Earlier quoted context omitted.
> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…
Yup. When a VC-backed company goes bankrupt, no one bats an eye. When Solyndra's loans go bad, even though it was a tiny fraction of the government's green energy portfolio, you get headlines and congressional hearings.
Microsoft is a national security threat: ex-White House cyber policy director
121–130 of 224 posts
Re: Microsoft is a national security threat: ex-White House cyber policy director
#122It’s amazing how much leverage MSFT is extracting from Excel. It’s the tiny brick supporting their entire skyscraper.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#123Earlier quoted context omitted.
This strategy would fall apart when you encounter an adversary willing to sacrifice its own people. Nations that care about their own people need to keep a technological advantage on the battlefield.
I mean, all treaties are at risk of failure from bad actors, even implicit ones like mutually-assured-destruction, and in the later case it has been shown to be incredibly effective. But I don't feel like grinding the threat of powerful weapons against each other to be a particularly wise long term solution to security. I think it's a pretty obvious ipso facto that the more, and more advanced weapons, that are placed…
Re: Microsoft is a national security threat: ex-White House cyber policy director
#124I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…
Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#125I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…
Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.
The government is able to employ tons of smart people that could be making way more money elsewhere.
They might not get the absolute best security people in the world, but they could get good enough - as good as they're getting from MS for a fraction of the price.
Additionally, government salaries aren't terrible when you factor in the pension. Most people want the money now. But if you want financial security in the future - that's a reason a lot of people chose to work for the Fed.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#126Earlier quoted context omitted.
Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.
Partly this is due to the concentration of wealth, inaccessible to taxing. Naturally government pay would lag behind even the more mediocre H1Bs.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#127Earlier quoted context omitted.
> Partly this is due to the concentration of wealth, inaccessible to taxing. This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. The problem is that there’s an entire political ideology holding that government is inherently wasteful and its adherents will oppose any attempt to track market salaries bec…
> This has nothing to do with it. Contractors cost notably more, so if the goal was economizing it’d be an obvious step to cut out the middlemen by hiring staff directly. It certainly has something to do with it. The market rates for engineers was distorted because FAANG had a lot of money to throw around, so therefore hiring staff at government pay rates is quite difficult and is subject to the General Schedule ( ht…
Politics enters the picture because the pay cap is derived from the salaries for politicians rather than what expertise is valued at on the open market:
https://www.opm.gov/policy-data-oversight/pay-leave/pay-admi...
Re: Microsoft is a national security threat: ex-White House cyber policy director
#128> According to an early report on the breach, an anonymous source said that the compromised systems were the Infrastructure Protection (IP) Gateway, which houses critical information about the interdependency of U.S. infrastructure, and the Chemical Security Assessment Tool (CSAT), which houses private sector chemical security plans.
> CSAT is an online portal that contains highly sensitive information that determines which facilities are considered high-risk under the Chemical Facility Anti-Terrorism Standards (CFATS).
> CISA declined to confirm or deny which of their systems were taken offline.
https://securityintelligence.com/news/cisa-hackers-key-syste...
> In late February, CISA had already issued a warning that cyber threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. Ivanti Connect Secure is a widely deployed SSL VPN, while Ivanti Policy Secure (IPS) is a network access control (NAC) solution.
> Now, CISA itself has fallen victim to a cyberattack involving Ivanti products.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#129Re: Microsoft is a national security threat: ex-White House cyber policy director
#130Earlier quoted context omitted.
> Microsoft didn't even bother with key rotations anymore after 2021 because one time they fucked it up and it caused an outage, so they decided to just not do that anymore. Key rotation is almost like restoring from backups. It's an absolutely necessary capability and practice.
You'd be surprised at how little cloud vendors give a shit about security internally. Story time: I recently went ahead and implemented key rotation for one of our authz services, since it had none, and was reprimanded for "not implementing it like Google". Fun fact: Google's jwks.json endpoint claims to be "certs" from the path ( https://www.googleapis.com/oauth2/v3/certs ). They are not certs - there is no X.509 wr…