Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

221–230 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#221

The government does most things poorly and with little regard to budget or quality. They can't solve problems that are much simpler than cloud computing, so why should I expect them to perform better at a more complex problem?

> The government does most things poorly and with little regard to budget or quality. That's a common line by conservatives who are actively sabotaging government with policies and laws which they then point to as evidence of such inefficiencies.

[dead]

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#222

The government does most things poorly and with little regard to budget or quality. They can't solve problems that are much simpler than cloud computing, so why should I expect them to perform better at a more complex problem?

I think this perspective has resolutely been debunked at this point. The government has historically, routinely, consistently, solved problems more complex than cloud computing. The only way you'd think otherwise is if you had some other motivation to pretend otherwise... some sort of ideology.

https://news.ycombinator.com/item?id=47434383

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#223

> [...]And because federal agencies were allowed to deploy the product during the review, GCC High spread across the government as well as the defense industry. By late 2024, FedRAMP reviewers concluded that they had little choice but to authorize the technology — not because their questions had been answered or their review was complete, but largely on the grounds that Microsoft’s product was already being used acro…

> Not criticizing FedRAMP Think it's very important to criticize FedRAMP. The FedRAMP board is extremely slow moving and continuously disregards industry feedback. As a result, FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave. This has a sticker p…

> Going through FedRAMP yourself requires a staff who is willing to put in a dedicated effort on the compliance paperwork

But couldn’t you say the same for CMMC 2.0, NIST 800-171, RMF, JSIG, STIG, etc?

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#225
post #210

Earlier quoted context omitted.

I can only speak from the perspective of someone who used/admined in all those 3 environments. I'm surprised you ranked google's support above microsoft. I've also seen bugs that would be unusual in other clouds, but other clouds have other pros/cons as well. GCP for example is capable, but it is tedious to use, and even harder to log/audit. Of all 3 CSPs azure has the best identity management system. they're the wor…

The GCP support was fine, not great. For specific problems that you could provide data for and ideally a reproduction they were very good. But if you had feedback or concerns about how something was designed, or a missing feature they were useless (all of support, sales and product)

Thanks, sounds about right. In my experience too, they're ok, but not great at "hand holding", for better or worse.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#226

Earlier quoted context omitted.

But it doesn't. Full authentication bypass exploits are extremely rare and unheard of among tech giants. Maybe account takeover/recovery, sure, but full bypass? It just never happens. Microsoft goes beyond that: they've managed to have a critical vulnerability in almost every authentication product they have ever created. It's exceptional.

> But it doesn't. That we know of. > It's exceptional. I agree, but I look at it as a question of cost. would it make sense for Russia to spend on resources to compromise GCP or AWS? Microsoft's EntraID/AzureAD itself is an exceptional product in that organization's dependency on it, especially US government orgs, is exceptional. If APTs target AWS, they will compromise it, period. Of course the caveat is time, skill…

"If APTs target AWS, they will compromise it"

Not all compromises are the same. They might get into some logging API in AWS. With Azure, the get the master keys. Both are compromises; they aren't the same. Either you have never used Azure, know nothing about security, or you work in MS marketing.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#228

> [...]And because federal agencies were allowed to deploy the product during the review, GCC High spread across the government as well as the defense industry. By late 2024, FedRAMP reviewers concluded that they had little choice but to authorize the technology — not because their questions had been answered or their review was complete, but largely on the grounds that Microsoft’s product was already being used acro…

> Not criticizing FedRAMP Think it's very important to criticize FedRAMP. The FedRAMP board is extremely slow moving and continuously disregards industry feedback. As a result, FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave. This has a sticker p…

> FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave

Having been through FedRAMP twice, I can this is absolute fiction. What does Palantir have to do with anything?

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#229
post #40

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?

Ah so it’s not just me and my company!
Post reply on HN