back
96 comments
> Microsoft has placed a major bet that customers will embrace its effort to incorporate AI into its security product platforms. Microsoft said, after months of testing with customers, that Security Copilot helped security analysts be 22% faster and 7% more accurate.

Good news! I am sure there aren't any deeper issues around Microsoft's ideology, arrogance, or crass financially-motivated reasoning. Otherwise I might start wondering if maybe Microsoft's security AI might not actually work that well.

https://en.wikipedia.org/wiki/Trustworthy_computing

Trustworthy Computing initiative was 22 years ago. Hopefully the new start menu ads won't be another attack vector.

Based on their existing screw ups, the ads process probably runs as SYSTEM and have more rights to your system than you do.
They should run that security AI on their own systems, maybe then it would find all the holes the hackers are using to root their systems.
> Attacks like these will spur proactive security measures at many companies, for example increasing employee training, upgrading email security to an E5 level, adopting the use of audit logs and increasing the use of encryption during file transfers, Stella said. E5 is considered the premium tier for Microsoft 365 customers, offering enhanced security and other services, he said.

What incentive does Microsoft have to change when the customer response to security breaches is to buy more expensive licenses from them? There's not much leverage in criticizing Microsoft, as is hinted in the article: the leverage is in criticizing orgs that continue to give MS more money.

Yes, we will hit you in the skull with a large stick repeatedly, but if you subscribe to our Helmet Deluxe Plan it will hurt much less!
This is basically their stategy. And, with the outsourcing of IT to the cloud and to external companies, their success is assured.
Implicating some of their cheaper products don't offer enough security. I don't understand what goes through the head of people working at Microsoft today but the results are quite lacking.
> I don't understand what goes through the head of people working at Microsoft today but the results are quite lacking

This is nothing new. Microsoft and security was always a problem mariage.

Because they're still drunk on OpenAI integrations being the next unicorn, and have completely forgotten the trustworthy computing email Bill sent them 20 years ago.
> Availability: Our products should always be available when our customers need them.

"Beginning mandatory shutdown for software updates. There's nothing you could possibly need your own computer for in the next hour, and all the data you lost when we killed your programs is your fault for not using Microsoft applications instead."

> Privacy: Users should be in control of how their data is used

"Telemetry is very important, for example the hardware IDs of that USB stick you plugged in were also reported to us by another computer an hour earlier, so now we know there's a relationship between you! Isn't metadata grand? But trust us, we have only your privacy in mind. By the way, did you ever finish that novel you were working on from the last crash report?"

> Users should be in control of when and if they receive information to make best use of their time.

"Hey! You still haven't linked your logon to a Microsoft account! Hey! Use Bing! Hey! It looks like you launched a web browser that isn't from Microsoft, switch to Edge instead! Hey! Here are advertisements on your lock-screen just cuz we can!"

Is that the one that bought us various fad service oriented technologies, even more broken DCOM and Code Access Security in the .Net Framework, topped with a peppering of Vista, UAC and shovelling the lumpy turds that remained into virtualization (LSASS etc) yet still somehow managing to run their entire AV software as SYSTEM resulting in a zero touch complete system remote compromise?

Trust is of course earned. Bill's words were lost unfortunately under the next year's priority, the one after that and the one after that.

Today it's AI. Tomorrow it's whatever Satya says that pumps the stock. I've worked with their tech for 30 years and customer requirements, safety and security is somewhere down the priority list. That is the only truth.

> Privacy: Users should be in control of how their data is used. Policies for information use should be clear to the user. Users should be in control of when and if they receive information to make best use of their time. It should be easy for users to specify appropriate use of their information including controlling the use of email they send.

Thrown out of the window long since

One thing they are good at is consistency... https://techrights.org/n/2024/01/30/Microsoft_is_Making_Even...
> Regrettably, the marketplace is far from healthy

The unhealthy thing here isn't the marketplace, it's government policy. If you eschew popular open-source tools for closed/proprietary alternatives, this will happen. Linux will always have several orders of magnitude more experts banging on it than Windows ever will. Vendors pontificating about security will not change this fundamental asymmetry. Also, don't want product lock-in? Don't choose vendors with a significant risk or history of lock-in. Don't endorse face-eating leopards and then blame others when they eat your face.

Save taxpayer money today by outsourcing to a vendor that might have a problem, but really isn’t your “fault” per se. OR spend a lot of taxpayer money running your own system; which if there is a problem is very much your “fault”.

I don’t agree with the outcome, but the logic isn’t hard to follow.

How is outsourcing a cost saving? You have to pay for the shit, you make it sound like its somehow free. Logic does not checkout.
It's not really about open source versus priority, it's about open source quality, which quite frankly isn't there. It's like living in a rickety shed at the best of times on the desktop.
> it's about open source quality, which quite frankly isn't there. It's like living in a rickety shed at the best of times on the desktop

First, we're not talking about the desktop here, we're talking about services. Open source provides much better quality for services. It is frankly appalling to me to see the government relying on Microsoft services given the quality and reliability and security of open source alternatives--not to mention the lower cost.

Second, the biggest obstacle to a standardized Linux desktop that everyone can use and rely on is the lack of a big player in the market willing to invest in one. Imagine if the government took even a fraction of the money it spends on Windows desktops, and spent it on developing a standardized Linux desktop instead. Isn't that exactly the sort of coordination problem that governments are supposed to solve?

> open source quality

you are communicating on it right now

My impression was that they did a hard switch to proper Secure OS engineers for Windows about 10 years back.. I kind of wonder if that pushed engineers and managers with the worst habits out to periphery things from the OS perspective..
The article has nothing to do with Windows; it talks about security issues and breaches in their services, mainly Exchange.
Right, something that runs on windows is the periphery from an OS engineers perspective. "You don't have to leave the company, but you can't stay here."
Recommendations in article are sound, zero trust infrastructure is a nice to have.

Probably need something similar to a wake up call some industrial companies got with stux in the 2010s or hell their insurance company charging the sh*t out them unless they fix some things.

Years? Try decades. When has Microsoft not been a source of endless security problems?
Windows is quite secure these days. Arguably more secure than Linux.
Who argues that?
Microsoft is much more than Windows though. Active Directory is still a terribly insecure mess that forms the backbones of most major companies. Beyond that, all of Windows still runs on unsalted NTLM hashes. NetNTLM and NetNTLMv2 are more secure salted hash types, but both use the original unsalted NTLM hash to form the NetNTLM/v2 hashes. That allows attackers to simply pass-the-hash to authenticate as domain/local Windows accounts without ever having to know the password.

I mean this very sincerely: The day Microsoft's products are actually secure is the day I'm out of a job.

At first I thought this was an astonishing point to make. And then I asked myself if it is or isn't.

Can Firefox still write to ~/.profile if there's a buffer overrun somewhere for example? Did I curl | sh some random shit 50 times since December?

What is security even?

Having more healthy competition in the form of Linux would have been net positive for the society:

> Failure of accountability

Many in the security community see the CSRB report and the recent CISA emergency directive as direct indictments not only of Microsoft’s security culture, but a government that has allowed Microsoft to maintain lucrative government contracts with no fear of competition across many of its services.

“The federal government gets off the hook a little easy in this report,” said Mark Montgomery, senior director at the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies. “Despite significant encouragement from outside experts, the Biden administration, and its predecessors, have failed to treat cloud computing as a national critical infrastructure, that is itself critical to maintaining the security of our national critical infrastructures.”

Sen. Ron Wyden, D-Ore., who called for a federal investigation following the State Department email hack, said the federal government shared responsibility for the negligent behavior disclosed in the report.

Wyden said Microsoft has been rewarded with billions of dollars in federal contracts, while not being held to account for even the most basic security standards.

I pound this a lot here, but open source investment is a security and military matter to the state. Relying on unfunded overworked and frankly exploited programmers for major aspects of security infrastructure is madness.

The US has a billion or ten to spare for this. Billion. With a B. This is an investment that is not just defense, it is an investment in the general economy.

The NSA budget is (maybe) 3.6 billion dollars. A general secure computing base for the American economy is worth at least 3x that.

I recall the brief storm that came up ~ 7 months ago with:

'Everything authenticated by Microsoft is tainted' ( https://news.ycombinator.com/item?id=37702095 )

... and thought something significant will definitely come out of this. (It didn't, so far I could tell.)

Here in AU it feels most orgs and gov agencies still assume Microsoft is the arbiter and epitome of good security practice, and their products seem to be excluded from serious scrutiny or regular review, as per almost every other vendor. (Google may be another exception, but their attack surface is obviously quite different.)

It's crazy how slack big tech is. For companies who have such a grueling application process you'd think they'd have more to show for it. disappointing.
Seems like they are trying hard to be the Boeing of tech.
Everyone has slowly been trying to be the boeing of everything for 50 years now and we're starting to feel it.
IMHO, this article isn't very substantive and reads like FUD for clicks.

I'm inclined to believe that Microsoft is doing fairly well amongst Fortune 500 and cloud companies. Not perfect, but fairly well.

Am I offbase?

Edit: I guess I am. Thanks for clarifying and augmenting with more evidence, repliers.

I think yes, you’re off base.

Microsoft got their MSA secret stolen, allowing China to read government emails.

Do you need another example?

https://www.theregister.com/AMP/2023/09/06/microsoft_stolen_...

Also Microsoft still does not know how that secret was stolen and has knowingly mislead customers and the media about that fact.

https://www.dhs.gov/news/2024/04/02/cyber-safety-review-boar...

Yes, you are offbase. This is a fairly well written article that highlights and summarizes a few of their most recent gaffs. We recently re-evaluated our EDR solution and Microsoft was in the final 3. We didn't move them past the RFI process because of these recent incidents, on top of a very poorly packaged product (Defender). Microsoft has been really pushing the notion they're a security company (and my 401k would love it if that were true), but the sad reality is they continue to fall short in every possible way. I'll likely share this article with my peers when challenged on why we didn't move forward with them in our EDR project.
I am unsure if ancient tech companies doing well is an indicator of quality.

Sales teams and various vendor lockouts/ins can cause people to bend the knee.

I accidentally pay $70/mo to microsoft because I bought wrong licenses that I needed only to serve a customer. Up until I started this company, I was 0% Microsoft.

You're right and wrong. I know about a team that does well and one that I think is begging for a major CVE.

Microsoft is said to be a collection of almost independent companies sharing a domain and a CEO. Based on my experience, small as it is, I can believe it.

There is a very strong professional code of conduct within security circles that you should monetize the security of your own product as little as possible, because your own security is not a revenue stream, it's your most basic obligation to your customer.

Like everything else in life, there's always trade-offs here, say, promoting your security practices to attract customers, but the general rule is that moment you start having different tiers of protection, you start venturing into some seriously morally grey areas.

Microsoft didn't just start venturing into morally grey areas, they decided to set up their entire business model there, to the point that they didn't even know that they were hacked because they couldn't generate revenue from that knowledge.

THAT'S why Microsoft deserves every piece of bad press it's getting right now. Not that they had a security incident (everyone will have security incidents), it's that they deliberately ignored accepted industry standards to do so, and to this day they're stonewalling efforts to assess the full impact.

Agreed. Almost all of the quotes are from Microsoft competitors shilling their wares.