SolarWinds hackers were able to access Microsoft source code
msrc-blog.microsoft.com
msrc-blog.microsoft.com
In my opinion the smooth operation of our infrastructure relies less on its security as it does on the discretion of the hackers that have already compromised it.
tplacek's point isn't that source is worse than disassembler output, it's that governments already have and have had access to source for a while (by design as Microsoft does provide source access to many customers, partners, etc). The tooling to dissemble built versions and craft exploits has also existed for a long while.
If source access enabled a rash of zero days, that point in time would have come long in the past.
Not that alternative means were likely employed for a number of years before that.
This works...until you go against a target that's heard of fuzzing before and has the time and money to do it to their own code.
The really interesting Windows exploits require a combination of "throwing stuff that will flummox the software" and a deep level understanding of structures hidden to the average developer. Look at Yardin Shafir's really wonderful blog post about developing a kernel bug to a PoC - there's a lot of moving parts and security checks in modern windows, and having the source is a HUGE help.
I also found another hint about their findings in this PDF written by Yarden's co-researcher Alex Ionescu: https://www.usenix.org/system/files/woot20_slides_ionescu.pd.... One of the slides specifically mentions the use of fuzzing tools to find these issues.
If there are other, better links I don't know about, please kindly share. :)
Here's a tweet from the original finder: https://twitter.com/gabe_k/status/1330966182543777792?s=20
Yarden & Ionescu's work are both really top notch. Also anything by Google Project Zero if you want to do a deep dive on the subject.
Umm sir, have you somehow missed seeing the quality of Microsoft products in the last few decades.
i suspect we'll be seeing a lot more attention on reproducible and cryptographically secure build environments, similar to the gitian stuff in bitcoin land.
I agree that it is a staggering debacle; I disagree that the weakest link is the only point of interest.
SolarWinds did not vet its build process and outputs; no antivirus, no government entity, no so-called intelligence agency, no mighty software corporation caught the compromise... for more than six months.
The set of characteristics of this compromise is notable and there are many sobering conclusions.
Also mentioned in this other, brief HN discussion.
I don't know how much of this is true. Wouldn't it be helpful for bad actors to understand how Windows defenses work looking at the code thereby increasing the risk?
The principles for developing secure software were identified in the 1970s by Saltzer and Schroeder, and they're still true today. One of those principles is "open design", that is, don't depend on design secrecy for security of the system. Instead, depend on secrecy of things that are trivially changed (like private keys and passwords). Then, when the secret is exposed (or you think it might be), you quickly change all the secrets and there's no problem. One source of this paper: https://www.cs.virginia.edu/~evans/cs551/saltzer/
In the case of Windows, the source code is not really secret anyway. Most governments have continuous access to the source code, typically through the Microsoft Government Support Program (GSP) https://www.microsoft.com/en-us/securityengineering/gsp Many businesses and universities also have access to Windows source code. You can see various programs to provide such access in different cases via https://www.microsoft.com/en-us/sharedsource/ In addition, Microsoft employs a huge number of employees who have access to its source code, and you can't really keep a secret long when a large number of people know the secret. Efforts like bribes, appeals to patriotism, etc. will eventually successfully get someone to reveal a secret if there's a large enough group, especially since it's relatively easy to identify who works for Microsoft or otherwise might have such access.
If that's not enough, Microsoft distributes executables, and disassembers & decompilers can provide enough information for static analysis anyway. So you could re-derive what you need to attack Windows if you needed the source code for some reason.
Anyone who depends on secrecy of code to provide security is in trouble. Typically the real reason to keep (some) code secret is to support certain proprietary business models and to meet certain legal obligations, and are not really about security.
Note that Microsoft understands this; they're quite clear in stating that the security of Windows does not depend on keeping its source code a secret.
(The point is correct, but SSDs are probably a bad example: it is very standardised whether it is in consumer or enterprise space. Maybe nVidia and AMD with regards to graphics card would be a better example?)
Kerckhoffs's principle is usually stated as "A cryptosystem should be secure even if everything about the system, except the key, is public knowledge." Note that Kerckhoffs's principle only refers to cryptosystems. The open design principle is a generalization that applies to all systems, whether or not they are cryptosystems.
Yes. But with not enough eyes carefully reviewing the code security vulnerabilities will remain also in open source code. And once a bad actor finds it it will be easier to implement an exploit.
It's not opening the source that makes the software more secure. It's enough reviewers or white hats looking at the code. Security vulnerabilities in Linux (both kernel and user space) show that regularly.
Of course with closed source your external reviewers are zero, so that's not the solution.
Thank you for that additional point, it's worth being said and helps us model the closed source alternative.
Cool memory, thanks for sharing.
That's a lot of code. Scary.
It's estimated to be around 40 million lines of code
ALL source code for ALL active AND inactive projects? I highly doubt it.
You simply have no idea if the attackers had access to unshared, proprietary code or not. Like Azure server-side components.
I'm personally not a huge fan of Windows, and it definitely has flaws but the amount of considerations taken into account, and the speed with which issues are identified and repaired in a code base of that size, especially while maintaining a disgusting amount of backwards compatibility is crazy impressive.
That aside, having access to the source code does make finding issues easier. It sounds like that knowledge is assumed in their risk assessments which would make that a fair statement.
Do we know if they had access to their issue tracker? That would make it far easier to make zero-day exploits faster.
In any case, it's silly to think otherwise. It's always safer to assume everyone that we wouldn't want to know something already knows that, whatever it is.
While Microsoft does not assume that attackers haven't seen the source code, we cannot say how many people who are capable of spotting security issues have reviewed the code.
That being said, it's worth also saying it's a hard comparison to make overall; it's possible there are important parts of the Linux code base that have in fact had less eyes on them than Microsoft has had on theirs; without numbers it's hard to be certain.
This has been on the front page all day: https://madaidans-insecurities.github.io/guides/linux-harden...
It is safe to assume it is more PRIVATE than a Microsoft OS, but not more secure.
Please don't react emotionally to this... It was a bit jarring of a shift in thought to me as well, at first.
only windows applications that do not run in full trust mode, like store apps won't do that. and even without store apps you can use something like msix or app-v to package your apps in a "small" sandbox, but you can breakout from the sandbox via runFullTrust
With the Windows model, you don't check your guests at the door. You can't search all guests so you assume all guests are hostile and with it you're always taxed with playing security theater which can not only be expensive in terms of hardware resources but mental resources as well as losing more control over your own environment. Because you let unaudited people in your home, before long you have to lock down most parts of it, even from yourself. In gaining control you've lost control because you don't control for openness in the first place. For the few binaries I run on Linux I sandbox them in a VM anyway. But different models, different hosts, each has their weaknesses.
They might sincerely thing so, not knowing they were targeted and now all the binaries they ship are also containing a payload added by the attacker.
With open source software and especially the Linux distro model where one set of people writes the software and another buikds it from source and integrates it is much harder if not impossible to pull off such an attack affecting all users of a piece of software.
Is that why Microsoft, and all you people who poke at its binaries, have fixed all the bugs in MS binaries? /s
The true value in source code at this level are the comments and symbols. Microsoft provides most ofthe symbols, the comments you can’t recover from a binary.
Now that an adversary has MS’s source code, it is indeed easier for them to do vulnerability research. So this is a net loss for MSs overall security posture, not a win.
The "best" market for any such code would be... what... China? Other than the possibility of figuring out potential hacks who could make use of the code in in its sheer mass? By the time you figure out something clever your version of the code is hopelessly out of date.
If you read between the lines they are saying that accounts were compromised, but not through token stealing, which means the attackers got the passwords to the accounts, and likely skirted MFA requirements because they were already inside, or there were none.
While there are many avenues to steal passwords once you have the foothold the attackers did, it would be interesting to know the details as to how these particular accounts were compromised.
Obviously a lot we can only speculate about.
I am not going to make a broad statement saying they don't exist, I'm just saying I haven't found one yet. It's really annoying because I rarely have my phone on me when I'm at home so I have to go track it down. I'd be so happy if they let me use a yubikey :(
What I am saying is that these credentials can be stolen from MITM attacks, log files stored on random servers, or even basic mistakes like literally writing the password where other people can see it.
Knowing what kind of operational mistakes Microsoft made that led to account compromises would help others from becoming victim to similar attacks.
I could be wrong about that, though, and I’d be curious to learn and understand more.
The comment in the article speaks to #1. And of course, we have to take that with a grain of salt. I doubt any company impacted by this would be fully honest if there was a customer breach. Regardless, you also can't prove a negative. So all they can really say is what they did. Which doesn't mean services/data weren't compromised. Given the size of Microsoft, I find it hard to believe that every service running there has the logs/audit trail to know whether they were inappropriately accessed.
But I took the OPs comment to be focused on #2 as well. There is a very real possibility that having access to the source code could help the attackers attack customers. Having access to the source code can help in locating vulnerabilities that allow future attacks against customers/services.
The "risk" mentioned in the quote a few comments up, and in the context of the post by MSRC, isn't about the risk of leaking Microsoft IP. It's about the risk that Microsoft customers might have been affected. Whether or not MSRC found evidence of a breach of customer accounts/data is a related but separate question.
And this doesn't look like something bored 15 year old would pull, So I doubt it was to access their source.
If I had to guess, they were either trying to find something specific, about one of MS's customers (some gov org) or the target was Azure. Lots of corps keep a lot of data there.
Or in charge of protecting them.
https://nam06.safelinks.protection.outlook.com/?url=https%3A...
https://web.archive.org/web/20150107212718/http://winsupersi...
Also I’m guessing that there are a lot of other proprietary vendor-supplied pieces that get built with Windows. What happens if these are not available?
https://tech.slashdot.org/story/20/09/30/1843232/windows-xp-...
> The account did not have permissions to modify any code or engineering systems and our investigation further confirmed no changes were made. These accounts were investigated and remediated.
I would also hope that direct commits don’t go immediately to a production system without some sort of review. At my workplace we have branch protections for all “main” branches that would result in a deployment. At least one other person has to review changes and all of our automated checks have to pass before anything can even get close to running through a deployment pipeline.
However, if it were an admin account that were breached that would definitely make it possible to circumvent any number of protections in place.
EDIT: Sorry, somehow I missed the reply by thatsamonad or I would have replied to it instead of its parent.
[0]: https://freedom-to-tinker.com/2013/10/09/the-linux-backdoor-...
... was able to insert a bug into a mirror of the kernel, which was caught in short order.
That means nothing, of course it was caught, otherwise we'd never had heard about it. We can only speculate about the ones that haven't been caught...
> But some people didn’t like BitKeeper, so a second copy of the source code was kept so that developers could get the code via another code system called CVS. The CVS copy of the code was a direct clone of the primary BitKeeper copy.
Could a hack like this one go undetected for so long in a widely used free/open-source project developed in the open, such as the Linux kernel?
While I have no doubt that something like this could happen to the Linux kernel source code (because security is Capital-H Hard), my perception is that something like this is less likely to happen to the Linux kernel -- and, were it to happen, it would likely be detected sooner, due to the inherent transparency of widely used open-source code.
Giant bureaucracies have a bunch of tasks they need to accomplish. Giant bureaucracies hire poorly trained people to accomplish those tasks and buy software to aid it's those people in accomplishing those tasks. The software is sold "by the feature" so it is colloquially "garbage" that is itself produced as cheaply as necessary to achieve these features. Naturally, such garbage is constantly updated and all these giant bureaucracies are sieves with these updates running through them. Sure, if these bureaucracies hired competent people, downloaded open source tools, tested the tools themselves and essentially had their own quality control in-house, this might not have happened. But that wouldn't be the out-sourcing-based, cut costs and skills to the bone, neoliberal paradigm that's near and dear to the high level managers' heart, now would it?
Now, you would think that an event like this would create a realization "what we do is too important for outsourcing, for bargain-basement, neoliberal style operations". But the Office of Personnel Management hack [1] was what should have created this realization and didn't.
[1] https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
But yeah, to your point - being able to read and analyze the Linux kernel source is considered a feature, not a liability :)
On the one hand, open source projects make for an environment where bad actors could propose changes to the software that include these bug/backdoors. The benefit to the open source arena is that these changes can easily be analyzed and tested.
In Microsoft's case, the source being visible but not editable is still a real risk (assuming the bad actor is able to extract the data they're viewing for further analysis), because they can use the source to determine avenues for attack.
The fact that is was read-only does help ensure that no new attack vectors were created, but it still increases the chance of new attack vectors being found/used in the future.
Most common issue was access tokens found in public places.
Would be interesting to know what happens when code is updated - which I obviously wouldn't do. Wonder how long it would take until caught.
Since open source projects probably dont do "red teaming" (to use a fancy buzz word) I wonder how they could practice this?
If I were a nation state I wouldn’t try to poison mainline kernel - there would be far easier sources along the stack for both local and remote attacks which would more easily go unnoticed. Tools that come to mind are systemd, openssh, http/ftp services, GNU tools and common non-gnu shell utilities. Failing that, distribution level kernels would be my next bet purely because any commits would be less scrutinised.
For that reason I’ve moved away from those managers and stuff like react (I trust facebook but dependency trees are huge) - the worst part is you can’t not patch, but you might be doomed by any upgrade.
I think eventually it’ll snuff out innovation in medium sized businesses and government - large businesses can afford the cost of manual review and startups will ignore the risk, but middle-tier will be screwed.
I’d love to see a crowdsourced review model, but I just don’t think it can be viable without getting abused.
WP says that SolarWinds "had about 300,000 customers as of December 2020, including nearly all Fortune 500 companies and numerous federal agencies."
Everyone who thought that was a good idea, for whatever reasons - given the history of security - obviously screwed up badly. When -so many people- go -so wrong-, the problem is clearly bigger than the loss of 'too many secrets'.
What I've not seen anyone discuss is the potential for an attacker to take the source-code of a single Windows core component (a system DLL for example), add in a backdoor, build it and then distribute the binary via a compromise such as the SolarWinds update mechanism.
In other words, insert a modified core Windows DLL into some other popular Windows driver or application package updater published and signed via a 'trusted' channel other than Microsoft itself.
IDK what their revenue looks like, but I'm guessing that selling the OS isn't as front and center as it used to be (from the way they are changing in terms of supporting things like linux).
Even if they keep a pretty tight license around the source, releasing it to the public would earn a lot of good will while potentially finding and fixing security problems.
I don't think Windows will be open-sourced precisely because it's not as important as it used to be. It'd be a ton of work to root out vendor code incompatible with OSS licensing, remove internal dependencies etc. That's not worth it unless we have big plans for Windows to stay relevant, which I have no knowledge of but suspect that we don't.
Probably we'll see the most relevant pieces be opened up, like the driver model awhile back.
Disclaimer: work at Microsoft but in Azure
The horrible new version that is ridiculously huge, phones home, and somehow is slow enough to need a loading screen?
I really wish they would've just opened the good one, but you can already find that one in the leaked 2k source...
Which it probably does.
Apparently its also an obstacle for many other closed source programs when it comes to considering a transition to open source
Russinovich said never say never though, so I don’t know. https://www.wired.com/2015/04/microsoft-open-source-windows-...
It just means you can read the source.
What I am thinking as well. Unimaginable if it was 10 years ago, but modern Microsoft seems to be taking a different approach. And Apple desperately need some competition to keep Tim Cook honest.
Are they OK? Ze googles, they do nothing
People trash Microsoft a lot but some of the people there are the best in their respective fields.
You may have a rubbish internet connection. If you are using a VPN with a slow internet connection, investigate a split tunnel. Teams traffic involves only three IP ranges so it is easy to split out and route direct to shave a fair bit of latency.
Other issues will require more investigation but they are local to you.
The three heroes of ethics, ideal working conditions and examples of behaviour towards the society in general.
The only reason most startups use open source ecosystems is economics.
The nice thing about Java is the deployment and management tooling. It's cross-platform and mature. C# is not nearly as good in this respect, although with the open-source it is finally free to move with that.
C#/.NET hasn't been tied to windows for a number of years now. .NET Core/.NET 5 is cross-platform and great to work with. All of our CI/CD runs on Linux agents too.
C# is not tied to Windows, some new features in the latest C# 9.0 doesn't even support running on the Windows-only classic .NET Framework.
All new .NET development + C# features is being invested into .NET 5+ (FKA .NET Core), i.e. the high-performance cross-platform runtime.
> The nice thing about Java is the deployment and management tooling. It's cross-platform and mature. C# is not nearly as good in this respect, although with the open-source it is finally free to move with that.
Citation needed, I deploy my .NET 5 Apps with Linux tools, either rsync, Docker as well as AWS ECS. All clean + simple, only requires a single command to publish your App ready for distribution, that you can either rsync across or include it in the runtime image of your Docker build.
Tried to publish a Java package last week and the whole experience was a shit show, by far the worst experience of all languages where the recommendation to publish a package is to push it to bintray first, make it available to jCenter than sync it to Maven, where you need to get manual approval to include it in jCenter then you need to create yet another account/credentials with a 3rd Party which requires a manual request via a damn Jira ticket. Then each package manager has different requirements as to what a package needs, I could publish it to bintray but couldn't get it to jCenter without uploading a POM which new Kotlin projects aren't created with, then MavenCentral requires a stricter POM and Java Docs but there's no standard way to publish to a repository as bintray needs their own non-compatible task, so now I have duplicated generated POM's in my gradle build to satisfy different repositories, for bintray I needed to hook into their bintrayUpload task and generate the POM just just before it uploaded the package which I needed to decompile its sources to find out where exactly the POM file needs to be written to, no examples of which existed for Kotlin build.gradle.kts scripts that new Kotlin projects are created with. Then there's the case that every build.gradle example uses configuration that is already deprecated and Java/gradle seems to be the only one requiring uploading binary .jar's with your source projects.
Every other language has a single repository you can publish to that you don't need to jump hoops to get, published using standard tools, simple, clean, straight-forward & well documented.
Something C# never was, given that it always JITs before execution and AOT compilation to dynamic libraries has been available since version 1.0 via NGEN.
Plus lots of additional AOT alternatives like Windows 8.x Bartok compiler, .NET Native and CoreRT.
This on top of third party offerings like Mono AOT or IL2CPP, and the research compilers from Singularity and Midori projects.
Whereas for Java, while AOT has been available since around 2000, it has been for the most part only available on commercial JDKs, and free beer AOT only came with the release of GraalVM community, the addition of J/Rockit JIT caches into OpenJDK, and IBM releasing OpenJ9 as FOSS as well.
Abstracted far enough, everything is basically the same thing.
How so, I had nothing but issues when trying to deploy cross-platform Java because of the Java ecosystem itself being bad compared to C# or Golang where you just compile stuff and run it.
There's still a lot of cruft from who they used to be, but I feel like most people I know echo the sentiment that Satya has been a revolution. Things like them embracing Linux, acquiring and not ruining NPM and Github, contributing to open source projects, and all the work they've done with Dotnet Core seem to really have bought them a lot of goodwill, at least with the people I know.
Windows is a great example - forced updates, forced ads, forced data-ming and spying, stupid UI changes etc. all make an otherwise decent OS a real pain to use and a must-avoid for the privacy conscious. These are easy to fix for a company like MS, but they do not.
I don't understand whinning about that when you have bilions of people using your OS, so shitton of people who are newbies at computers then you want to help them to stay as secure as possible.
"at best(worst?)" this thing is "not nicest", but it's totally reasonable.
you have reasonable control over updates on non-home versions, imo.
I don't mind Chrome's forced auto-updates, because they've never gotten in my way.
Furthermore such updates which usually require a reboot can easily interrupt important work or a long running task.
Just yesterday my Windows install which exists solely to run steam and steam games updated and then committed suicide in a fashion that can't be automatically repaired and requires a reinstall with zero explanation. For reference the hardware is fine as is the Linux install on another drive. The windows drive is a ssd less than 6 months old. I can even mount the ntfs filesystem which appears to be just fine.
There is absolutely no excuse for not letting users pick when or if they would like to update their OS especially when their QA has completely gone to shit and they cannot realistically promise that their update wont break your install.
Forced updates are unnecessary and a bad idea, even more so in rolling-release models.
That doesn't explain forced feature updates.
It really wasn't that long ago that most commercial software still had to support IE8 (released 2009), for example, because that's where the user base was and they didn't upgrade.
Have you seen the WSL2 DirectX support?[0] They're extending it, too!
Microsoft gets mocked for embrace/extend/extinguish, but really, it means just do a better job than the competition. Embrace: "do what others are doing", extend: "do a better job at it, have more features than the competition", extinguish: "sell customers on those features and improvements". How anyone could be against competition, simply because it's framed in a cheesy phrase, is beyond me.
Microsoft is a big company. Some things it does will always be trashy - like fighting tooth and nails to keep Linux desktops and truly-open formats out of European public-service procurement. That's still going on, 20 years and 2 CEOs later, and will probably never stop, because screw public interest when there is so much money on the line!
But sure, in some areas they behave better now. They had no choice, after losing a whole generation of developers and seeing their cash-cows (Windows, Office, and AD/Exchange) under siege from SaaS insurgents. I've still to see something where their efforts are not fundamentally tied to their immediate self-interest, though.
Microsoft has done some good things with .NET Core, but they still don't have a very friendly OSS or partner strategy.
AppGet is a pretty good example; there was an existing Open source solution that filled a need, and Microsoft decided to create their own replacement, not bothering to give any credit (until there was an internet ruckus) to the original despite the very striking similarities and relative level of obviousness that they were at bare minimum 'inspired' by the tool; after all, they interviewed him for a role and even warned him the day before it came out... [0]
Octopus is another example. I -hate- TFS Release pipelines. Octopus Deploy was (until they ruined their pricing model) a far superior product overall. You can really tell the way TFS Release pipelines were done, they tried to 'checkbox-copy' Octopus Deploy's features without making it too much like Octopus to be obvious.
But the checkbox-copy strategy is inferior in many ways. In Octo you can have a stage that runs in all environments (but certain steps on/off per env) and configure server groups that way. In TFS Release, You have to have to 'copy' the steps for every stage. It's like their data model is missing a 1-many relationship or two somewhere.
And the impacts in the case of their behavior has a second-order effect; I am curious whether TFS Release eating into Octopus's market share was a factor in their price hikes a couple years ago; in that regard, I can't blame them if that's the case.
[0] - https://medium.com/@keivan/the-day-appget-died-e9a5c96c8b22
If your work is such that scaling to bazillions of servers or other artifacts isn’t an issue, Microsoft is a smart choice. If you are building Facebook, it is a dumb choice.
The state of SQL Server's MVCC suppot is arguably enough to preclude use even before we talk about licensing.
I never thought I would miss Oracle until I learned about NOLOCK and the cost of enabling MVCC in SQL Server.
a little early to come to this conclusion, one way or another, I think
I don't think this is some fundamental shift in Microsoft or its values: simply a shift in their market positioning and brand value/identity.
Their products are still proprietary spyware, designed to get as many people locked into the Windows (or now Azure) licensing ecosystem as possible. Even the best parts of VS Code, often cited as one of their best new releases, are either spyware or proprietary. Windows remains a tire fire.
GitHub and NPM are prime examples of this concept that one can turn money into goodwill. I assume money also changed hands for the first-class support that Docker has for windows.
And no, to me Microsoft is actually worse than before as they have turned Windows into a spyware. The forced updates (not just security updates) make it even worse.
https://insights.stackoverflow.com/survey/2020#technology-mo...
Maybe they are all wrong. Maybe PHP still sucks just less.
It's more around the ads in the start menu, the telemetry they send, and their tendency to reset my telemetry settings around updates.
I don't feel like I'm in full control when I'm using a computer running windows. Which, y'know, is probably fine for 95% of computer users, they want more of an appliance than a general computing experience.
Yes, they've started imitating macOs / ios and have even gone beyond what Apple does in blatantly turning Windows OS into a spyware.
Prove that.
https://msrc-blog.microsoft.com/2020/12/31/microsoft-interna...
Drives me crazy that Reuters could write an entire post about a Microsoft blog post, yet not link to the post itself.
You'll note that they buried the byline in this piece at the bottom, crediting "Reuters staff" at the top.
You're saying Reuters shouldn't report severe security breaches at Microsoft? Or that they are doing it because someone there dislikes Microsoft? For the latter - does the motivation really matter?
Their motivation of generating click-bait at Microsoft's expense matters as it means you should seek clarifying information from other sources. Or just ignore Reuters and hope the drop in traffic drives them to more closely tell the whole story.
Simplified, sure, but not overly so.
(Linking or not linking to corporate blog posts - I agree they should do that, but I suspect it's a general article style guide thing.)
What we believe organizations should do and what they actually do in is often misaligned based on problematic underlying driving forces/goals.
Profit motives have tended to overcome all other incentives in our (the US) economic structure. It may be a broader problem globally due to power and influence of the US.
The same can be said about consumer motives. I probably should shop locally more often, but I may not be able to afford local rates and have to pass the costs down the line if I want to continue supply more basic underlying goals (eating, staying sheltered, etc).
At some point we have to have the difficult conversations of choosing the tradeoffs we do and don't want to support, otherwise we may let flawed underlying goal structures guide us to the paths of least resistance, which may ultimately not be good for humanity (or it may be, who knows).
Given a lot of current directions, I find it hard to believe our underlying system structures are great for human well being. It may have been a good run for awhile but that may be a short temporal anomaly. We may have to more throughly consider long term consequences of goals we set that may run counter to their actual intent.
It's easy for some to simply ignore the underlying problems and play the game optimally for oneself. Personally, I've never been happy with that option (the option which OP sort of alludes to).
I'd not be surprise if someone in Reuters is profitting from hyping the breach.
The article is in contradiction with the headline, isn't it?
>We detected unusual activity with a small number of internal accounts and upon review, we discovered one account had been used to view source code in a number of source code repositories. The account did not have permissions to modify any code or engineering systems and our investigation further confirmed no changes were made. These accounts were investigated and remediated.
>At Microsoft, we have an inner source approach – the use of open source software development best practices and an open source-like culture – to making source code viewable within Microsoft. This means we do not rely on the secrecy of source code for the security of products, and our threat models assume that attackers have knowledge of source code. So viewing source code isn’t tied to elevation of risk.
https://msrc-blog.microsoft.com/2020/12/31/microsoft-interna...
MS has an "open source" culture? I laughed and remain skeptical ...
Yeah, I recognize MBA speak when I see it. That's why I chuckled. They were hacked and somebody saw their code. Now some guy in upper management has to spew some bullshit to protect the company's "image".
I don't know if to pat Microsoft on the back or give the ma scolding.
If you are up against a military intelligence hell bent on discovering attack vectors produced by the private commercial industry then this is a losing battle-whoever has infinite resources win.
In this case the governments of the world can print unlimited money and has to access to the top of the creme, we are talking 0.0001% of the population working on discovering the next zero day vulnerability.
How does a for profit corporation go up against an adversary with infinite resources?
The largest corporations are wealthier than some nations. Governments do not have unlimited resources. When national security depends on corporate security, governments can subsidize it with some other parts of their own "infinite resources".
Not saying I disagree with your point overall, but this rhetoric rubs me the wrong way.
Who owns the money printers? Is it microsoft or is it the governments recognized by the USGOV?
Who has control over the monetary supply? Is it microsoft or is it the governments who control respective central bank?
Who has control over deciding whether microsoft is a monopoly or not? Again, its not the corporation.
Sure you can have corporations richer than most developing nations but that has no relevance on the policy/power balance between government and a corporation.
Even if all of the corporations in America formed a coalition, it is the government which has monpoly over violence that can decide out of whim if you are suddenly against them or with them.
Why would basic facts rub you the wrong way? Do you believe that corporations can control the military, police and paramilitary forces in the Western world?