Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

121–130 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#121
post #92

Earlier quoted context omitted.

> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…

Yup. When a VC-backed company goes bankrupt, no one bats an eye. When Solyndra's loans go bad, even though it was a tiny fraction of the government's green energy portfolio, you get headlines and congressional hearings.

How many middle class workers were robbed through income tax to pay for the $524million dollars lost on solindra? Government money totally ruins any private business, to the tune of a huge party where everyone takes as much as possible with no accountability

Re: Microsoft is a national security threat: ex-White House cyber policy director

#122

It’s amazing how much leverage MSFT is extracting from Excel. It’s the tiny brick supporting their entire skyscraper.

No, Active Directory, Exchange, Word, and probably half a dozen other products also play an important role, and the integrations between them.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#123
post #74
post #33

Earlier quoted context omitted.

This strategy would fall apart when you encounter an adversary willing to sacrifice its own people. Nations that care about their own people need to keep a technological advantage on the battlefield.

I mean, all treaties are at risk of failure from bad actors, even implicit ones like mutually-assured-destruction, and in the later case it has been shown to be incredibly effective. But I don't feel like grinding the threat of powerful weapons against each other to be a particularly wise long term solution to security. I think it's a pretty obvious ipso facto that the more, and more advanced weapons, that are placed…

Adversaries willing to sacrifice their own people are absolutely a problem for societies that care about their own people.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#124
post #66

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

The US government isn't in need of a thousand high-skilled hackers. They are in need of a million normal employees with some basic security awareness. Anyone with a modicum of skill can find thousands of areas to improve. The issue is that almost nobody is in a position to get anything changed. Even basic software choices are a multi-year epic.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#125
post #66

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

Um, NASA?

The government is able to employ tons of smart people that could be making way more money elsewhere.

They might not get the absolute best security people in the world, but they could get good enough - as good as they're getting from MS for a fraction of the price.

Additionally, government salaries aren't terrible when you factor in the pension. Most people want the money now. But if you want financial security in the future - that's a reason a lot of people chose to work for the Fed.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#126
post #66

Earlier quoted context omitted.

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.

The US government spent $6.1 TRILLION dollars in 2023. I don't think raising taxes is the solution to the government offering a more competitive wage.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#127
post #92

Earlier quoted context omitted.

> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…

> This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. It certainly has something to do with it. The market rates for engineers was distorted because FAANG had a lot of money to throw around, so therefore hiring staff at government pay rates is quite difficult and is subject to the General Schedule ( ht…

Yes, the GS scale is a problem. My point was that it’s not a problem because we’re trying to save money – if that were the case, someone would notice that raising the cap to allow a $300k civil service job is cheaper than allowing the same job to be performed by a $500k contractor who takes home less and is replaced more frequently.

Politics enters the picture because the pay cap is derived from the salaries for politicians rather than what expertise is valued at on the open market:

https://www.opm.gov/policy-data-oversight/pay-leave/pay-admi...

Re: Microsoft is a national security threat: ex-White House cyber policy director

#128
The US govt can also do a lot better. The very agency they formed to counter cyber threats and alert against(CISA) itself got hacked because they failed to patch or remediate, and led to a serious leak of sensitive chemical industry information among others. Because they failed to follow their own security advisory. And they won't even put out a report detailing the hack like MS did.

> According to an early report on the breach, an anonymous source said that the compromised systems were the Infrastructure Protection (IP) Gateway, which houses critical information about the interdependency of U.S. infrastructure, and the Chemical Security Assessment Tool (CSAT), which houses private sector chemical security plans.

> CSAT is an online portal that contains highly sensitive information that determines which facilities are considered high-risk under the Chemical Facility Anti-Terrorism Standards (CFATS).

> CISA declined to confirm or deny which of their systems were taken offline.

https://securityintelligence.com/news/cisa-hackers-key-syste...

> In late February, CISA had already issued a warning that cyber threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. Ivanti Connect Secure is a widely deployed SSL VPN, while Ivanti Policy Secure (IPS) is a network access control (NAC) solution.

> Now, CISA itself has fallen victim to a cyberattack involving Ivanti products.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#130
post #96

Earlier quoted context omitted.

> Microsoft didn't even bother with key rotations anymore after 2021 because one time they fucked it up and it caused an outage, so they decided to just not do that anymore. Key rotation is almost like restoring from backups. It's an absolutely necessary capability and practice.

You'd be surprised at how little cloud vendors give a shit about security internally. Story time: I recently went ahead and implemented key rotation for one of our authz services, since it had none, and was reprimanded for "not implementing it like Google". Fun fact: Google's jwks.json endpoint claims to be "certs" from the path ( https://www.googleapis.com/oauth2/v3/certs ). They are not certs - there is no X.509 wr…

Are there any large companies that don't operate like feature factories? It seems to be such a common issue and the natural result of the incentive structure.
Post reply on HN