> A programming flaw in its cloud services also allowed China-backed hackers to steal email from federal officials. On Friday, Microsoft said it would stop using China-based engineers to support Defense Department cloud-computing programs after a report by investigative outlet ProPublica revealed the practice, prompting Defense Secretary Pete Hegseth to order a review of Pentagon cloud deals.
Anyway, from what I can tell being in this industry, a lot of things need to be explicitly illegal to stop companies from doing it.
Edit: The penalities also have to be meaningful. There's a lot of "technically not legal, but sue us lol" going on.
"Hey, this is a really really stupid idea." Isn't going to stop a middle manager from trying to come in under budget.
At most MS will pay a nominal fine, and proceed to learn nothing.
Microsoft also has a captive market here. Realistically you aren't going to migrate millions of employees and servers to another tech stack, even over something egregiously bad.
Something like storing cleared data really should be handled 100% internally with an open source stack that's regularly audited.
But that sounds really difficult, even if it would be cheaper or the same price in the long run.
I didn't suggested preventing the fulfillment of existing contracts. Nobody would change for all costumers. They just wouldn't get any new contractors.
Sanctions already exist.
So after the current contract do you switch stacks, or just have a 3rd partner Microsoft shop maintain your existing stack?
Regardless, I don't think our current legal system has any real ability to hold a company like Microsoft accountable.
But yeah I don't know any party who has such ideas.
Neither is "you can go to jail" when it comes to export controls training
Would the CCP allow their cloud infra to be administrated by US staff in the US? Never.