Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

21–30 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#21
post #13

Microsoft’s security failures are a threat to national security. Microsoft itself is not.

Anything used will become a target. How the hell is MS a bigger threat than the rest? If anything a lot of the industry is a way bigger threat and spends less on security.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#22
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

"never apply".

https://dodcio.defense.gov/Open-Source-Software-FAQ/

Re: Microsoft is a national security threat: ex-White House cyber policy director

#23
I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-term commitment to shift to something else & up-level your IT department to be able to execute multi-year projects competently. Instead of meeting Microsoft on the business playing field, it's trying to use scary "national security threat" verbiage to try to bully them in the court of public opinion.

Regarding security, at the end of the day, the US government is a huge target for adversaries. You can't outsource your security practices & if MS software is really that much worse they should be fixing their purchasing requirements. The reality though is that whatever software the US government would switch to would become the focus of adversarial research.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#24
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Open Source != GPL. Nor on Github. I don't know what the parent fully meant, but I do know that some agencies have full access to some Microsoft source code.

From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers.

You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law.

I don't want my missiles to not have code I cannot edit, and stepping back from the top secret sphere, tangential I am appalled at how crappy car firmwares are closed source.

In the old days, a country's national transport agencies could look at evey linkage, every rod, every part of a car design.

Now 90% of the design is hidden. And with electric cars, it's even more firmware.

And the idea that OTA updates are a thing for cars. The madness. The absolute madness.

How much do you want to bet that charging firmwares are remotely updatable?

Now imagine that 9am on Monday, every electric car explodes?

Even today, that would mean an immense number of houses on fire. How could the fire department handle it?

And how could it be handled as the fires spread? And what if lots of other infra goes up?

And that's today. What about when 90% of transportationn is electric? Even if not a single house or building burned, or person was hurt, how would you replace all those buses, trucks, delivery vehicles, and cars? As COVID showed us, you cannot ramp up and down overnight.

And what if it happened to all our allies? Would they still sell part to us?

What of all the tractors are electric, and we miss corn and wheat planting season?

My point in this tangent is... no one is even looking at the important bits. And to reiterate, how much do you want to bet charging firmwares are remotely updated? Really, they should be air gapped from the entire rest of the car.

Letting potential hackers have access in this way, is just plain lazy and reckless.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#25
post #22
post #5

Earlier quoted context omitted.

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

"never apply". https://dodcio.defense.gov/Open-Source-Software-FAQ/

“All”

Re: Microsoft is a national security threat: ex-White House cyber policy director

#26
post #10

all tax payer funded software should be open source

Dunno if all government software should be open source but government should definitely avoid vendor lock ins.

There's a couple places in the book Skunk Works where the author laments the government's procurement strategy for planes that always ensured different manufacturers got at least some contracts so they wouldn't go out of business and leave the government reliant on just one supplier. He derided it as a form of socialism! Alas, it was a reasonable approach.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#27

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

The Pentagon can’t even pass an audit for the past 6 years, but yeah Microsoft is the national security threat.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#28
post #5

all tax payer funded software should be open source

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

This is actually not a bad idea for an international peace treaty. If you make weapons, they must be open source. If the real power in these tools is the secrecy behind their design and implementation, seems like a great way to suck the power out of them.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#29

Wait til someone tells them that Google can basically unplug the internet

Even more reason to tackle monopolies and break up 'too big to fail' companies.

Larger ships carry more people and can thus sink with more, let's cut the ships in half?

Point being, there's a lot of infrastructure that kinda doesn't make sense split up. If you want resiliency, build a second system in parallel not make management of an existing one times more expensive.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#30
post #24
post #5

Earlier quoted context omitted.

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Open Source != GPL. Nor on Github. I don't know what the parent fully meant, but I do know that some agencies have full access to some Microsoft source code. From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers. You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law. I don't want my missiles…

That's all fine and good but I don't want missiles with code you can edit. I didn't vote for you, nor do I trust you.
Post reply on HN