Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

271–280 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#272
post #239

I don't see a future here that doesn't involve significant legislation over network security and include jail time for major offenses. Every time something like this happens, there's always that organizational Cassandra (usually the CISO) that saw it all coming but was ignored. Sooner or later someone will get burned badly enough that the consensus will be that tech cannot regulate itself on security. We've already g…

I can think of one solution to the "too few players" problem. Break them up.

I, too, wouldn't mind living in that timeline, but that's just not going to happen for a number of reasons that are so obvious as to not be worth enumerating. Dwelling on unrealistic solutions prevents you from perceiving the possible.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#273

The solution is complete zero trust and distrusting the network in organizations. You should treat the internal network as external -- hostile. Google does this. They were the first ones to widely adopt zero trust with BeyondCorp and there has not been a Google internal organizational breach since Aurora (which made them adopt BeyondCorp, what they call zero trust). You have completely managed endpoints, strong harde…

I'm half with you, but riddle me this: in a ZT environment, every request needs to be accompanied by some verifiable assertion of identity and authorization. In this case, and others we've seen recently, the identity provider themselves has been compromised. For example because an attacker has obtained signing keys that allow them to effectively masquerade approval from.the identity provider. So even in a ZT environment, isnt it game over at that point?

It seems that we have a situation where all out trust is in the identity provider now, and we suffer when that provider is compromised.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#274

The solution is complete zero trust and distrusting the network in organizations. You should treat the internal network as external -- hostile. Google does this. They were the first ones to widely adopt zero trust with BeyondCorp and there has not been a Google internal organizational breach since Aurora (which made them adopt BeyondCorp, what they call zero trust). You have completely managed endpoints, strong harde…

Are there any other companies besides Google that have implemented this solution? If not then I don't think you can really call it a solved problem.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#275

Earlier quoted context omitted.

I agree Microsoft is a problem. I just wish you tech guys took an equally critical stance towards Google, a genuine ad company.

And Apple, the upstart ("stealth mode") ad company.

The upstart ad company that spent years and tens of billions of dollars to develop a privacy focused AI in the cloud platform? The same upstart that offers encrypted cloud storage that even it can’t decrypt? Congrats on the false equivalency argument.

Guys like you do yourself a disservice. No one takes your hyperbolic statements seriously. Keep posting this nonsense if it makes you feel better.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#277

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

There is nothing wrong with processes per se, From civil engineering to automotive to aviation there is a tangible outcome to all the laborious audits and paperwork. These systems are lot safer after regulations were put in place however onerous and ineffective they seem

What would this even look like in software?

I always wonder if software is different than physical construction, or if software is just less mature of a discipline.

In software, we can’t estimate projects accurately and consistently. We have to build a few to throw away just to get a better (yet still incomplete) picture of the problem we’re trying to solve.

Imagine if the people building your house had to build half of it and then start over. Maybe twice.

That never happens in physical construction. Maybe something has to be redone because someone made a mistake, but almost never due to not understanding the problem. So what’s different about software?

Re: Microsoft Chose Profit over Security, Whistleblower Says

#279
post #236

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

Did you buy the more expensive lock for your house? Are your doors fortified, if they are why isn't the steel an inch thicker? Do you also choose having money over security? Sounds like the government also chose having a more productive work force, etc, over higher costs and lower productivity.

> why isn't the steel an inch thicker?

In our analysis we determined that if the steel doors were thicker it would hinder our team of ex-special-forces security guards from operating their bazookas effectively in the event a suspicious person is spotted. Unfortunately it’s all too common that potentially dangerous fugitives on the run are trying to blend in as “mail carriers” and “neighbors on a walk”. Anyway, the auditors relented on the steel door issue, but then hammered us on why we didn’t have any tanks moving in formation in the front yard as a deterrent. In fairness, the FedEx guy made it all the way to our front door in two separate incidents last week. So the auditors have a point.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#280
post #63

Earlier quoted context omitted.

I do. It's law, regulation and liability. Until heads roll, until someone is punished, likely nothing will happen.

This is a non-solution, and automatic "head rolling" and punishments will only lead to reducing the actual meaningful experience accumulation - the mean time between major breaches like this is long enough and variable enough that the next person would be likely equally incompetent, inexperienced and inattentive. There's no easy solution, because it's inherently very difficult problem - making a correct trade-off bet…

You are completely and totally wrong and fundamentally misunderstand how the world works.

This is old stuff, man, but it always plays out.

SKIN IN THE DAMN GAME is the only thing that matters.

The parties involved don't feel any pain from sucking at security, so they may continue to suck at security. It REALLY is that simple.

Post reply on HN