For sure they have a lot of insight to share but it would be nice to see them address before touting their laurels. (Yes they've gotten a lot better, but in my opinion still nowhere near as bulletproof as it should be).
> It's fair to say Microsoft doesn't have a great track record over the last several decades with security of their flagship OS.
Nope, not fair or accurate at all. Their track record has been great, and it's likely you are judging them for transparency mixed with a reputation from >20 years ago. They have a good record of patching security holes; if we all assumed that more patches = worse security, it would only incentivize companies to be quiet.
As for development, again over the past decade, they've been completely different from the past, and are fully embracing and pushing best practices. As other commenters like to point out, this is not your grandpa's microsoft.
> but in my opinion still nowhere near as bulletproof as it should be).
Assuming that security should be bulletproof is a misunderstanding of how security works.
https://www.wiz.io/blog/bingbang
https://www.theverge.com/2023/7/12/23792371/security-breach-...
https://www.wiz.io/blog/midnight-blizzard-microsoft-breach-a...
I would agree, the Windows OS has really matured since XP, from a security perspective at least.
I would definitely expect better than this from a tech giant like MS. When was the last time Google, Meta, or Apple got breached like this?
Edited to add, I think them open sourcing some security training is good, it benefits everyone whether or not MS themselves are a great example of a secure company.
Or if your processes are good at all, and it's not just luck, or being less of a target, that means the holes haven't been exploited yet.
People who claim this kind of failure is useful are clueless. Failures are interesting in exploratory processes and useful when occurring within a predicted failure regime (i.e testing to failure). Unexpected failures in predicted success regimes just indicate process weaknesses. Repeated and continuous failures in similar fashions do not indicate strength, they indicate structural process deficiencies despite what cybersecurity bozos would like you to believe.
Once involving signing keys so critical that (from rough memory) they had to restore them silently after initially deleting them?
Look at the number of vulnerabilities introduced by Windows version. It's good that they're fixing them frequently, but the fact that they need to do so in the first place (and there's more and more of them with each new version) is itself a problem.
For that matter, can you link to anybody technically competent at Microsoft who would dare to make a claim like that and then actually back it up with experimental evidence? No point listening to the blather of the Microsoft PR team when the silence of the technical team tells you all you need to know.
"Good judgement is the result of experience. Experience is the result of bad judgement"
[1] https://news.microsoft.com/2000/12/07/gates-offers-new-techn...