So...Golden SAML isn't a vulnerability, as the CyberArk article quoted in the post reiterates, it's a type of attack that requires completely comprising the box before using. Unless I am misunderstanding something, I don't see any particular flaw, per se. As Microsoft (mocked in the article) would say, it's not crossing a security boundary. SSO will ALWAYS have this particular tradeoff. If your SSO infrastructure is…
Microsoft Chose Profit over Security, Whistleblower Says
171–180 of 318 posts
Re: Microsoft Chose Profit over Security, Whistleblower Says
#172> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…
Re: Microsoft Chose Profit over Security, Whistleblower Says
#173> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…
The Microsoft bribes scandal broke not too long after I had to take the "hey don't do bribes" training at Microsoft. That event really drove home for me the fact that all of the trainings, emails, processes, etc. are mostly plausible deniability. There are people who care about security at MS. I know, I've met them, but for the most part all of this exists so that Satya can plausibly say in court or in front of congr…
Re: Microsoft Chose Profit over Security, Whistleblower Says
#174If you want sanity paired with outcomes in the career, work at places that are technical and have a strong regulatory incentive and related funding, or a strong threat model closely tied to profits to care about security culturally.
Main examples for me that hit that are:
- pre-IPO startups that want to pass SOC2 etc to go public: have the reg and profit incentive and pay to buy a security team from scratch
- crypto: has the threat model and profit incentive due to key theft and so on. Pays well too and great risk space to test out sec skills
- public tech cos providing a lot of critical infra: to an extent, some can veer into Too Big to Fail like MSFT, some have stronger internal sec teams like Google/Project Zero, Verizon/Paranoids, Cloudflare seems good.
- Banking is maybe: they have funds, more risk-averse culture, heavily regulated. But healthcare is also heavily regulated and id never work in it due to the volume of exploits and lack of care.
So ya, don’t work at MSFT as a sec eng IMO unless you’re on the DART team and want to see a lot of diverse incident response with legit threat actors, or want to do really low level OS sec.
No idea about Apple sec eng work, on this note.
This is also why the avg tenure in security careers +/- 10 years. Your sanity runs out and often pay is good enough where you can save up and do something else with your life by 30/40.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#175Earlier quoted context omitted.
Let's Encrypt Google Trust Services Disclaimer: I've worked in both of these :)
What products do those two companies sell?
LE is of course, a non-profit, so maybe this doesn't apply there.
Google Trust Services operates under Google, and is technically "for profit". But no, we did not put profits over security.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#176Re: Microsoft Chose Profit over Security, Whistleblower Says
#177Earlier quoted context omitted.
The Microsoft bribes scandal broke not too long after I had to take the "hey don't do bribes" training at Microsoft. That event really drove home for me the fact that all of the trainings, emails, processes, etc. are mostly plausible deniability. There are people who care about security at MS. I know, I've met them, but for the most part all of this exists so that Satya can plausibly say in court or in front of congr…
At higher levels compensation is now tied to security outcomes. This is as committed as it gets. Definitely not theater.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#178> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…
I have no broad evidence of this, but I suspect that the more beginner-friendly Linuxes are guilty of a lot of the sins that you laid out here. I seem to remember some controversy with Canonical recording your searches when hitting the super key, and Ubuntu having Amazon ads built in by default. People who love to geek out about computers can of course install Arch or Gentoo or NixOS Minimal and then audit the packag…
It's a fantasy to think that random devs can audit kernel/security code. No single person can. Too many lines of code to audit (that you didn't write yourself). Even if you hired a team, by the time the team does the audit, the goalposts have moved with new source code.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#179Earlier quoted context omitted.
It's not surprising when a linux distribution was taken over by a capitalistic firm, it decided to forgo good values, and instead prioritized profits over everything else. > I really don't know how to fix this problem Stop using software made by companies that do bad things. Improve the software that doesn't.
> Stop using software made by companies that do bad things. Improve the software that doesn't Or stop buying their stock... but that is difficult thing to embrace. As, we know, these companies are very profitable.
I think a lot of people with full-time desk jobs have a 401k or a Roth IRA, and most of those are stock-based (which is really the only way to make sure your money doesn't decay in value due to inflation), and those are generally going to be stuff like total-indexes or S&P500-based index funds.
There's probably technically something else you could peg it to, so that's probably not strictly true, but I think an awful lot of people are sort of buying Apple stock without fully realizing it.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#180The hearing will be streamed on YouTube in ten minutes from this comment: https://www.youtube.com/watch?v=kB2GCmasH4c