Good news! I am sure there aren't any deeper issues around Microsoft's ideology, arrogance, or crass financially-motivated reasoning. Otherwise I might start wondering if maybe Microsoft's security AI might not actually work that well.
Trustworthy Computing initiative was 22 years ago. Hopefully the new start menu ads won't be another attack vector.
What incentive does Microsoft have to change when the customer response to security breaches is to buy more expensive licenses from them? There's not much leverage in criticizing Microsoft, as is hinted in the article: the leverage is in criticizing orgs that continue to give MS more money.
This is nothing new. Microsoft and security was always a problem mariage.
"Beginning mandatory shutdown for software updates. There's nothing you could possibly need your own computer for in the next hour, and all the data you lost when we killed your programs is your fault for not using Microsoft applications instead."
> Privacy: Users should be in control of how their data is used
"Telemetry is very important, for example the hardware IDs of that USB stick you plugged in were also reported to us by another computer an hour earlier, so now we know there's a relationship between you! Isn't metadata grand? But trust us, we have only your privacy in mind. By the way, did you ever finish that novel you were working on from the last crash report?"
> Users should be in control of when and if they receive information to make best use of their time.
"Hey! You still haven't linked your logon to a Microsoft account! Hey! Use Bing! Hey! It looks like you launched a web browser that isn't from Microsoft, switch to Edge instead! Hey! Here are advertisements on your lock-screen just cuz we can!"
Trust is of course earned. Bill's words were lost unfortunately under the next year's priority, the one after that and the one after that.
Today it's AI. Tomorrow it's whatever Satya says that pumps the stock. I've worked with their tech for 30 years and customer requirements, safety and security is somewhere down the priority list. That is the only truth.
Thrown out of the window long since
The unhealthy thing here isn't the marketplace, it's government policy. If you eschew popular open-source tools for closed/proprietary alternatives, this will happen. Linux will always have several orders of magnitude more experts banging on it than Windows ever will. Vendors pontificating about security will not change this fundamental asymmetry. Also, don't want product lock-in? Don't choose vendors with a significant risk or history of lock-in. Don't endorse face-eating leopards and then blame others when they eat your face.
I don’t agree with the outcome, but the logic isn’t hard to follow.
First, we're not talking about the desktop here, we're talking about services. Open source provides much better quality for services. It is frankly appalling to me to see the government relying on Microsoft services given the quality and reliability and security of open source alternatives--not to mention the lower cost.
Second, the biggest obstacle to a standardized Linux desktop that everyone can use and rely on is the lack of a big player in the market willing to invest in one. Imagine if the government took even a fraction of the money it spends on Windows desktops, and spent it on developing a standardized Linux desktop instead. Isn't that exactly the sort of coordination problem that governments are supposed to solve?
you are communicating on it right now
Probably need something similar to a wake up call some industrial companies got with stux in the 2010s or hell their insurance company charging the sh*t out them unless they fix some things.
I mean this very sincerely: The day Microsoft's products are actually secure is the day I'm out of a job.
Can Firefox still write to ~/.profile if there's a buffer overrun somewhere for example? Did I curl | sh some random shit 50 times since December?
What is security even?
> Failure of accountability
Many in the security community see the CSRB report and the recent CISA emergency directive as direct indictments not only of Microsoft’s security culture, but a government that has allowed Microsoft to maintain lucrative government contracts with no fear of competition across many of its services.
“The federal government gets off the hook a little easy in this report,” said Mark Montgomery, senior director at the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies. “Despite significant encouragement from outside experts, the Biden administration, and its predecessors, have failed to treat cloud computing as a national critical infrastructure, that is itself critical to maintaining the security of our national critical infrastructures.”
Sen. Ron Wyden, D-Ore., who called for a federal investigation following the State Department email hack, said the federal government shared responsibility for the negligent behavior disclosed in the report.
Wyden said Microsoft has been rewarded with billions of dollars in federal contracts, while not being held to account for even the most basic security standards.
The US has a billion or ten to spare for this. Billion. With a B. This is an investment that is not just defense, it is an investment in the general economy.
The NSA budget is (maybe) 3.6 billion dollars. A general secure computing base for the American economy is worth at least 3x that.
'Everything authenticated by Microsoft is tainted' ( https://news.ycombinator.com/item?id=37702095 )
... and thought something significant will definitely come out of this. (It didn't, so far I could tell.)
Here in AU it feels most orgs and gov agencies still assume Microsoft is the arbiter and epitome of good security practice, and their products seem to be excluded from serious scrutiny or regular review, as per almost every other vendor. (Google may be another exception, but their attack surface is obviously quite different.)
I'm inclined to believe that Microsoft is doing fairly well amongst Fortune 500 and cloud companies. Not perfect, but fairly well.
Am I offbase?
Edit: I guess I am. Thanks for clarifying and augmenting with more evidence, repliers.
Microsoft got their MSA secret stolen, allowing China to read government emails.
Do you need another example?
https://www.theregister.com/AMP/2023/09/06/microsoft_stolen_...
https://www.dhs.gov/news/2024/04/02/cyber-safety-review-boar...
Sales teams and various vendor lockouts/ins can cause people to bend the knee.
I accidentally pay $70/mo to microsoft because I bought wrong licenses that I needed only to serve a customer. Up until I started this company, I was 0% Microsoft.
Microsoft is said to be a collection of almost independent companies sharing a domain and a CEO. Based on my experience, small as it is, I can believe it.
Like everything else in life, there's always trade-offs here, say, promoting your security practices to attract customers, but the general rule is that moment you start having different tiers of protection, you start venturing into some seriously morally grey areas.
Microsoft didn't just start venturing into morally grey areas, they decided to set up their entire business model there, to the point that they didn't even know that they were hacked because they couldn't generate revenue from that knowledge.
THAT'S why Microsoft deserves every piece of bad press it's getting right now. Not that they had a security incident (everyone will have security incidents), it's that they deliberately ignored accepted industry standards to do so, and to this day they're stonewalling efforts to assess the full impact.