In a scathing indictment of Microsoft corporate security and transparency, a Biden administration-appointed review board issued a report Tuesday saying “a cascade of errors” by the tech giant let state-backed Chinese cyber operators break into email accounts of senior U.S. officials including Commerce Secretary Gina Raimondo.
The Cyber Safety Review Board, created in 2021 by executive order, describes shoddy cybersecurity practices, a lax corporate culture and a lack of sincerity about the company’s knowledge of the targeted breach, which affected multiple U.S. agencies that deal with China.
It concluded that “Microsoft’s security culture was inadequate and requires an overhaul” given the company’s ubiquity and critical role in the global technology ecosystem. Microsoft products “underpin essential services that support national security, the foundations of our economy, and public health and safety.”
Angry letters always have the biggest impact.
Its like that exercise where you
- Write angry letter
- send it
- they put it in the drawer (garbage) and don’t read it
I thought US Gov had their own email systems. When did they start moving officials’ mailboxes to Microsoft?
Govcloud
During my time contracting in the FedGov, they went “all in” on Microsoft products. From email to Teams to other products, they were becoming a Microsoft shop top to bottom. This was fine for products which were fully mature. For all the jokes about it, Microsoft email is actually pretty good. Azure AD is fine, as long as you have a team of sysadmins to unfuck permissions issues. Permissions will get fucked, as there is a dearth of tools for mapping them. But, that’s been a perennial problem with AD permissions well back to the NT 4.0 days (maybe longer, I was dealing with Novell before that). And there isn’t much better for centralized user management than AD, though third party PAM tools do help here, a lot. Their security tools were (and still are) shit on toast from a usage perspective. Seriously, the only reason people choose MS Defender anything is because “no one ever got fired for choosing IBM Microsoft”.
The main problem is that Microsoft is a “for profit” company. This means that there will always be tension between Security and Profit. So, it’s unsurprising that they have a lax security culture. Security isn’t profitable. The appearance of security is, and I have little doubt Microsoft will be able to roll out all kinds of documentation showing that they were “compliant” with all the required security controls. This means exactly dick, as it’s easy to have insecure systems be “fully compliant” and then do exactly fuck all to actually secure the systems. “Compliant” is a baseline and only proves that you’re not going to get hacked within the first ten minutes of plugging a network cable in. Actually securing the system means a lot of people, processes and efforts finding and fixing holes not covered by the baselines and watching the network for anomalies. That’s really expensive and makes ITs job a pain a lot of times. It also makes no money, as it doesn’t do much to enhance the appearance of security, so it tends to get ignored and eventually cut. The end result is exactly what we have here today, a major hack which didn’t get picked up on for weeks.
China has scared the US into abandoning neoliberalism, rethinking globalization, and becoming more isolationist and protectionist. I think China has also convinced the Federal government that more state involvement in the economy is necessary. Perhaps this will move the US in the direction of a more state directed market economy, much like, well, China. It’s fascinating how much influence our “enemies” can have on us.
Sorry… you think neoliberalism is a good thing?
Who did you vote for in the Republican primary?
I don’t know that I agree with their conclusions, but I don’t see them saying what you’re implying. Including in their post history.
Maybe they don’t know what neoliberalism is then (and possibly not you either):
Neoliberalism is contemporarily used to refer to market-oriented reform policies such as “eliminating price controls, deregulating capital markets, lowering trade barriers” and reducing, especially through privatization and austerity, state influence in the economy.
No, I don’t support neoliberalism. The point of my comment wasn’t to lament the death of neoliberalism, it was to point out how remarkable it is that China got Washington to turn against its own policies. The US has been trying to push the “Washington consensus” on the rest of the world for nearly half a century, only to do a total 180 now that they realize their policies might be a threat to their own national security. I find it very ironic.
Oh no, a scathing report, that is the government’s most powerful tool against businesses. Surely something will come of this.
Lol at US officials using ms mail. Who comes up with those ideas?
I’m not sure other countries are much brighter in that regard though.
Business people who don’t understand computers. They still run everything and still make these bad decisions. It’s still crazy.
As I predicted back in 2023 and here it is on the 2nd Paragraph of the 3rd page.
“In fact, when combined with another flaw in Microsoft’s authentication system, the key permitted Storm-0558 to gain full access to essentially any Exchange Online account anywhere in the world.”
The attackers weren’t just in GovCloud, they had access to ALL of it and Microsoft STILL doesn’t know how the attackers obtained a copy of their Private Crypto Key.
JFC what a bunch of bozos.