Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

121–130 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#121

The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't…

As a Microsoftie of more than a decade... Yeah, I see this. We have an internal system called Cosmos[0] that does a great job of processing huge quantities of data very fast. And we sat on it for years while the rest of the industry moved to Spark and its derivatives. We finally released it as Azure Data Lake Analytics (ADLA) but did a shit job of supporting/promoting it. We built Synapse, and it's garbage. We've now…

Their support team likes to sit on things for a while too. I'm on day 4 of waiting for Azure to approve my support request to increase Azure Batch vCPUs from default of 4 to 20 for ESv3 series. I signed up last week and converted to a paid account. I'm going to use Google Cloud Batch today instead.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#122

The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't…

And the same applies to regions. Try running is most of the regions, each is a bit different. And its not historical / sequential differences, just random.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#123
Yeah, but this is how things work at that level.

Microsoft can be abhorrent. They will always get the contracts. Why? Corporate welfare.

Microsoft will drive the rules. Why? Too big to fail.

Microsoft will push their slop. Why? Cause they have contractors after contractors in the federal government pushing MS solutions. Doesnt matter if they're bad.

And, who'd pay for a 3PAO audit of a Linux distro? Ubuntu and Redhat have. Its a $120k moat.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#124
post #95

Earlier quoted context omitted.

Ugh this sounds like when I worked at Oracle/OCI. Some environments required a VPN, some a jumpbox, and some required logging into a virtual desktop, and then logging into a jumpbox. Just thinking about it gives me PTSD

any sufficiently large organization that is around for a decade or two trends towards spaghetti-access

And yet, somehow AWS managed to get this right-ish. They evolved, learned by making mistakes, and created de-facto standards (like object storage protocol) on the way, while at the same time supporting decades-old services. And I'm sure they'll withstand the current AI craze.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#125
post #98

Earlier quoted context omitted.

Absolute contempt for their users at every level. It’s so transparent. This is the end game of anticompetitive practices for decades— they just don’t have to try anymore… for now. Some day they’ll either have to compete in good faith or sink. I doubt that will happen soon, but someday.

It's hard to argue against contempt but... I'm gonna try. It feels like at the end of the line it's just a checkbox someone gets without having to consider the consequences of the changes. Either it's too big or there's too many levels where decisions get made and handed down to drones (or AI), but the people who decide seem to have no concept of what their products are used for and the people who implement features…

If not contempt, at least disregard or indifference

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#126

Earlier quoted context omitted.

I worked at a hospital in that timeframe and they rolled out Teams. Up until they, shadow IT teams were running Slack just fine. Man, what a horrendous pile of crap Teams was back then. The Slack teams were griping that they should just buy Slack, but Teams was the "enterprise solution." The problems were amplified during remote COVID work. Teams is fine now, but how many corporations went through years of frustratio…

Teams is still a horrendous pile of crap. It's just that you've gotten used to the stench. It has few redeeming qualities other than, "we don't have to pay for another subscription" and that's not even the case in the EU.

Yeah but today you can at least have a video call more or less normally. Back then it was a hiccup after a hiccup, it was impossible to work normally, and yet orgs pushed it down everybody's throats as it was bundled.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#127

It's not very clear from the article, but I get the feeling from the context that the 'pile of shit' quote referenced the package of documentation about the service rather than the service itself. (That seems to be the main complaint, that Microsoft never provided the clear information required to conduct the assessment properly).

> The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica. > > Or, as one member of the team put it: “The package is a pile of shit.” Yes, it seems pretty clear from that quote that the reviewer said the security package was a `pile of shit`, and pr…

MS was (and still is it seems) unable to produce the data flow diagrams that FedRAMP wanted, ones that other cloud providers had no problem with. If the documentation is in such dire state, then the system itself is likely to also be in a dire state. I.e. The documentation is a pile of shit, so the system is also a pile of shit.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#128

Earlier quoted context omitted.

Amazon is selling servers and storage. If you need to see logs properly, then get a right tool for it. Cloudwatch is a stop gap solution.

See my other comment. Logs are just one small symptom of a larger problem of poorly integrated very complex services where the complexity is pushed onto the users and not properly managed by Amazon. Which sounds very much like the problems with Azure.

My general approach is to only use the most basic services from each cloud. VMs, networks, L3 load balancers, blob storage, etc

Build the rest yourself. In many cases their higher level service is just the same open source package you would run, just managed worse.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#129

Earlier quoted context omitted.

any sufficiently large organization that is around for a decade or two trends towards spaghetti-access

And yet, somehow AWS managed to get this right-ish. They evolved, learned by making mistakes, and created de-facto standards (like object storage protocol) on the way, while at the same time supporting decades-old services. And I'm sure they'll withstand the current AI craze.

AWS had the benefit of not trying to retrofit IaaS on top of a (already bad) PaaS.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#130

Suddenly everyone on HN is an expert on Azure infrastructure. it isn't the best but it's really great at a lot of things feature-wise. top-notch documentation as well (despite what these "experts" said). Most companies literally run on Azure these days. Persistent hackers will get into any network, that's a guarantee, that's APT 101. It's law of averages. If it truly is "a pile of shit" given how it is probably the m…

I ran a one of the largest multi-cloud service across azure, aws and gcp.

Azure was hands down, obvious to everyone involved the worst technically. In capabilities, bugs/correctness, availability and support.

Post reply on HN