I work in infosec, and this sounds like a communication failure on the whistleblower's part. Contrary to what many people believe, the profits should be prioritized over security for the most companies, that's only natural (after all, they don't generate any profits themselves, typically). The key is finding the right balance for this tradeoff. Business leaders are the ones that are responsible for figuring out the a…
During my Master's, security was one of the subjects I took. It started with an equation that related risk (how much you'd lose if something bad happened), the probability of that risk, and the cost of mitigating that risk. The instruction being, one tries to find a mitigation that costs less than the exploitation of the risk. And note here that "cost" does not refer to just money, but could be computational cost, en…
Microsoft Chose Profit over Security, Whistleblower Says
81–90 of 318 posts
Re: Microsoft Chose Profit over Security, Whistleblower Says
#82Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…
Here in Norway a bridge built with known structural deficiencies did in fact collapse[1], and basically nothing has happened except tax payers get to pay even more for a new bridge. Unless enough lives are lost, people generally don't care that much it seems. [1]: https://www.nrk.no/innlandet/statens-vegvesen-legg-fram-rapp...
Maybe they proudly stated knowing the risks, and while unfortunate, risks became reality. And then everything is fine.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#83The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…
I think it needs a massive cultural shift, but from customers. If customers were willing to evaluate security (consumers cannot, but enterprise can) properly, demand binding assurances, and make buying choices accordingly industry would respond.
Of course MS is too strongly entrenched in the desktop market for this to be completely effective.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#84I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.
* go bankrupt because we can't be secure
* be less secure and stay in business
...guess which one will almost always win.
Microsoft of course, as a multi-trillion-dollar company has no such threat and there's no reasonable excuse for this.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#85Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…
Here in Norway a bridge built with known structural deficiencies did in fact collapse[1], and basically nothing has happened except tax payers get to pay even more for a new bridge. Unless enough lives are lost, people generally don't care that much it seems. [1]: https://www.nrk.no/innlandet/statens-vegvesen-legg-fram-rapp...
If the public is expected to keep government and corporstions in check but the public doesn't care, it can only end poorly.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#86Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…
Lack of professional licensure that binds you to state regulation with jail time as one of the stated punishments besides financial liability.
Heh, the government could start effecting change by mandating licensure and sign-offs by licensed individuals when contracting for software products sold to the government.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#87I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.
I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…
Re: Microsoft Chose Profit over Security, Whistleblower Says
#88Earlier quoted context omitted.
Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.
Would that be securities fraud, because they're lying to investors? (Going by Matt Levine's "everything is securities fraud" logic here to see if that might actually change behavior…)
Re: Microsoft Chose Profit over Security, Whistleblower Says
#89The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…
This is exactly it. There is no incentive to prioritise security. It is not visible to customers, except in terms of compliance, most likely a check-list approach. I think it needs a massive cultural shift, but from customers. If customers were willing to evaluate security (consumers cannot, but enterprise can) properly, demand binding assurances, and make buying choices accordingly industry would respond. Of course…
Where i work, IT is outsourced and decision to buy most of the SW is made by managers who have no idea about computers.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#90This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…
Businesses want that when they login to a computer, they are SSO'ed in to all their apps. That's how ADFS works, you authenticate to it using kerberos and it issues you a SAML token. Here they stole apparently the key used to sign the SAML token so they could generate their own.
Unless there was some vulnerability that exposed the key publically, I fail to see how in this particular incident its Microsoft's fault.