Microsoft’s security failures are a threat to national security. Microsoft itself is not.
Microsoft is a national security threat: ex-White House cyber policy director
21–30 of 224 posts
Re: Microsoft is a national security threat: ex-White House cyber policy director
#22all tax payer funded software should be open source
I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?
Re: Microsoft is a national security threat: ex-White House cyber policy director
#23Regarding security, at the end of the day, the US government is a huge target for adversaries. You can't outsource your security practices & if MS software is really that much worse they should be fixing their purchasing requirements. The reality though is that whatever software the US government would switch to would become the focus of adversarial research.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#24all tax payer funded software should be open source
I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?
From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers.
You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law.
I don't want my missiles to not have code I cannot edit, and stepping back from the top secret sphere, tangential I am appalled at how crappy car firmwares are closed source.
In the old days, a country's national transport agencies could look at evey linkage, every rod, every part of a car design.
Now 90% of the design is hidden. And with electric cars, it's even more firmware.
And the idea that OTA updates are a thing for cars. The madness. The absolute madness.
How much do you want to bet that charging firmwares are remotely updatable?
Now imagine that 9am on Monday, every electric car explodes?
Even today, that would mean an immense number of houses on fire. How could the fire department handle it?
And how could it be handled as the fires spread? And what if lots of other infra goes up?
And that's today. What about when 90% of transportationn is electric? Even if not a single house or building burned, or person was hurt, how would you replace all those buses, trucks, delivery vehicles, and cars? As COVID showed us, you cannot ramp up and down overnight.
And what if it happened to all our allies? Would they still sell part to us?
What of all the tractors are electric, and we miss corn and wheat planting season?
My point in this tangent is... no one is even looking at the important bits. And to reiterate, how much do you want to bet charging firmwares are remotely updated? Really, they should be air gapped from the entire rest of the car.
Letting potential hackers have access in this way, is just plain lazy and reckless.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#25Earlier quoted context omitted.
I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?
"never apply". https://dodcio.defense.gov/Open-Source-Software-FAQ/
Re: Microsoft is a national security threat: ex-White House cyber policy director
#26all tax payer funded software should be open source
Dunno if all government software should be open source but government should definitely avoid vendor lock ins.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#27I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…
Re: Microsoft is a national security threat: ex-White House cyber policy director
#28all tax payer funded software should be open source
I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?
Re: Microsoft is a national security threat: ex-White House cyber policy director
#29Wait til someone tells them that Google can basically unplug the internet
Even more reason to tackle monopolies and break up 'too big to fail' companies.
Point being, there's a lot of infrastructure that kinda doesn't make sense split up. If you want resiliency, build a second system in parallel not make management of an existing one times more expensive.
Re: Microsoft is a national security threat: ex-White House cyber policy director
#30Earlier quoted context omitted.
I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?
Open Source != GPL. Nor on Github. I don't know what the parent fully meant, but I do know that some agencies have full access to some Microsoft source code. From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers. You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law. I don't want my missiles…