I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.
Microsoft Chose Profit over Security, Whistleblower Says
41–50 of 318 posts
Re: Microsoft Chose Profit over Security, Whistleblower Says
#42This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…
There are bugs and there are critical flaws you’ve been warned about. This is the latter.
The fact that this was known by Microsoft but not fixed is the story.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#43This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…
That is not a screw-up, that is a deliberate decision.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#44If you pay and promote people for features, and don't reward security culture, people are not dumb: they and the management layers will optimize for that.
I don't know how to design incentives to solve for this, but this is always going to be the way it is.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#45This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…
Many companies make bad choices around security for profit, however that factors I listed above make this extremely egregious.
I would seriously question any use of Microsoft products in any security conscious organization after this reveal. I also hope that anyone negatively effected by the Solar Winds sue Microsoft for knowing about the vulnerability for years without fixing it or disclosing it.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#46Earlier quoted context omitted.
I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…
Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#47What is different in our industry that companies (and managers) get away with such malice?
Re: Microsoft Chose Profit over Security, Whistleblower Says
#48This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…
My understanding is that it was a two-part exploit:
1) The Solarwinds product was hacked to allow backdoor access to organizations' on-prem networks.
2) The hackers then took advantage of the "Golden SAML" vulnerability in Microsoft's Active Directory Federation Service (AD FS) to leapfrog via "seamless SSO" from the on-prem network into the organization's cloud resources hosted by Microsoft.
The article is all about how various Microsoft leaders and staff did not fix #2, because many said it would never be an actual issue exposed to the world.
This is extra damning because Microsoft is selling components at the core of both governments' on-prem and cloud systems, so if they don't take security extra seriously, their systems can present passive vulnerabilities.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#49> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees. Satya's model of making security a priority at Microsoft: - Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for? - Install a recorder which records everything you do. For the benefi…
That event really drove home for me the fact that all of the trainings, emails, processes, etc. are mostly plausible deniability. There are people who care about security at MS. I know, I've met them, but for the most part all of this exists so that Satya can plausibly say in court or in front of congress, "well we told them to do security better. This is clearly the fault of product teams or individual contributors, not Microsoft policy and incentives."
Re: Microsoft Chose Profit over Security, Whistleblower Says
#50corporate morality is a Potemkin village. It's all about the profit and appeasing the shareholder, baby!
is anybody honestly surprised at this point? The abbreviation of "M$" is well deserved despite small OSS contributions and attempts to PR their way out of previous history (ie, United States v. Microsoft Corp. [2001])