At Microsoft, years of security debt come crashing down
cybersecuritydive.com
cybersecuritydive.com
Good news! I am sure there aren't any deeper issues around Microsoft's ideology, arrogance, or crass financially-motivated reasoning. Otherwise I might start wondering if maybe Microsoft's security AI might not actually work that well.
Trustworthy Computing initiative was 22 years ago. Hopefully the new start menu ads won't be another attack vector.
apple and apps have more access to my phone than I do. And they have unfettered network access to exfiltrate anything they want.
We are unfortunately prisoner of the masses. The smart phone is a 99% device which means it caters for 99% of the users. And it's probably not a good idea letting 99% of the users anywhere near the thing based on the crap I've had to unstick over the years.
We can of course choose not to participate in this still if we don't want to.
The problem is that the alternatives are lacking, at least for the smartphone world. While on my PC I run a Linux distro, efforts like the PinePhone are still not good enough to be a daily driver.
What incentive does Microsoft have to change when the customer response to security breaches is to buy more expensive licenses from them? There's not much leverage in criticizing Microsoft, as is hinted in the article: the leverage is in criticizing orgs that continue to give MS more money.
This is nothing new. Microsoft and security was always a problem mariage.
"Beginning mandatory shutdown for software updates. There's nothing you could possibly need your own computer for in the next hour, and all the data you lost when we killed your programs is your fault for not using Microsoft applications instead."
> Privacy: Users should be in control of how their data is used
"Telemetry is very important, for example the hardware IDs of that USB stick you plugged in were also reported to us by another computer an hour earlier, so now we know there's a relationship between you! Isn't metadata grand? But trust us, we have only your privacy in mind. By the way, did you ever finish that novel you were working on from the last crash report?"
> Users should be in control of when and if they receive information to make best use of their time.
"Hey! You still haven't linked your logon to a Microsoft account! Hey! Use Bing! Hey! It looks like you launched a web browser that isn't from Microsoft, switch to Edge instead! Hey! Here are advertisements on your lock-screen just cuz we can!"
Trust is of course earned. Bill's words were lost unfortunately under the next year's priority, the one after that and the one after that.
Today it's AI. Tomorrow it's whatever Satya says that pumps the stock. I've worked with their tech for 30 years and customer requirements, safety and security is somewhere down the priority list. That is the only truth.
Thrown out of the window long since
The unhealthy thing here isn't the marketplace, it's government policy. If you eschew popular open-source tools for closed/proprietary alternatives, this will happen. Linux will always have several orders of magnitude more experts banging on it than Windows ever will. Vendors pontificating about security will not change this fundamental asymmetry. Also, don't want product lock-in? Don't choose vendors with a significant risk or history of lock-in. Don't endorse face-eating leopards and then blame others when they eat your face.
I don’t agree with the outcome, but the logic isn’t hard to follow.
First, we're not talking about the desktop here, we're talking about services. Open source provides much better quality for services. It is frankly appalling to me to see the government relying on Microsoft services given the quality and reliability and security of open source alternatives--not to mention the lower cost.
Second, the biggest obstacle to a standardized Linux desktop that everyone can use and rely on is the lack of a big player in the market willing to invest in one. Imagine if the government took even a fraction of the money it spends on Windows desktops, and spent it on developing a standardized Linux desktop instead. Isn't that exactly the sort of coordination problem that governments are supposed to solve?
I agree with your second point. I'm in the UK and have advocated this position for years. We have so much government infra here, considering NHS etc, that it would be cost effective to dedicate people to a "national standard computing" infrastructure. But it doesn't exist. Yet.
I am forced to use O365 every day in my work. It's a piece of crap. The LibreOffice equivalents that I have on my personal Linux machines are better for everyday office applications. As for server side, even if we leave aside all the times I see supposedly reliable MS infrastructure break when I'm trying to do an everyday task, a quick Google search will show you plenty of equivalents, and as for "scaling", the government, or any large organization, could get better value for money paying someone to engineer whatever customizations are necessary in the open source alternatives--which it could then deploy for free on as many servers as it wanted--than from MS's licensing model.
Also a lot of assumptions about the ROI there and the availability of any engineers who can customise it.
You suspect wrongly.
> There's a lot of collaboration stuff in there which is pretty much unbeatable.
Evidently you and I have had very different experiences.
You're welcome.
...
> Show me an open source O365 equivalent that scales to the 10,000 seats in my org.
...
> Now how do I collaborate with the people in the other 3 orgs I work with who use O365?
I hope you used an excavator, moving those goalposts.
(I will add I despise it to the core, but I know why people use it)
As you pointed out once the goal posts shifted, the reason they use Microsoft is because Microsoft is notoriously incompatible with anyone but Microsoft, but also ubiquitous.
you are communicating on it right now
YMMV.
But that isn't the point. The point is that the open source desktops do not even touch Windows in usability, quality, reliability and consistency. At best everything is fragmented at 80% complete. Show me an open source O365 and you might have something fit for an SME or government.
I had a chuckle about this one. Seriously, none of MS crap comes close to a modern rolling release distro + KDE.
> Show me an open source O365 and you might have something fit for an SME or government.
Libre Office is pretty good, but its usability needs lots of work. To this day Libre Office still ships with templates that look like they were designed in 1998.
- You want a quick and dirty document or presentation that looks pretty good: MS Office is the winner.
- You want a large document with lots of figures, captions etc: Libre Office is the winner.Try to keep a larger document meticulously styled with named styles, MS Word will trip over tons of its bugs that lurks in the dark, and it will make an non-salvageable mess of figure placement, caption numbering, losing header formatting and what not.
What OSS software needs is more investment in UX. Libre Office needs a reality check here. In this respect KDE is a great outlier, as it looks great, is responsive and has tons of pro features that are discoverable.
Probably need something similar to a wake up call some industrial companies got with stux in the 2010s or hell their insurance company charging the sh*t out them unless they fix some things.
And I think they're probably right (although I'm not a security professional).
How about the opinion of people who have nothing to win nor lose ?
The people who think that Linux security is fine also make arguments, but those arguments are much less detailed (and much less convincing IMHO), such as the frequently-made argument that the fact that Linux's source code is readily available at no cost to anyone who wants to search it for security holes means that Linux's security will tend to be better than the security of systems whose source code is held secret. I mean, sure, if that were the only thing we knew about operating systems and we were forced to choose an OS based on that single piece of information, we'd choose one of the open-source ones, but the persuasiveness of that argument is more than cancelled out when we consider all the other things we know, such as the fact that many exploitable vulnerabilities have been found in Linux that examination of old versions of the source code reveal have been present for decades.
>How about the opinion of people who have nothing to win nor lose?
The question is complicated enough that my guess is that basically the only people who make the mental effort to resolve the question are people with a stake in it.
How many people for example who do not have a loved one with the cancer or a unusually high risk for that cancer and who do not hope to advance their careers as cancer-curers or cancer-preventers take the trouble to learn about the diagnosis and treatment of a particular kind of cancer?
Shall I take each point and explain why they are bullshit ? Probably not, but do tell me. This kind of post is a perfect example of the bullshit I spoke about.
Just a quote to illustrate:
The Linux kernel's size grows exponentially across each release, and it can be thought of as equivalent to running all user space code as root in PID 1, if not even more dangerous.
What the fuck.When two sentences later it says, "it can be thought of as equivalent to running all user space code as root in PID 1", it is elaborating on "no isolation . . . whatsoever". Specifically, it is saying that the organization of kernel code is analogous to organizing userspace so that all userspace code run as root in a single process.
The author of the madaidans site BTW is a Whonix and open-source developer, so how is it in his self-interest to criticize Linux's security? There is no indication anywhere on the site that the author or anyone else want to sell the reader anything.
I mean this very sincerely: The day Microsoft's products are actually secure is the day I'm out of a job.
AD is just a fancy interface to LDAP with Kerberos, that sound familiar in any way?
The big difference is that a breach of any single Entra ID connected service doesn’t give attackers widespread access to unrelated systems sharing the same tenant. For comparison, once you’ve got a foothold on an Active Directory domain member, it’s surprisingly easy to move horizontally to the rest of the network.
Can Firefox still write to ~/.profile if there's a buffer overrun somewhere for example? Did I curl | sh some random shit 50 times since December?
What is security even?
> Failure of accountability
Many in the security community see the CSRB report and the recent CISA emergency directive as direct indictments not only of Microsoft’s security culture, but a government that has allowed Microsoft to maintain lucrative government contracts with no fear of competition across many of its services.
“The federal government gets off the hook a little easy in this report,” said Mark Montgomery, senior director at the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies. “Despite significant encouragement from outside experts, the Biden administration, and its predecessors, have failed to treat cloud computing as a national critical infrastructure, that is itself critical to maintaining the security of our national critical infrastructures.”
Sen. Ron Wyden, D-Ore., who called for a federal investigation following the State Department email hack, said the federal government shared responsibility for the negligent behavior disclosed in the report.
Wyden said Microsoft has been rewarded with billions of dollars in federal contracts, while not being held to account for even the most basic security standards.
The US has a billion or ten to spare for this. Billion. With a B. This is an investment that is not just defense, it is an investment in the general economy.
The NSA budget is (maybe) 3.6 billion dollars. A general secure computing base for the American economy is worth at least 3x that.
'Everything authenticated by Microsoft is tainted' ( https://news.ycombinator.com/item?id=37702095 )
... and thought something significant will definitely come out of this. (It didn't, so far I could tell.)
Here in AU it feels most orgs and gov agencies still assume Microsoft is the arbiter and epitome of good security practice, and their products seem to be excluded from serious scrutiny or regular review, as per almost every other vendor. (Google may be another exception, but their attack surface is obviously quite different.)
I'm inclined to believe that Microsoft is doing fairly well amongst Fortune 500 and cloud companies. Not perfect, but fairly well.
Am I offbase?
Edit: I guess I am. Thanks for clarifying and augmenting with more evidence, repliers.
Microsoft got their MSA secret stolen, allowing China to read government emails.
Do you need another example?
https://www.theregister.com/AMP/2023/09/06/microsoft_stolen_...
https://www.dhs.gov/news/2024/04/02/cyber-safety-review-boar...
Just the branding - the name and logo is exactly the same as Windows Defender. It even puts an icon in the taskbar tray, resulting in two identical logos for two identically named products that do completely different things.
No idea what they were thinking there. It seems they thought that the separation in consumers’ minds between “Microsoft” and “Windows” was strong, which it absolutely is not.
Microsoft branding is so bad.
https://www.microsoft.com/en-us/microsoft-365/blog/2022/06/1...
Windows Defender aka Windows Security:
https://support.microsoft.com/en-us/windows/stay-protected-w...
Microsoft Defender XDR (completely different thing, previously known as Microsoft Defender for 365):
https://www.microsoft.com/en-us/security/business/siem-and-x...
Microsoft Defender for Endpoint (also a different thing, basically XDR lite):
https://www.microsoft.com/en-us/security/business/endpoint-s...
I find it odd that you'll reject Microsoft based on "recent incidents", as if security incidents don't happen with the competitors?
And were those incidents detected by the competitor or a client?
> One of the more damaging findings was that Microsoft learned of the attacks only because the State Department had set up an internal alert system after purchasing a G5 license from the company.
Although I mean the lack of on-prem really should be a nonstarter for a lot of large companies. Having a defense in depth where you need to be on the VPN before you can actually authenticate to the services does help. Or in the case of governments; they can run private fiber lines between buildings and then you can't even attack the server from the public web.
I'm not following you here. Surely you could just look them up yourself?
Just look at this enormous list of CVEs in Oracle products (which also includes cloud products), as one example: https://www.oracle.com/security-alerts/public-vuln-to-adviso...
Sure, but you do realize that all of those bugs in their products may have been exploited in their clouds in different ways?
"May" is not what the article linked at the top of the page is talking about.
Sales teams and various vendor lockouts/ins can cause people to bend the knee.
I accidentally pay $70/mo to microsoft because I bought wrong licenses that I needed only to serve a customer. Up until I started this company, I was 0% Microsoft.
Microsoft is said to be a collection of almost independent companies sharing a domain and a CEO. Based on my experience, small as it is, I can believe it.
"Microsoft is a many-headed beast. Some heads are benevolent. Some less so."
> Microsoft is said to be a collection of almost independent companies sharing a domain and a CEO.
Fairly true.
Like everything else in life, there's always trade-offs here, say, promoting your security practices to attract customers, but the general rule is that moment you start having different tiers of protection, you start venturing into some seriously morally grey areas.
Microsoft didn't just start venturing into morally grey areas, they decided to set up their entire business model there, to the point that they didn't even know that they were hacked because they couldn't generate revenue from that knowledge.
THAT'S why Microsoft deserves every piece of bad press it's getting right now. Not that they had a security incident (everyone will have security incidents), it's that they deliberately ignored accepted industry standards to do so, and to this day they're stonewalling efforts to assess the full impact.