Microsoft "doubling down" on cybersecurity
axios.com
axios.com
And as for cybersecurity - MS is now forcing AI agents to run on your machine in the background. That undermines everyone’s privacy and security.
- Microsoft is one of the top conglomerates and has a lot of issues which are common at that size of the organization while delivering incredible revenue results.
- I completely agree with you that we can make a list of Microsoft completely unfair practices. One of my companies is full dedicated to Microsoft Windows System Programming/Internals and I an personally not using Windows "anymore" since I cannot (be 100% sure) disable telemetry and all those scammy bloatware.
- Having said all that, I have insiding information about the first cybersecurity approach from Microsoft Bill Gates time and it was real. Following that thing, today cybersecurity IS geopolitics so you cannot play the wrong game.
In the last year there have been multiple huge security breaches at Microsoft. And it's not just that there were bugs. It's that these cases showed a shocking negligence in security systems and processes, and no defense in depth.
So why exactly does Nadella deserve any trust on security? All of this happened on his watch. And like, it's not even a close call where he could plausibly blame his predecessors. He had a decade to get his house in order, and appears to have done nothing at all. If anything, it's the opposite: his words on are empty and can't be trusted, until they actually deliver.
Maybe they should rebase their OS with SeL4, a capabilities system and isolated NT+Win32 subsystems on top per application. It should requiere a current-ish computer to run that, but the resources would be properly spent.
A jail + own FS + subsystem would be taxing over four or fives applications open, but documents and software would stay in their own jails. Interop ala COM/OLE? Forget that, the data sharing protocols would be far more restrictive. If any, a noexec subvolume with OLE objects saved as files. Nothing like DBUS or message passing. The user would see a directory with the objects from the clipboard per application. And to be shareable between applications, the user must drop the object in a directory with shared objects explicitly.
> Interop ala COM/OLE? Forget that, the data sharing protocols would be far more restrictive
This would be unacceptable to any business. COM/OLE is absolutely critical for cross-application functionality, especially for Office.
[0] https://learn.microsoft.com/en-us/virtualization/windowscont...
[1] https://learn.microsoft.com/en-us/windows/security/applicati...
Either be secure, or get ransonwares on a week basis plumetting down any profit. Their choice.
Here is the security certification page for Windows Server [1]. They achieved EAL1+ which is: "applicable where some confidence in correct operation is required, but the threats to security are not viewed as serious" [2].
Stating your dreams is not the same as achieving them. Please point to actual evidence that their dreams have been reached. And no, it is "battle-tested" and "no new bugs have been discovered yet" and "you can not prove it is bad" are not evidence, it needs to be actual positive evidence of quality, not the absence of evidence of defects.
[1] https://learn.microsoft.com/en-us/windows/security/security-...
[2] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR...
But you gotta save your portfolio, so, let's defend them, yet again, go $MSFT!
I am having trouble naming one change they have delivered since Nadella came along that isn't user hostile or a net loss for security in some way.