Live data from Hacker News

Microsoft is a national security threat: ex-White House cyber policy director

theregister.com

71–80 of 224 posts

Re: Microsoft is a national security threat: ex-White House cyber policy director

#71
post #43

Earlier quoted context omitted.

What does one have to do with the other? It’s possible to have more than one threat.

Security is frequently only as strong as the weakest link. If you’re an adversary, would you spend more time on an org’a poor security practices (pentagon failing audits) or a more difficult software vendor?

[dead]

Re: Microsoft is a national security threat: ex-White House cyber policy director

#72
post #52
post #24

Earlier quoted context omitted.

Open Source != GPL. Nor on Github. I don't know what the parent fully meant, but I do know that some agencies have full access to some Microsoft source code. From where I sit, I find it absurd that everything we use isn't open source. Again, not free, but the code given to purchasers. You don't need closed source to protect IP, and the proof is in all of these API lawsuits, and copyright law. I don't want my missiles…

> I do know that some agencies have full access to some Microsoft source code. Access does not mean open source. Open source = OSI and what I think GP meant. And I hold the sentiment that government funded development should be open source.

Open source goes back almost a century, and does mean access to the source code. GPL was created, and other licenses, to allow more than personal use.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#73

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

> The right answer here is if the situation is that bad, make a very public long-term commitment to shift to something else & up-level your IT department to be able to execute multi-year projects competently.

The problem is that there isn't much in terms of alternatives, especially not if you prefer to have one software / vendor / tech stack.

- In groupware, there used to be Lotus Notes, but that went down the drain years ago. Thunderbird can do everything Outlook can (i.e. provide an email client, calendar and address book), but there is no official(ly supported) Thunderbird server software suite so there's always a potential for subtle bugs between whatever one chooses for directory, email and calendar backends.

- for AD there's obviously Samba but it, again, lacks a management UI that supports all of its features, so yet another potential for issues.

- the Office suite alternatives are even more of a nightmare, both in terms of usability, stability as well as compatibility with the millions of legacy files originating from Office. Or hell, even compatibility with old versions of the same app isn't a given in LibreOffice. (And I'm not sure stuff like MS Access even has a FOSS counterpart)

- And then, there's all the other stuff that integrates with AD for authentication/authorization. In a lot of cases, it's "either use MS AD or you're on your own when you hit issues".

- finally, Windows itself. Essentially, the US Government would have to sink billions of dollars into ReactOS development to make it compatible enough with mainstream Windows versions to run all the legacy software that people use - and no, WINE alone is not enough, not for anything that deals with hardware directly. And I wouldn't assume it's possible to even hire enough developers that are skilled to develop for WINE/ReactOS and fulfill the project requirements of never having been exposed to Windows source code.

Microsoft has achieved an insane amount of vendor lock-in, even Apple with all its financial and technological might or Valve (who invested a huge amount of money and work into getting WINE feature-rich enough to run a ton of AAA games on their Steam Deck) have been able to even come close. They can provide as shitty a service/software as they want, their audience literally has no other choice.

(Me personally, I'll keep my Windows 7 and 10 VMs alive for as long as I can, but no way in hell I'm ever moving to the ad-ridden, bling-bling flashy pseudo-hipster-UI disaster that is Windows 11)

Re: Microsoft is a national security threat: ex-White House cyber policy director

#74
post #33
post #28

Earlier quoted context omitted.

This is actually not a bad idea for an international peace treaty. If you make weapons, they must be open source. If the real power in these tools is the secrecy behind their design and implementation, seems like a great way to suck the power out of them.

This strategy would fall apart when you encounter an adversary willing to sacrifice its own people. Nations that care about their own people need to keep a technological advantage on the battlefield.

I mean, all treaties are at risk of failure from bad actors, even implicit ones like mutually-assured-destruction, and in the later case it has been shown to be incredibly effective. But I don't feel like grinding the threat of powerful weapons against each other to be a particularly wise long term solution to security.

I think it's a pretty obvious ipso facto that the more, and more advanced weapons, that are placed into the global battlefield, the less actual security (in life and liberty) we can expect.

The problem isn't that there are adversaries that are willing to sacrifice their people, almost every war is one of attrition after all, it's that leaders that would be adversaries like this are inevitable in a governmental structure that is delegated a monopoly on violence.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#75

CSRB's report on the Exchange Online breach that dropped a couple weeks ago was pretty damning. Microsoft had a situation where a threat actor had access to the entirety of Exchange Online, and possibly their entire cloud. CSRB describes the entire incident as completely avoidable, and resulting from Microsoft's inadequate security culture, and it calls Microsoft out for making public statements about the breach and…

> Microsoft didn't even bother with key rotations anymore after 2021 because one time they fucked it up and it caused an outage, so they decided to just not do that anymore.

Key rotation is almost like restoring from backups. It's an absolutely necessary capability and practice.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#76
post #47
post #5

Earlier quoted context omitted.

I see this sentiment all the time, but it could never apply to the defense sector. Do you really want our nations enemies to have access to the source code of fighter jets, cruise missiles, the nuclear weapons program, or missile defense systems?

Certainly. It’s not like giving them the source code would increase risk significantly, if the software is designed well. I think it would actually strengthen as more researchers would study and submit contribs. I think Linux is as or more secure than windows and it’s open source. There’s tons of sensitive systems that are open source. It’s a design fallacy that security through obscurity is good.

>It’s a design fallacy that security through obscurity is good.

Yet, still obscurity increases security.

Reverse engineering is not trivial and raises the bar.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#77
post #66

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

Well you can't not outsource your security because gov payscale limits do not match market reality. You have to realise that a ton of people who should be directly employed by NSA etc. are actually working for their contracts for this reason.

Partly this is due to the concentration of wealth, inaccessible to taxing.

Naturally government pay would lag behind even the more mediocre H1Bs.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#78
post #59

Earlier quoted context omitted.

Anything used will become a target. How the hell is MS a bigger threat than the rest? If anything a lot of the industry is a way bigger threat and spends less on security.

I don’t understand your comment. Microsofts failures are a threat precisely because it is so used, especially by the US govt. And they may spend a lot on security, but their recent failures have been pretty amateurish. A recent breach they had was due to an old, non-2fa service account with a weak password and privileged access. See also the CISA report about last years breach.

[deleted]

Re: Microsoft is a national security threat: ex-White House cyber policy director

#79
post #49

Earlier quoted context omitted.

Because auditable does not mean the same thing as audited. It is silly that people keep pushing that dead argument after Heartbleed pounded a stake through its heart. Audits are time consuming, challenging, and boring. Experience shows even critical, high profile projects hardly get any review at all by the "world", let alone actual audits by competent domain experts. Quality verification depends on auditing and audi…

the market will determine what should and should not be audited, according to supply and demand. thinking that a couple employees that were not paid for with profit but with printed and taxed government dollars is not and never will be a substitute for the free market, which is a synonym for humanity. not respecting that fact will always result in loss and inefficiency. and no amount of paragraphs can undo that.

The market has been horrid in determining that. There are a few dozen massive companies funding a significant amount of the menial and boring work done on FOSS. Possibly because they have more to lose from their competitors building moats and wide-scale incidents.

Thankfully governments are now also funding FOSS work but this really doesn't align with what you're envisioning, I think.

Re: Microsoft is a national security threat: ex-White House cyber policy director

#80
post #35

I'm not a fan of Microsoft, but this is some amazing blame shifting. The root cause of the problem is the government single-sourcing a vendor and being incapable of negotiating with said vendor. The US government is 10% of Microsoft's annual revenue just on security services (if I read the article correctly) but is failing to negotiate. The right answer here is if the situation is that bad, make a very public long-te…

I’d imagine that these proclamations are part of the negotiation. I wouldn’t want to be a Microsoft account executive on the US govt contract right now; they’re about to have a massive load of additional requirements. And if they don’t play ball, possibly antitrust to weaken their stranglehold on being the only real enterprise player. I’m not saying any of this is the right approach, but it’s a tool in the government…

any commercial channel filled with this much money will attract hordes of smiling useful idiots filling every possible niche. Now you have another problem, managing useful idiots over time.

source: knows some idiots

Post reply on HN