I am flabbergasted that the United States government does not have a requirement that anyone who touches their systems MUST be a vetted US citizen.
A little-known Microsoft program could expose the Defense Department to hackers
51–59 of 59 posts
Re: A little-known Microsoft program could expose the Defense Department to hackers
#52I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds. I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing…
The first is a little embarrassing for Microsoft, but a venal sin, not a mortal one. Makes them look like cheapskates offshoring work, instead of training local workers, but Ok, fine.
The second would be a mortal sin, assuming ( its not clear from the article whether) these non-US people are really operating at IL4 and up. Those assets really need US people especially at the higher impact levels. All of the above is public info described in FedRAMP standards.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#53I am flabbergasted that the United States government does not have a requirement that anyone who touches their systems MUST be a vetted US citizen.
There’s no single overarching federal requirement when it comes to citizenship etc, but I would’ve assumed that ITAR requirements at the very least would’ve made this work US citizen on US soil only.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#54Earlier quoted context omitted.
There’s no single overarching federal requirement when it comes to citizenship etc, but I would’ve assumed that ITAR requirements at the very least would’ve made this work US citizen on US soil only.
Permanent residents are US Persons for ITAR purposes
Re: A little-known Microsoft program could expose the Defense Department to hackers
#55This article is trying to show it as more scary than it is. The key points are: this is systems up to secret level only and sessions are recorded and watched by an escort; the escort is not as tech savvy as the engineers performing maintenance (who are also Microsoft employees, from many countries of origin) but there are other controls too; they can’t just run unsigned code etc. The top secret stuff isn’t using this…
Re: A little-known Microsoft program could expose the Defense Department to hackers
#56I work in azure and this is wildly mischaracterizing the risk, though it is news to me that there are non-US nationals doing escorts for the non-airgapped government clouds. I assume it is OK to say this: Microsoft has a “China” cloud and a non-airgapped “US Government” cloud. It is standard practice that engineers making production touches in the clouds have to be “escorted” by vendors who make sure you’re not doing…
Re: A little-known Microsoft program could expose the Defense Department to hackers
#57Did I miss it, but what do these "digital escorts" actually do. The article doesn't seem to actually explain it. Edit: It's people who watch over what foriegn engineers are doing.
Re: A little-known Microsoft program could expose the Defense Department to hackers
#58some engineers who write the code for production US systems that contain controlled unclassified information live in china. the US government was unaware that this was happening because MSFT hid it from them. as a result, govt stakeholders are/were unable to assess the risk.
all MSFT ATO's should be revoked.
some of the comments point out that foreign workers will help maintain facilities overseas, but govt stakeholders are aware of this, assess the risk, and implement risk controls.
but shady M$FT hid this from govt, and that amplifies the problem!
disclaimer: am google