Microsoft ties executive pay to security after multiple failures and breaches
arstechnica.com
arstechnica.com
But the first phase will be a lot of "security & quality" presentations to the troops, some hiring and ground prep-work so the blaming can be done when things go south.
I would like to be more positive, but I already saw this cycle too many times.
How about security being part of the requirements to keep a job instead of monetary bonus? and this has to be applied to the top, only then to the bottom.
Because the monetary incentives are greater than the position for executives, and they are the ones to be accountable.
Of course this is a form of lip service. Of course there's way more to do. But they are making a very public statement to prioritize security. That's a positive.
You should meet my director who wants everything to be covered under the rug while he focuses on empire building.
I see some devs thinking I was talking about them and getting defensive :) It's not a "we discover a bug, we fire you" situation, that's ridiculous.
- the Peter Principle (as a loosely related concept)
and
- that the new MS diktats would immediately be gamed.
What was my surprise when I saw both those concepts mentioned in the See Also section!
I did not know about most of the other See Also points, though, except for Confirmation bias, which I had read about on Hacker News, and the Hawthorne Effect, which I had read about elsewhere, IIRC, in a Dale Carnegie or similar self-help book.
What's the percentage? What are the milestones?
Edit: The "security plans and milestones" appear to be here: https://www.microsoft.com/en-us/security/blog/2024/05/03/sec...
Security is somewhere under that umbrella. Also all the other stuff end users give a shit about that Microsoft doesn't...
"How did we do?"
"Please take a few minutes to fill out this survey on your recent interaction with Microsoft"
MS is a publicly quoted company wot sells shares. They are therefore answerable to their shareholders. Shareholders first, everyone else comes second is largely the first order of the day.
It's a bit shit when you try to factor in some sort of moral angle but that is how things are.
In this way, executives and policy makers have a harder time moving on and not being accounting before the effect of their bad decisions is apparent, because the reputation for sharesholder value destruction could haunt them. Executives will be incentivized to create a better security culture.
Wikipedia is an exception, of course.
Of course another reply notes the clear external vs. internal link approach of wikipedia, too.
Seems like they're finally doing something about that, to set an example for the rest of the industry.
A lot of them don't make much sense for us, we primarily make a Win32 B2B program hosted by these customers themselves and a lot of the checklists are all about more generic web SaaS things (because we charge like SaaS). But the person on the other end wants all the questions answered regardless.
Seems that as long as you can put a checkmark in a box that you follow various "best practices" and whatnot, actual details don't matter. You put a checkmark in a box, you did your best.
My current place, there are developers still using like node 10 and other ancient software, but god forbid you not fill out a checklist.
Very often the best answer would be like:
> Q: Do you use multi-tenant databases?
> A: N/A: you'll be deploying our product on your own server.
That's actually a perfectly fine answer! The person reading it doesn't have to explain large gaps in the answers to their boss. It documents why this isn't relevant in a way their successor can easily understand next year when they're reviewing those 100 vendors as part of their annual Vendor Management Policy™ process.
"Which controls exist for medical data?"
"Sir, this is a Wendy's™ app."
If you see the same questions over and over and over again, consider filling out a SIG LITE questionnaire and offering that to buyers from the start. If you can give them all or most of the info they need in a common format, you might be able to head off a lot of follow-up questions.
It's the same thing every time because the actual security is in the details, but details are so fucking boring.
Giant products like AWS and Azure are too big to grill about their security controls. If you try to ask an AWS rep about something, they'll direct you to their security portal where you can download a SOC2 report and a few other things. That's about all you'll get from them unless you're equally huge. The most you can really go by is their reputation. If you trust AWS, buy their product. If you don't, don't. That's all the prior research a typical < 10,000 employee business can possibly do.
My suspicion is that your friend is only talking to clients who've vetted Azure and figured "it's Microsoft: they're big so they probably know more about it than I do". It's not that they don't care. It's that there's nothing they can do about it. The people who don't already trust Azure would never have gotten as far as talking to your friend in the first place.
But in practice, yes many clients probably assume that by running in the cloud, they're "secure" (thus, failing their end of the bargain).
This is a step in the right direction to get the top-layer prioritizing security.
The main challenge he highlighted is there're no financial incentives for most companies in the industry to stay secure (unless you're a security company) - the punishment (including reputational risk) is just way too small.
Even the good people at microsoft will forever be undermined by this shit, complete demoralization and throwing their hands up to doing anything properly
Let me guess: logging in with a Microsoft Account is a security protection, as is collecting more telemetry, for security of course.
I would expect this to result in lower feature velocity. In theory features are tied to increasing revenue. If so, I wonder if he is actually willing to make that trade off.
This is terrible.
Software in particular has been so lucky to have so many people able to steam ahead, break ground, make features and new products. This caring for the rest, looking at longer lifecycle & maintaining... It's not fun. It's not inspirational. It's not fast. It doesn't feel productive or creative.
And that's some of the next decades for this profession. An end to fun and innovation. More being yolked and driven by external demands & stressors. Good luck all.
How this particular new “tying” of one thing to another impacts the overall state of things is anyone’s guess.
Because you’re literally pulling that out of your ass. Even the article you link never mentions that and mentions multiple times that there was no such thing.
Quote: “Tying senior leaders’ compensation to diversity gains in their respective organizations.”
If you think that an increase from 6.5% to 7% in Hispanic employees or from 28.6% to 29.7% in women is all driven by requiring exec approval for straight white men, then you’re delusional.
Note that I’m not necessarily tying years of hardcore DEI quota hiring per se to their recent failures. For all I know the two things might be unrelated. I’m just saying they already tie exec compensation to all sorts of other things some of which might conflict with one another.
DEI is about inclusion (that's the I) of people who have traditionally been excluded from opportunities. It's not about keeping anyone else out or down. Try actually educating yourself instead of repeating brain dead nonsense.
You’re simply dismissing others’ experience, but I’m not lying to you when I say that many of us have direct experience with this. At the big tech companies this is normal practice. Also race questions are standard in the application process, even if optional, and even if you don’t answer them, internal diversity teams will guess at people’s races where they don’t have data. In hiring decision meetings, people definitely discuss protected traits as a reason to say yes. In promotion meetings, these diversity metrics are reviewed and tweaks are made based on protected traits. If you’re a junior manager you are not going to be in the room when that happens, to keep things secret.
> Try actually educating yourself instead of repeating brain dead nonsense.
Read the guidelines: https://news.ycombinator.com/newsguidelines.html
I wish DEI groups had as much power as right wingers fantasize. Maybe we'd see more under represented communities in C-suite, instead the head of DEI trots everyone out for a meeting to talk about what they want to do and then "mysteriously" leaves 8 months later when they realize "wait, I don't actually get to do anything".
Anyway, I read as much of the linked article as I could stomach, but I gave up at this point:
> When I began my career, I believed that the systems for determining who got a job or a promotion at a company like Microsoft at least aimed at an ideal of meritocracy
I have had these conversations with fuckhead managers in the past. How the hell can we have a meritocracy when non-cis-white-males have far less opportunity to gain the resume points necessary to compete? “Meritocracy” in this sense is, at best, nothing more than a cover for conservatism.
A historical lack of diversity obviously has a compounding effect on the skills of a population and the only way to fix that historical wrong is to promote people who would not otherwise have had that opportunity.
Instead of railing against diversity quotas, maybe instead you could think about why the fuck they are necessary in the fist place?
Could it be that the biggest company in the world benefits from these policies? By acknowledging that a resume might be affected by lack of opportunity, Microsoft gets to sample from a larger pool of potential excellence.
It’s pretty simple really. Isn’t the success of Microsoft proof that diversity is actually beneficial to private industry?
I’ve come to the conclusion that “meritocracy” - when used in the context of diversity - is just another code word for “racist fuckhead”, and honestly I’m sick of hearing about it.
Sounds racist. And illegal?
the ceo of ibm was on camera saying things exactly like this to everyone in the meeting, no idea where they get these ideas from
>My sole motivation is to get things to where merit and merit alone determines who gets hired and promoted
The problem is that "merit" is an incredibly loaded term. It _sounds_ nice. But reality is messy.
For example, how do you explain the incredibly tight and consistent correlation between the income group you're at by 30 and the one you were born into? Where is the merit in that?
> There weren’t any quotas around how many of these “diverse” candidates I had to actually hire
> Again, there was no quota