I'm inclined to believe that Microsoft is doing fairly well amongst Fortune 500 and cloud companies. Not perfect, but fairly well.
Am I offbase?
Edit: I guess I am. Thanks for clarifying and augmenting with more evidence, repliers.
I'm inclined to believe that Microsoft is doing fairly well amongst Fortune 500 and cloud companies. Not perfect, but fairly well.
Am I offbase?
Edit: I guess I am. Thanks for clarifying and augmenting with more evidence, repliers.
Microsoft got their MSA secret stolen, allowing China to read government emails.
Do you need another example?
https://www.theregister.com/AMP/2023/09/06/microsoft_stolen_...
https://www.dhs.gov/news/2024/04/02/cyber-safety-review-boar...
Just the branding - the name and logo is exactly the same as Windows Defender. It even puts an icon in the taskbar tray, resulting in two identical logos for two identically named products that do completely different things.
No idea what they were thinking there. It seems they thought that the separation in consumers’ minds between “Microsoft” and “Windows” was strong, which it absolutely is not.
https://www.microsoft.com/en-us/microsoft-365/blog/2022/06/1...
Windows Defender aka Windows Security:
https://support.microsoft.com/en-us/windows/stay-protected-w...
Microsoft Defender XDR (completely different thing, previously known as Microsoft Defender for 365):
https://www.microsoft.com/en-us/security/business/siem-and-x...
Microsoft Defender for Endpoint (also a different thing, basically XDR lite):
https://www.microsoft.com/en-us/security/business/endpoint-s...
Microsoft branding is so bad.
I find it odd that you'll reject Microsoft based on "recent incidents", as if security incidents don't happen with the competitors?
And were those incidents detected by the competitor or a client?
> One of the more damaging findings was that Microsoft learned of the attacks only because the State Department had set up an internal alert system after purchasing a G5 license from the company.
Although I mean the lack of on-prem really should be a nonstarter for a lot of large companies. Having a defense in depth where you need to be on the VPN before you can actually authenticate to the services does help. Or in the case of governments; they can run private fiber lines between buildings and then you can't even attack the server from the public web.
I'm not following you here. Surely you could just look them up yourself?
Just look at this enormous list of CVEs in Oracle products (which also includes cloud products), as one example: https://www.oracle.com/security-alerts/public-vuln-to-adviso...
Sure, but you do realize that all of those bugs in their products may have been exploited in their clouds in different ways?
"May" is not what the article linked at the top of the page is talking about.
Sales teams and various vendor lockouts/ins can cause people to bend the knee.
I accidentally pay $70/mo to microsoft because I bought wrong licenses that I needed only to serve a customer. Up until I started this company, I was 0% Microsoft.
Microsoft is said to be a collection of almost independent companies sharing a domain and a CEO. Based on my experience, small as it is, I can believe it.
"Microsoft is a many-headed beast. Some heads are benevolent. Some less so."
> Microsoft is said to be a collection of almost independent companies sharing a domain and a CEO.
Fairly true.
Like everything else in life, there's always trade-offs here, say, promoting your security practices to attract customers, but the general rule is that moment you start having different tiers of protection, you start venturing into some seriously morally grey areas.
Microsoft didn't just start venturing into morally grey areas, they decided to set up their entire business model there, to the point that they didn't even know that they were hacked because they couldn't generate revenue from that knowledge.
THAT'S why Microsoft deserves every piece of bad press it's getting right now. Not that they had a security incident (everyone will have security incidents), it's that they deliberately ignored accepted industry standards to do so, and to this day they're stonewalling efforts to assess the full impact.