Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

151–160 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#151

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

In the profit-center view, everything is either a cost center or a profit center. And it is nearly impossible to get anyone to truly care about a "cost center".

Re: Microsoft Chose Profit over Security, Whistleblower Says

#152

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

> you know, what if a user missed an ad and wants to go back and see what they missed

I have meetings with adtech guys and this gets pitched every time. Along with "a way to save ads so you can watch them again at home later!" And "alexa enable ads that you can talk to!"

Re: Microsoft Chose Profit over Security, Whistleblower Says

#154

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

In the profit-center view, everything is either a cost center or a profit center. And it is nearly impossible to get anyone to truly care about a "cost center".

What if the company is providing only cybersecurity-related services? Could it be in this case, that everything is on profit side.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#155

So...Golden SAML isn't a vulnerability, as the CyberArk article quoted in the post reiterates, it's a type of attack that requires completely comprising the box before using. Unless I am misunderstanding something, I don't see any particular flaw, per se. As Microsoft (mocked in the article) would say, it's not crossing a security boundary. SSO will ALWAYS have this particular tradeoff. If your SSO infrastructure is…

Sounds like the vulnerability was one within AD FS and that exposed the private key, making golden SAML possible.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#156

Earlier quoted context omitted.

> legal team wants everyone to behave ethically at all times do you really believe that? compliance under scrutiny, more like it

The best job is sitting around and doing nothing. So ideally yes. But sure, ethically speaking when things get heated they will exploit every loophole they can find to avoid liability. So, lawful evil?

Most corporate law guidance is about risk mitigation, not about ethics. Less activity generally translates to less risk.

You can see a similar phenomenon with security professionals. True, the only secure computer is one disconnected from the Internet, turned off, put in a Faraday cage, on the moon, under armed guard - but that's not useful.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#157

Earlier quoted context omitted.

I mean, if you have no evidence of this, why even post such an (incorrect) conspiracy theory comment?

Well the Amazon ads in Ubuntu absolutely did happen, as well as the searches with the super key. [1] I'll admit it's maybe a bit of an extrapolation to assume that they're as bad as Microsoft, which is why I disclosed that I didn't have a ton of evidence for this. [1] https://www.gnu.org/philosophy/ubuntu-spyware.en.html I realize that GNU is sort of conspiratorial in its own right, but at least one entity seemed to…

Well, here are the facts (I was an insider at the time, and this is my testimony).

Searches were anonymized and sent through Canonical servers to provide extended search result sets. This was configurable and could be disabled. Canonical of course had your IP address so they could reply, just like any and every HTTP server does. Your search query was not stored anywhere or aggregated, and it was not associated back to the originating IP address except to reply. Your privacy was respected and protected at all times.

The Amazon search did appear as a plugin in an early prelease. It was never shipped in a released Ubuntu.

The goal was to make things as easy as possible, even for the technically averse (who were still commonplace a decade ago), while still respecting and protecting your privacy.

Of course, no matter what you do, someone is going to scream for everyone to come witness the oppression inherent in the system. We did it anyway with the expectation of baseless knee-jerk outcry and we were not disappointed.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#158

> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…

The Microsoft bribes scandal broke not too long after I had to take the "hey don't do bribes" training at Microsoft. That event really drove home for me the fact that all of the trainings, emails, processes, etc. are mostly plausible deniability. There are people who care about security at MS. I know, I've met them, but for the most part all of this exists so that Satya can plausibly say in court or in front of congr…

To be fair, it's not really possible to come up with good policy to handle this at scale. It would be too intrusive to require employees to divulge their private financial accounts (and near impossible to audit that the employee has truly divulged all their financial accounts), and the more internal controls you put in place, the slower the deal-making gets, with no guarantee of good behavior.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#159
post #83

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

This is exactly it. There is no incentive to prioritise security. It is not visible to customers, except in terms of compliance, most likely a check-list approach. I think it needs a massive cultural shift, but from customers. If customers were willing to evaluate security (consumers cannot, but enterprise can) properly, demand binding assurances, and make buying choices accordingly industry would respond. Of course…

The purpose of using Microsoft products in an office environment is so that your office can be run with as much personal computer enhancement as you originally realized when you first effectively replaced the traditional office machines or more-labor-intensive tasks with software-powered substitutes.

Which all occurred way before any of the things like "single-sign-on" got popular among those who didn't seem to know any better. The second this appeared it was easily recognized as one of the many consumer/entertainment features that must be disabled across every bit of any serious corporate network.

Also best disabled on any home computer before it is allowed to touch the internet.

There was no forthcoming mitigation, all Microsoft leadership could do was throw up their hands, after all there were unsurmountable reasons why such a threat could not be overcome.

>it required customers to turn off one of Microsoft’s most convenient and popular features:

Like any other office no-brainer:

>the ability to access nearly every program used at work with a single logon.

Duh.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#160

Earlier quoted context omitted.

What products do those two companies sell?

they sell market protection. to google. it makes crawlers much more expensive. makes everyone depend on their CDNs etc.

Are you referring to google trust services? I don't see how that applies to let's encrypt otherwise.
Post reply on HN