Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

81–90 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#81
post #69

I work in infosec, and this sounds like a communication failure on the whistleblower's part. Contrary to what many people believe, the profits should be prioritized over security for the most companies, that's only natural (after all, they don't generate any profits themselves, typically). The key is finding the right balance for this tradeoff. Business leaders are the ones that are responsible for figuring out the a…

During my Master's, security was one of the subjects I took. It started with an equation that related risk (how much you'd lose if something bad happened), the probability of that risk, and the cost of mitigating that risk. The instruction being, one tries to find a mitigation that costs less than the exploitation of the risk. And note here that "cost" does not refer to just money, but could be computational cost, en…

For the MS size entities, the risk calculation is way more complicated. The 1:1 between cost of mitigation vs cost of exploitation only applies to opportunistic attacks, really. At the level where APTs get involved, the data / access might be so valuable that they'd gladly outspend blue team's budget by a factor of 10-100.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#82
post #47

Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…

Here in Norway a bridge built with known structural deficiencies did in fact collapse[1], and basically nothing has happened except tax payers get to pay even more for a new bridge. Unless enough lives are lost, people generally don't care that much it seems. [1]: https://www.nrk.no/innlandet/statens-vegvesen-legg-fram-rapp...

> basically nothing has happened

Maybe they proudly stated knowing the risks, and while unfortunate, risks became reality. And then everything is fine.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#83

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

This is exactly it. There is no incentive to prioritise security. It is not visible to customers, except in terms of compliance, most likely a check-list approach.

I think it needs a massive cultural shift, but from customers. If customers were willing to evaluate security (consumers cannot, but enterprise can) properly, demand binding assurances, and make buying choices accordingly industry would respond.

Of course MS is too strongly entrenched in the desktop market for this to be completely effective.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#84

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

In other words, when faced with an existential threat...

* go bankrupt because we can't be secure

* be less secure and stay in business

...guess which one will almost always win.

Microsoft of course, as a multi-trillion-dollar company has no such threat and there's no reasonable excuse for this.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#85
post #47

Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…

Here in Norway a bridge built with known structural deficiencies did in fact collapse[1], and basically nothing has happened except tax payers get to pay even more for a new bridge. Unless enough lives are lost, people generally don't care that much it seems. [1]: https://www.nrk.no/innlandet/statens-vegvesen-legg-fram-rapp...

I'm not sure if this would line up with the Dunbar number or something similar, but it sure seems reasonable that societies and centralized power should never grow beyond the scale where people stop caring.

If the public is expected to keep government and corporstions in check but the public doesn't care, it can only end poorly.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#86
post #47

Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…

>What is different in our industry that companies (and managers) get away with such malice?

Lack of professional licensure that binds you to state regulation with jail time as one of the stated punishments besides financial liability.

Heh, the government could start effecting change by mandating licensure and sign-offs by licensed individuals when contracting for software products sold to the government.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#87
post #13

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.

I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so. > Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security." https://www.wired.com/2002/01/bill-gates-trustworthy-computi... > Satya Nadella in 2024: "If you’re faced with the tradeoff between se…

Related to the GPs point, do you know of any company that publicly admits that they chose profit above all else?

Re: Microsoft Chose Profit over Security, Whistleblower Says

#88
post #62
post #26

Earlier quoted context omitted.

Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.

Would that be securities fraud, because they're lying to investors? (Going by Matt Levine's "everything is securities fraud" logic here to see if that might actually change behavior…)

Investors are very happy with profit over security choices. Moreover, decisions to maximize profitability thinking only in short term is also not bad for them if they perceive that can sell their shares before the consequences. A company that do not place profit above other things is not a good company to invest money and see it grow. A company will invest in security only as long as it increases profitability. Doing otherwise is not maximizing profits and lose investors. If you are a "security company", surely this means that you need the security to sell the product and get profitability. Other companies will have other tradeoffs to choose how much they invest in security to maximize profitability.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#89
post #83

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

This is exactly it. There is no incentive to prioritise security. It is not visible to customers, except in terms of compliance, most likely a check-list approach. I think it needs a massive cultural shift, but from customers. If customers were willing to evaluate security (consumers cannot, but enterprise can) properly, demand binding assurances, and make buying choices accordingly industry would respond. Of course…

> If customers were willing to evaluate security (consumers cannot, but enterprise can)

Where i work, IT is outsourced and decision to buy most of the SW is made by managers who have no idea about computers.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#90

This whole article seems a bit odd to me. What is "the product" ? Presumably this is not related to earlier problems with SolarWinds. Did MS screw up. Yes. However, all things have bugs. I takes one person finding one bug and exploiting it. and there are enormous resources going into finding one, and I am certain that this is the only one. I am sure the NSA is sitting on a pile of them. Whereas the developers have to…

Because as far as I can tell, there was no "vulnerability" here, it's just how the product works. Stealing an OAuth key is just as bad. Stealing a domain's krbtgt key is just as bad.

Businesses want that when they login to a computer, they are SSO'ed in to all their apps. That's how ADFS works, you authenticate to it using kerberos and it issues you a SAML token. Here they stole apparently the key used to sign the SAML token so they could generate their own.

Unless there was some vulnerability that exposed the key publically, I fail to see how in this particular incident its Microsoft's fault.

Post reply on HN