On Microsoft, the U.S. Government Must Embrace the Stick
lawfaremedia.org
lawfaremedia.org
> But what are the incentives guiding Microsoft toward, in the words of public relations weasels the world over, “taking your security very seriously”?
Seven years before that, in 2002, Bill Gates, then CEO, sent an immediately famous email to all of Microsoft:
https://www.wired.com/2002/01/bill-gates-trustworthy-computi...
Over the last year it has become clear that ensuring .NET is a platform for Trustworthy Computing is more important than any other part of our work. If we don't do this, people simply won't be willing -- or able -- to take advantage of all the other great work we do. Trustworthy Computing is the highest priority for all the work we are doing. We must lead the industry to a whole new level of Trustworthiness in computing.
It gets stronger and better from there. I don't love Microsoft, but the OP's history is wrong.
Then they stopped talking about it by 7 and by 8 it was all about the touch UI and "convergence." Some kind of rot kept spreading and now we have an extremely flaky Windows 11[0][1][2][3] and Russians infiltrating Microsoft for 5+ months (and may still even be in the system today![4]) using goddamn password-spraying.
One CEO memo from 22 years ago doesn't make a strong case against the OP's argument, in fact a reading of later history enhances it.
In comparison, Google has never gotten hacked on the scale they did with China, or Microsoft recently with Russia, since implementing zero-trust company-wide. If you know of any such incident since 2009, I'd be keen to learn them.
0. https://www.windowslatest.com/2024/03/16/windows-11-kb503585...
1. https://www.theregister.com/2024/01/12/microsoft_update_for_...
2. https://www.windowslatest.com/2024/02/19/windows-february-20...
3. https://www.theverge.com/2023/8/24/23844054/microsoft-window...
4. https://www.foxbusiness.com/technology/microsoft-warns-russi...
I'm making a guess here that the real issue is that customers don't understand security and won't pay for it. They do understand that security is inconvenient and punish MS for implementing inconvenient features. That would explain the behaviour seen around the release of Vista - a company learning that security might be important to their CEO and dev team, but they will get financially punished for prioritising it so the bean counters step in and overrule that funny business on behalf of the customers.
I'd go further and say that the correct thing to do here is to train government purchasing officers on security and punish them for buying insecure software. This "Microsoft has the market buttoned up due to a few key strengths" business in the article shows that too. If the government really understood its own needs, it could organise for someone else to build software that meets them. From their perspective Libreoffice and MS Office might be incomparable, but there is no argument that technically they are very similar. Business needs could be met too if someone put some budget into it for a few years and it isn't that hard. The issue here is entirely that government contracts won't move around based on real security concerns.
And just four years before that, Bill was being recalcitrant in front of the US government, with utterances like:
'I don’t know what you mean “concerned.”'
It's possible that the whole organisation had a resilient change of attitude in 2002, but as sibling comment by Andrex observes, there's no evidence to suggest this.
For example - https://news.ycombinator.com/item?id=37702095 'Everything authenticated by Microsoft is tainted' from 2023-09
I don't see what that has to do with security. Microsoft could be both monopolistic and security-focused.
Nor, obviously, should we assume that email represented a sincere, persistent, commitment to fundamental change of the way the company operates -- conversely, that there were no cynical elements of propaganda / marketing to that action.
Trustworthy computing has not been the guiding principle for Microsoft for years.
Yes, Kaspersky. Outsourcing your security to Russia.
Windows is loaded with defenses and security. You may debate it's affectiveness, efficiency, etc., but factually it's there.
Anyone want to educate me on this? Anything I want to do in a spreadsheet, I can do in Gnumeric, Libre Office, or even Numbers; anything more complicated I'd rather do in a proper programming language. What makes Excel really so indispensable?
First you need to understand that this is a minority position. Despite the last decade or so of "software eating the world", most line-of-business type people are not programmers, and couldn't write a python script if their life depended on it. I don't say this to criticize; I couldn't put together a corporate financial statement if my life depended on it either. Not everyone has the professional time (or desire) to learn to program.
But if you have this tool, Excel, that is critical to your job in many non-programming-y ways, but can manipulate data in ways that programmers would usually use code to accomplish, well... that's great, you use it, and are able to do your job better and more efficiently. And it flows naturally from the skills that you already have.
Google Sheets is also just missing some more advanced data analysis and charting features. Casual users might never notice but power users consider it unacceptable.
Nothing that compares to the math functions charting and table manipulations, extensibility via COM and .NET, PowerQuery, Lambda,...
This is HN so everyone will focus on the functions/features. While that is important its not the reason for not switching. The friction is much deeper.
At one point the business world went all in on MS Excel. Its not just that they use it, the entire management organization and feedback loops are based on Excel not the other way around. Moving away from excel is not a function choice anymore. Its a Executive leadership company structure decision. I'm guessing not many fortune 500 CEOS post on HN to confirm this.
No one can "beat" excel because to do so requires simply copying it pixel by pixel and function by function. If you did that MS would sue you out of existence.
More importantly, can you teach an analyst of some sort, who while being a power user is not a programmer to do it just as efficiently?
Doing math on a 2D grid of cells is the technology that Excel perfected in the 80s, the power of Excel is in the connectors, services, and interoperability that surround it. It's no small feat to have an application that can guide a beginner through grabbing 10k rows out of an Oracle database and putting it on a graph, while also having the power to allow experienced users the ability join arbitrary sources and construct models around the results then present it in a logical fashion.
I am very much not a fan of the current state of affairs, but unfortunately nothing does Office like Microsoft Office.
That's the thing that I was wondering about here. I don't really know this space very well, and still have bad feelings toward Microsoft for their behavior in the 80s and 90s, but is MS actually abusing their monopoly position here? I guess the article hinted at a few things; e.g. if you are an Office365 customer you have to be an Azure customer, and can't run it on AWS or GCP. But I didn't see a compelling case for how MS is using its Excel (or Office as a whole) dominance to actually harm consumers or competitors. Excel's features aren't magic and AFAIK don't require backroom deals to enable. Anyone can implement them, given a lot of time and hard work.
I think the main compelling part was that MS doesn't have an incentive to focus on security as much as they should, because people will keep using Office365 regardless, as there are no viable alternatives. But that doesn't seem like an anti-trust issue to me. That's fixable through legally-mandated fines for security incidents, fines that actually hurt MS significantly, not just token fines that are shrugged off as the cost of doing business. Make it significantly cheaper for MS to develop a better security posture, and they probably will do just that.
It's not illegal to have a monopoly, but one thing that's illegal (theoretically anyway) us using your monopoly in one area to gain market share in another area.
But it is kind of counter-intuitive to say that the linchpin of the entire Microsoft juggernaut fundamentally rests on their amazingly functional spreadsheet (which it sort of sounds like constitutes an actually useable "no-code" platform). Supposing that were true, what would be the strategy for people trying to bring about "The Year of the Linux Desktop"? Try to get LibreOffice or Gnumeric up to parity? Or try to get documentation / education for Jupyter / Python up to parity?
That is, aside from the bundling I'm not sure MS has done anything particularly illegal or immoral? Just incredibly good business sense.
And I say that as someone with a stubborn disdain for microsoft lol.
My worry is nebulous: Microsoft is somehow buying its way into everything - AI, OSS development, gaming, etc, and it feels insidious.
However, it doesn't feel illegal at all. Governments might fancy some cash, and it's their right to write some rules to get that cash, but I don't see how in practice Microsoft is doing much obviously wrong.
Hell, Excel still has the absolute best text/csv import of any spreadsheet I’ve used.
Fixed versus delimited columns. Arbitrary delimiters. And best of all, split existing column on delimiter to create multiple columns.
None of these are that fancy of functions. And there’s no reason why every other spreadsheet couldn’t implement them. But they don’t.
Maybe because it’s not sexy. Maybe because of bias against spreadsheets. I don’t know. I just wish Excel competitors would add them.
At home environment Google Sheets works just fine.
Lotus 1-2-3 gets that specific credit, I think. But Excel is so much more than that (for good or ill).
The majority of Microsoft's software was being written to target non-Microsoft platforms at this point, which started to change with their increasingly anti-competitive marketing techniques (such as the so-called 'AARD code'[1] in 1991).
Screenshots tell the difference rather nicely:
https://ift.wiki.uib.no/images/7/71/Csv_import_libreoffice.p... (LibreOffice)
https://learn.microsoft.com/en-us/power-query/media/power-qu... (Excel)
And even there, Excel tucks away a ton of functionality behind tabs and submenus: https://learn.microsoft.com/en-us/power-query/power-query-ui
Most people who say that Google Docs or other alternatives are good enough, or that they can program what they need in Python, barely scratch the surface of what Excel offers out of the box with little effort once you've mastered its concepts and workflows. It's like doing version management with "final_report_draft_v2_final (copy 2).txt". Might work for most people, but git offers so much more for those who know how to use it. Excel is the git of the business world.
Yes you can. Most people cannot or don't want to. Programming is just a skill used to reach an end and if your job description doesn't require it, you skip it.
Excel democratizes the data analysis better than any open source alternatives and programming languages. It is easier to use and relatively less buggy than all of the open source and proprietary alternatives. When one really needs programming, VBA is there and it provides a much shallower learning curve for the curious.
From a corporate point of view MS Office has unmatched integration with Windows, Active Directory, Sharepoint, SQLServer and many other programs. A huge amount of financial, management and engineering software tightly integrates with Microsoft software to provide functionality like automatic BOM dumps to Excel and then integrating that with manufacturing, currency conversion. The developers of such software are pretty content with it, especially due to long-term backwards compatibility MS provides for their APIs for all their products.
A lot of it is entropy and entrenched knowledge.
Not having to train all your accountants on something which is similar, but different enough they are less effective until they know it as well.
The integration is another piece, as the article mentioned - the MS ecosystem makes making all documents cloud documents and sharable and collaborative within your enterprise a total snap.
I'm not aware of actual core functional pieces of excel which matter to most users that you can't get elsewhere.
Same for Google Sheets, they're fairly interoperable with the MS formats too.
Also, Google Docs doesn't come close to Word. There are a lot of little features missing and each is essential to someone.
And then there is interoperability, everyone is using it and everyone accepts it as document format.
Are you a vim user. Great I want you do that in emacs, or an ide, or vs code or...
You are looking at the problem at the wrong level. Excel is an IDE with a built in programing language for array/set based processing (it a matrix but hard to work with in that frame). Even if it looks 90% the same that last 10 is a huge change for power users of the system. Those power users (10x accountants and analysts) are going to fight you. The organization is going to fire you when you kill their productivity.
* There was one insurmountable problem. At the time OpenOffice still had a 65k row limit that Excel had long since moved past. There was a 5 year old bug ticket opened to fix it, but the developers in that thread were still having debates insisting the users were wrong and that 65k ought to be enough for anyone. You should use a real database if you need more data they insisted. Needless to say, the first time a vendor shipped us a 100k spreadsheet that we couldn't open, the writing was on the wall even if no one else had had other issues.
(I did push 10 million rows but that was by accident, some Power Query code got a little greedy)
It's funny you list these when millions of SMEs are running on Google Spreadsheet.
I don't know about Gnumeric but I think the following guesstimate is not far from the truth: 99.9% of all Excel users are using not even 1% of Excel. Most Excel users can be "switched" to Google Spreadsheet and won't even notice any difference.
Further lock-in like VBA on Excel desktop, the crippled capability of the web version, and second class support on platforms other than Windows should not be taken as virtues of Excel. Forcing everything into a "document" paradigm sucks. Needing the editor to view the data is awful. There is no separation of concerns between content and presentation. Opening a file in the state the last person edited it in is horrible.
Conceded it is a powerful application, but what I see it used for mostly us visual grid layouts using cells, rather than true tabular data. I constantly see PMs using it to painstakingly make gantt charts, when MS Project is available. It's one step away from oil and canvas.
It seems obvious to me that it is true, from my particular slice of the world, so I find it surprising that anyone would find it unsurprising. (The reason is that I am aware that whole businesses/parts of businesses are built on Excel in a way that is not replaceable by programming languages, and which everyone would refuse to replace with anything besides Excel because it's best-in-class and integrated into everything already.)
99% of white collar employees globally know/have to know MS Office. Every government uses MS office. Every sector uses MS office.
Who doesn’t use Office? Startups, creatives, scientists.
What makes Excel indispensable? Think of it as the equivalent of the English language in business IT. You can speak with your peers in your language, sure. You need some sort of common understanding? You use the tool that everyone knows.
Anyways, that's your answer. I'm guessing you, like me, pretty much never have personal problems with your own data and stuff that only you work on; you keep backups and such and know about cross-platform things and so on.
We're the extreme minority. Most folks rely on what was sold to them, idea-wise or other. Since I've been doing more independent real-life IT work along with my IT teaching, I've learned to be less judgey -- and even though I know the tech up-and-down, I've learned it's infinitely harder to get a significant number of people to see things the way people like you and me do.
Maybe I’ll go for it in 10 years once MS forces Excel to subscription only licenses and all the current perpetual options are EoL, but until then I’d rather own my data and tools.
https://www.microsoft.com/en-us/microsoft-365/p/office-home-...
https://techcommunity.microsoft.com/t5/microsoft-365-blog/up...
> there aren’t many incentives in this scenario for Microsoft to really improve the security
This is wrong, the incentives already exist through financial and legal means, and anyone who works in an enterprise with their sprawling estate can tell you that they are constantly working on security controls and tooling. The key thing to remember is the sprawling estate, more surfaces means more attack vectors, and patches. I hope a cybersecurity professional isn't equating more mitigations with a poor security posture. It's when things are silent that you ought to be terrified.
> The FBI and the U.K.’s National Crime Agency, for example, have done a tremendous job of gaining access to things like the Tor hidden services that underpin attacker infrastructure, collecting evidence from them, and then shutting them down.
> when Western authorities started “disrupting” ransomware crews
Conveniently ignores that a lot of them work directly with MS to take down botnets and ransomware threat actors. No mention whatsoever of MS' role in this.
I struggled to take any of this seriously, especially when it came to the pretentious I-am-very-smarter-than-you attitude.
> as I looked around the room I couldn’t help wonder if the way to really deal with this problem would be found in a different venue ... perhaps at a capture-the-flag hacking contest being held in a dimly lit casino ballroom in Las Vegas.
Even without this hilarious security hole windows has no concept of app permissions. Antivirus's are a joke, they can't tell what is goodware or malware. Anything that can gain user space privledges can compromise the whole system under windows. They disable file extensions by default and make it easy to use fake ones. "Hey look at this report - exereport.pdf" or a dozen other executable extensions.
Adobe should be liable for PDF exploits as well. Start fining and fund a security org with it.
This is all documented in even basic tutorials. Windows is still what they designed back in the 90's. It doesn't get scrutiny because it's all closed source and has big political ties.
Could you elaborate on what you mean by this?
Known as "indirect syscalls".
Has this ever happened before? I can't name a single major company on earth that takes customer security seriously except through farcical characterization of the concept. It's just too much of an impediment to profitable business to be incentivized in any serious sense. Even the concept of "security" without parameterization of a threat model seems to make a joke of the concept.
I'm not claiming that free software offers security that's better per threat model, but they at least allow customization of the threat model itself. Without this being up for discussion such a claim to discuss security in general is extremely difficult to take seriously.
The Google threat model openly lauded in the article seemingly doesn't take state actors as a serious threat model, for instance. They'll just hand your data over to the state that asks for it because they want the business that happens under that state.
The article specifically mentioned the Google threat model was a result of a state actor threat ("Operation Aurora").
In addition to what the sibling poster pointed out about Aurora, even Google is starting to wise up about the undesirability of holding so much customer data (for Google, more from a government subpoena standpoint than from a security-from-hackers standpoint), with the recent changes to how their location tracking / Timeline feature works.
Wow.
The "humans who are exposing those vulnerabilities" are doing it to profit by committing extremely disruptive attacks on random businesses, hospitals, and important infrastructure.
I don't support literally getting them killed, but they're not innocent hackers driven by curiosity the way your comment makes it sound.
Am I reading this right that you’re more concerned with Russian assets that hack US companies for both financial gain and political leverage, than the US citizens whose lives are put at risk? What exactly do you think happens when a ransomware gang locks down a hospital?
What you call "assets" are people too, by the way.
Once you start dehumanizing, you won't stop dehumanizing. Eventually only people you agree with will be considered "people", and boom, you're a fascist.
The Glasgow bombers were doctors who studied with my cousin in Saudi Arabia back in the day. My cousin didn't go around making bombs though.
Yes, I think you did. I read it as two different snippets of thought published together with even more in a single blog post.
For profit. These people are criminals who are stealing from American companies.