Live data from Hacker News

Microsoft Dependency Has Risks

blog.miloslavhomer.cz

21–30 of 238 posts

Re: Microsoft Dependency Has Risks

#21

Fundamentally it’s hard to pushback against an authoritarian government. There is very little to stop Trump from sending Doge into MS headquarters with Marines and demanding admin access so they can make the change. Thinking the dependency on Microsoft (or any company) is the risk then you haven’t been paying attention.

The incident in question targeted someone outside of the US, where DOGE has no direct influence (yet).

Re: Microsoft Dependency Has Risks

#22

Earlier quoted context omitted.

I wasn't aware of any major Trump-era policies that significantly reduced Microsoft’s dominance. Curious what you're referencing?

Trump has been outrageously hostile to our supposed European allies, and is extremely petty, vindictive, and doesn’t give a damn about security or privacy. Furthermore, the checks that would normally provide counter this like congress or the Supreme Court are currently stacked such that he can do horrendous things without consequence. Our media and tech companies are also more than happy to avoid challenging him. Oth…

Thanks for the context!

Still seems like, for most businesses, the biggest hurdle is how deeply Microsoft’s services are embedded rather than politics

Re: Microsoft Dependency Has Risks

#23

Earlier quoted context omitted.

AD and Domain Servers are like a cancer that will grow metastases around your org, costing user and client cals all over the place, even for every desk phone if you're not careful. The only winning move is never to play their game in the first place.

I'm in a situation where due to staff skillsets and ease of management then GPOs are required. Local GPOs would be insane to manage across thousands of PCs

InTune/MDMs are finally eating away at the need for GPOs for most use cases. Someone already familiar with AD & Group Policy should be able to easily transition to InTune Configuration Policies. MS even has a tool now to import your GPOs.

There's still a few that don't have direct equivalents, but the list is growing smaller and smaller.

Re: Microsoft Dependency Has Risks

#24

Earlier quoted context omitted.

Trump has been outrageously hostile to our supposed European allies, and is extremely petty, vindictive, and doesn’t give a damn about security or privacy. Furthermore, the checks that would normally provide counter this like congress or the Supreme Court are currently stacked such that he can do horrendous things without consequence. Our media and tech companies are also more than happy to avoid challenging him. Oth…

Thanks for the context! Still seems like, for most businesses, the biggest hurdle is how deeply Microsoft’s services are embedded rather than politics

And the hardest part of it often ends up being "We can replace most of Microsoft's apps and services except one (and it's usually Excel) so we might as well just keep everything else."

Microsoft is king at "Good enough." It's rarely the best option of anything, but what they do put out is bundled aggressively and is generally "good enough."

So, you have a business where a large portion of the user base needs Excel. So you have licensing for that. Sure you can still use other services - you can use Okta instead of EntraID, some other MDM besides InTune, some other EDR besides Defender but once you have 1 product, why would you, when it's significantly cheaper (both in terms of actual cost per user per month and in terms of employing talent that can administer a MS ecosystem) to just go all in with Microsoft.

Because of the way Microsoft designed their suite of software and services, the only realistic choice is either all in on Microsoft, or no Microsoft at all, and to fix that we need antitrust action.

Re: Microsoft Dependency Has Risks

#25
post #11

For most businesses, the cost and difficulty of shifting away from Microsoft outweigh the benefits

Maybe. Some things go deep, true. However most businesses don't use most of Microsoft products - even the ones that do, the usage of the more complicated products is far more minuscule than imagined by e.g. CFOs, etc. The real thing keeping many "in the fold" as it were would be authentication services. Which are overcomplicated and probably easier to manage without...

It really depends on the size of the business. With smaller businesses it is easy to use alternatives. However any business beyond 1000 employees will give in to shareholder pressure and adopt distrust as its core value.

Microsoft Active Directory has excellent tooling for middle-management-heavy businesses. For better or for worse it provides the most integrated solution to reduce a desktop PC to a perfect thing for repetitive, boring, soul crushing office work. No other software solution comes close.

While I like Windows as a desktop platform, the reasons that it was designed as it is are very clear. To make cheapest laptops as dystopian as possible, you need systems that can run the same boring software for decades. Not for the good for the environment but for profits.

Windows provides all APIs to deeply integrate with Active Directory and MS Office. All engineering, accounting and finance software are deeply integrated with them. They literally run entire countries. I have seen engineering software that used Visio diagrams for designing factory pipelines. It is near impossible to pull the bigger businesses and governments out of this trap without completely upending entire sectors worth trillions. I think only very determined regimes like China can pull it off.

Re: Microsoft Dependency Has Risks

#26

Earlier quoted context omitted.

Right, it’s stuff like Active Directory and how everything’s tied together. Once you’re using that for auth, it’s really tough to back out without a lot of effort. We’ve looked into FreeIPA and similar options, but honestly, nothing really holds a candle to Active Directory yet.

AD and Domain Servers are like a cancer that will grow metastases around your org, costing user and client cals all over the place, even for every desk phone if you're not careful. The only winning move is never to play their game in the first place.

genuinely interested, what are the alternatives ? i know ping/forgerock and some old ibm stuff.

what is state of the art today that compares to ActiveDirectory (not talking azureAd - or whatever they call it these days) ?

Re: Microsoft Dependency Has Risks

#27
post #18

The trick with Microsoft is to very carefully separate the good parts from the bad ones. Labeling all of Microsoft as banned is really constraining your technology options. This is a gigantic organization with a very diverse set of people in it. There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situation…

"There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situations. There's a reason every AAA game engine depends on it in some way."

I'm not interested in AAA games engines writing and nor is most of the world. If that is it, then you have damned MS with (very) faint praise.

Re: Microsoft Dependency Has Risks

#28
post #18

The trick with Microsoft is to very carefully separate the good parts from the bad ones. Labeling all of Microsoft as banned is really constraining your technology options. This is a gigantic organization with a very diverse set of people in it. There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situation…

> There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situations. There's a reason every AAA game engine depends on it in some way.

The reason all the AAA games are on it is because they're on the Windows platform, and more importantly their customers are on the Windows platform.

If 95% of gamers ran MacOS instead of Windows, you'd see a very different tech stack among game developers.

Re: Microsoft Dependency Has Risks

#29
post #27
post #18

The trick with Microsoft is to very carefully separate the good parts from the bad ones. Labeling all of Microsoft as banned is really constraining your technology options. This is a gigantic organization with a very diverse set of people in it. There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situation…

"There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situations. There's a reason every AAA game engine depends on it in some way." I'm not interested in AAA games engines writing and nor is most of the world. If that is it, then you have damned MS with (very) faint praise.

I think you misunderstand- game engines are complex beasts and visual studio and/or .Net (in any of its incarnations) have the best debugging workflow I've seen.

Typescript is also Microsoft. So is ONNX.

Re: Microsoft Dependency Has Risks

#30
post #27
post #18

The trick with Microsoft is to very carefully separate the good parts from the bad ones. Labeling all of Microsoft as banned is really constraining your technology options. This is a gigantic organization with a very diverse set of people in it. There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situation…

"There aren't many things like .NET, MSSQL and Visual Studio out there. The debugger experience in VS is the holy grail if you have super nasty real world technology situations. There's a reason every AAA game engine depends on it in some way." I'm not interested in AAA games engines writing and nor is most of the world. If that is it, then you have damned MS with (very) faint praise.

To paint a picture: I’ve worked with Microsoft technologies almost exclusively for decades but recently I was forced to pick up some Node.js, Docker, and Linux tooling for a specific app.

I can’t express in words what a giant step backwards it is from ASP.NET and Visual Studio. It’s like bashing things with open source rocks after working in a rocket manufacturing facility festooned with Kuka robots.

It’s just… end-to-end bad. Everything from critical dependencies developed by one Russian kid that’s now getting shot at in Ukraine so “maintenance is paused” to everything being wired up with shell scripts that have fifty variants, no standards, and none of them work. I’ve spent more time just getting the builds and deployments to work (to an acceptable standard) for Node.js than I’ve spent developing entire .NET applications! [1]

I have had similar experiences every few years for decades. I touched PHP once and recoiled in horror. I tried to get a stable build going for some Python ML packages and learnt that they have a half-life measured in days or hours after which they become impossible to reproduce. Etc…

Keep on assuming “Microsoft is all bad” if you like. You’re tying both hands behind your back and poking the keyboard with your nose.

PS: The dotnet SDK is open source and works fine on Linux, and the IntelliJ Rider IDE is generally very good and cross-platform. You're not forced to use Windows.

[1] The effort required to get a NestJS app to have barely acceptable performance is significantly greater than the effort to rewrite it in .NET 9 which will immediately be faster and have a far bigger bag of performance tuning tools and technologies available if needed.

Post reply on HN