it.

We built Synapse, and it's garbage. We've now got Fabric which I guess is the new Synapse. I wouldn't really know because I probably have five different systems that I use that basically do large-scale data processing, and yet Fabric isn't one of them; who knows, maybe it will become the sixth?

We've had numerous internal systems for orchestrating jobs, and it wasn't until Azure Data Factory that we finally released something externally that we sort-of-kind-of-but-not-really use internally. (To be fair, some teams do use it internally, but we're not all rowing in the same direction.)

I regularly deal with multiple environments with different levels of isolation for security. I don't even know how it's all supposed to work -- I have my regular laptop and a secure workstation and three accounts that work on the two. Yet I have to do some privileged account escalation to activate these roles; when I'm done, there's no apparent way to end the activation early, so I just let it time out.

These things are but a fraction of the Azure offerings, but literally everything I have used in Azure makes me absolutely HATE working in the cloud. There's not a single bright side to it AFAICT. As best as I can tell, the only reason why Azure makes so much damn money is because Microsoft is huge and can leverage its size into growth. We're very much failing up here.

[0] https://www.microsoft.com/en-us/research/publication/big-dat...

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#88

Given the scale and scope of the Federal Government. what are the alternatives to Microsoft? Building in house. Outsourcing to consultants.

I think there's some context missing here. For those who don't remember, the CIA back in like 2014 or so built out private data centers with classified versions of AWS services and all IC workloads that don't require specialized hardware was supposed to be using. DOD historically used it as well for classified cloud workloads, but wanted its own, and this was the JEDI contract, which was also supposed to go to Amazon, until Trump got into a fight with Jeff Bezos in 2019, canceled the contract, and awarded it to Microsoft instead. Amazon sued, and Biden decided to just award the contract to everyone and split it between all the major cloud vendors. That still doesn't mean anyone can actually use it without FedRAMP approval, but well, there you go.

The alternative was AWS, which has been operating at every classification level for over a decade at this point. It's now split between Amazon, Microsoft, Oracle, and Google, which is especially amusing because Google withdrew from the original bid process when they were still pretending to give a shit that their employees don't like working for the military.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#89
post #17

Earlier quoted context omitted.

It's why these enterprise vendors want foot in the door at all costs. They know that if they get entrenched first, it's impossible to migrate away. That's basically free money from a customer that has zero cost ceiling.

That's false that Government agencies have 0 cost ceiling. Maybe DoD does, but most offices have extremely tight budgets.

As far as I know numbers aren't reported, but there's probably at least as many DIB GCC-H customers as government, who in part use it because the government does and it's compliant. Once they're locked in it's very hard to migrate.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#90
post #40

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?

I haven't seen it in a while (perhaps mostly because I'm in Google stuff way less than I used to be) but for years multiple Google sites would get in a state where its auth would route me through about twenty redirects in a loop and never actually finish authenticating me. Clearing cookies and re-logging-in from scratch was the only fix.

Youtube was always involved, somehow, for some reason, even when what I was doing wasn't connected to Youtube at all or the account I was using had never even been intentionally used with Youtube. It'd route me through a few Youtube domain names.

(Microsoft's is indeed even worse, on some of theirs [Azure Devops, looking at you] I can't use them in pinned tabs because somehow they manage to get into a totally broken state where the page won't load due to whatever's happening with their auth flow in the background, and no method of reloading the tab fixes it, and it does this every couple days—but copy-pasting the same URL to a new tab does work)

Post reply on HN