Microsoft CEO Satya Nadella is now personally responsible for security flaws.
Microsoft is pivoting its company culture to make security a top priority, President Brad Smith testified to Congress on Thursday, promising that security will be "more important even than the company’s work on artificial intelligence."
Satya Nadella, Microsoft's CEO, "has taken on the responsibility personally to serve as the senior executive with overall accountability for Microsoft’s security," Smith told Congress.
His testimony comes after Microsoft admitted that it could have taken steps to prevent two aggressive nation-state cyberattacks from China and Russia.
According to Microsoft whistleblower Andrew Harris, Microsoft spent years ignoring a vulnerability while he proposed fixes to the "security nightmare." Instead, Microsoft feared it might lose its government contract by warning about the bug and allegedly downplayed the problem, choosing profits over security, ProPublica reported.
This apparent negligence led to one of the largest cyberattacks in US history, and officials' sensitive data was compromised due to Microsoft's security failures. The China-linked hackers stole 60,000 US State Department emails, Reuters reported. And several federal agencies were hit, giving attackers access to sensitive government information, including data from the National Nuclear Security Administration and the National Institutes of Health, ProPublica reported. Even Microsoft itself was breached, with a Russian group accessing senior staff emails this year, including their "correspondence with government officials," Reuters reported.
To reinforce the shift in company culture toward "empowering and rewarding every employee to find security issues, report them," and "help fix them," Smith said that Nadella sent an email out to all staff urging that security should always remain top of mind.
Well recall is why they're so focused on security now. They want to host every detail of your life. They can't do that now because their platform is a tire fire.
you can have a propietary os thats secure, but the problem is once you get to the point where youre selling data and allow anything to be installed of course, its no longer secure.
You can't verify it's secure if it's proprietary, so it's never secure? Having control over other people's computing creates bad incentives to gain at your user's expense, so it's day 1 you should lose trust.
That's the crux of it here. Microsoft wanted to get into the data game they saw Facebook and Google reaping. However, Microsoft still charge you for the software they use to harvest your data.
"Microsoft is pivoting its company culture to make security a top priority..."
The fact that this had to be stated is a testament to garbage leadership. Notice it's not even the top priority, just a top priority. These guys will still get bonuses of course.
Like most big tech companies, they're actually several divisions all competing with each other. Lately, the AI divisions have latched on to the hype and they're pushing their wares to other divisions, often with enough clout to keep those in security/privacy quiet. Integrating LLM's is also a great way for a middle manager type to curry favour with the bosses, and to build little empires for themselves.
Are you kidding? I've known Microsoft as a shitty software vendor that gives a rats ass about security for over 40 years now. Microsoft never has cared about security, it's a running gag at this point
Its part of their large scale automation strategy, wherein they gobble up as much of the business practices of an organization's staff as possible and then offer to provide "AI Employees" who replicate the logic of human staffers at a discounted price.
I've spent the better part of my life watching microsoft fuck people over and then when they finally - finally get called out on it they do a bunch of bashful aw-shucksing before doing it again and again and again.
No.
Microsoft is dead. Kill it with fire. The US government should have known better, but they didn't because like every other organization they have a boatload of clueless mid-level managers who only every learned Windows and fall for microsoft's garbage every time, despite the eye-popping price.
NO MICROSOFT. EVER. They're a criminal organizaiton, the amount of destruction they've created will never be known.
I remember them saying all the same exact things in the early 2000s after a slew of widespread disasters. Security will never be a higher priority than whatever cool new thing they want to sell.
It would take ripping apart and rewriting hundreds of thousands of lines of source code, if not millions. Not just bloat from one off bright ideas, that led to the next bright ideas, but the deliberate obsfucation to protect proprietary code, in more instances than I can imagine. I'm not a programmer, so I could be wrong, obviously, but from my admittedly limited perspective, they'd be better off writing a whole new OS without all the built-in garbage nobody wants.
I think Windows 11 was supposed to be that clean break. They've reimplemented a lot of core functionality compared to XP & 7. If they're still getting breached then they obviously aren't serious about security.
the funniest part of the fall of MS for me has been the cunts getting so excited about fucking off the home users they forgot one vital thing: C-suite and beancounters run at a home user level. And most infrastructure techs will happily flick to a linux distro come server build time.
Their current direction has also pretty much killed their use in anything related to media distribution, it's virtually a detailed list of TPN violations
According to Microsoft whistleblower Andrew Harris, Microsoft spent years ignoring a vulnerability while he proposed fixes to the "security nightmare." Instead, Microsoft feared it might lose its government contract by warning about the bug and allegedly downplayed the problem
This says everything about this shitty company. Worst of the worst. Because that’s how they make 90% of their cash. By exploiting licensing deals and siphoning data to sell to whomever because they do not care who it is so long as they bid the highest.
It’s amazing no one has tried to break up their control over PCs. Make this world make sense.
Seriously, why are governments using Microsoft software?
Don't give me the nonsense line of "they need support". There is support for Linux too, and Linux, sorry, works, is reliable and most importantly: a hell of a lot safer than windows. This is example #346269 where Microsoft not only fails to keep windows even remotely safe, but actively sabotaged their customers (in this case the US government) for their own profit.
And again, "wwheeeyyyrreee sooowwyyyy, pleeeaaasseeee forgif us?" Look! Look! Even our CEO will now be interested in secuwity!
Seriously I'm so tired of having to read this over and over and he government will just contoi to pump millions over millions into that piece of crap company.
Switch to Linux already and have computers that you can trust have no known issues that are not being resolved to cover for a few rich assholes!
I imagine it must suck to be involved in a big government procurement, because you are pretty much guaranteed to have to get pulled into legal proceedings by one or more of the losers.
A much much larger proportion of users are computer illiterate, especially federal employees. On top of that, the vast majority of basic software applications used are the Microsoft suite of Outlook, Word, Excel, PowerPoint, etc. How do you
Retrain an aging workforce to use a new OS.
Retrain to use new software suite for email, docs, etc.
Or rebuild existing software to run on Linux
...there's more but I'm short on time...
The ENTIRE US govt runs on Microsoft. That's a very big pie to rebake. Where do you even begin. I do agree with you, it just feels unsurmountable.
Political leadership isn't technically knowledgeable. It is focused on building large social networks of agreeable people. And Linux is an application by and for techies, not CEOs or social clubs. Consequently, when you've got six old white Harvard Alums in a room discussing how to run the country, one of them is going to be a Microsoft C-level and none of them are going to mention an alternative OS (except maybe Apple, in so far as they want their phone to magically integrate with a hostile OS rival).
Switch to Linux already and have computers that you can trust
A lot of these Microsoft features are about internal surveillance of staff and accumulating behavior patterns for future automation of service. This is not intended to be about building trust in the OS from the perspective of system security. Its more about finding patterns in human behavior that can be leveraged to reduce the size and pay-scale of your work force.
To that end, Microsoft is a highly valued partner while the Linux developers are an outright threat.
Satya Nadella, Microsoft’s CEO, “has taken on the responsibility personally to serve as the senior executive with overall accountability for Microsoft’s security,”
Err. Wasn't that already true? He's chief executive officer, not chief some shit that doesn't include security officer.
Rather than driving the industry forward with leadership and vision Microsoft is being driven by AI and Advertising fads that are self destructing facebook and google.
Its clear its too late for Microsoft to do anything but lose trust at this point. If the outlook hacks and US government didnt cause them to rethink these terrible anti-privacy ideas then a bit of AI backlash won't either. As soon as people look away they'll start stuffing the OS with snoopware again.
Linux is great. It was initially concerning to migrate but overall I'm happy I did. I assume Microsoft will attempt to make things more incompatible and proprietary as a last chance attempt to hold onto users. Ultimate this will just lead to more people switching to Linux faster over time.
According to Microsoft whistleblower Andrew Harris, Microsoft spent years ignoring a vulnerability while he proposed fixes to the "security nightmare." Instead, Microsoft feared it might lose its government contract by warning about the bug and allegedly downplayed the problem, choosing profits over security, ProPublica reported.
And this is exactly the problem. You STILL cannot trust them, fool me once, fool me twice?
This entire "weeewweeee sowwwyyy" bullshit excuse completely ignored the fact that they purposefully allowed the US government to be attacked because money is their bottom line. If it were a person (and aren't companies persons now in the US?) they would have been jailed for treason. Jail these assholes already and switch ALL your computers to Linux
This is like that psychopath GF that lies and pushes you around to test your limits with the evil plan to manipulate you. Every once in a while you can complain about her behavior and then she will bombard you with fake love and forgiveness to push later in the future again.
Look at this smug assholes face. He knows damn well they won't be doing anything of the sort unless it increases their profit margins. And he also knows damn well the government won't do anything to seriously hinder their margins.
Bread and circuses. This is just another show. You want change? Stop using Microsoft. Period.
Why in the absolute fuuuuuck would a "secure" computer with sensitive data be running motherfucking Windows?! Linux is easy enough for pretty much any Windows user in an office environment to handle these days. There's just no excuse for sensitive business to ever be done on Windows at this point.
The company I work at "supports" Linux in the sense that you're allowed to use Linux but then you're essentially on your own when it comes to solving problems. I asked why there's no proper Linux support and the short answer was "it's too much trouble". The long answer was "don't ask. I don't want to get into it".
So my guess is that setting up company wide policies and support for Linux is significantly more work than it is for Windows or Mac.
They legally can't prioritize shit but shareholder profits. We are all about to watch a US based company, purposefully fuck over the US government and possibly us by extension, and nothing will happen. Fuck this oligarchy.
Oh, shit haha! I thought you were serious for a second. Can you imagine if we ever held a corporation accountable for the damage they've caused? I mean it obviously can't happen, but wow! You had me for a second!
Question is: For how long? Security costs money, AI brings profits (in several ways).
At the moment they are making a big production of caring for the user. Which they basically never did, actually. They are only as pro user as they have to to improve their profits. Just wait until the shareholders reign them in because they want the company to extract more money out of the customersvictims.
Rough month for reflection at M$. Possibly finally took it too far with users via Recall and - quite a feat here - showed Microsoft in a negative light for another big solidified base in government.
I hope MS can fulfill its promise and not abandon it like they did with Surface RT, Windows Mobile, Windows Phone 7, Lumia, Kinect, Xbox, MSN Messenger, Cortana, Tango Studio, “Windows 10 is MS’s last OS”, etc.
So we start...click on the paint brush icon...that tiny colourful thing right under the big ass "W" Icon. Now hit agree on the window asking if you're secure. Wait a few moments and agree you your 2FA app on your phone. You might have to ask your wife to agree if you are married and bought the license for your spouse only. Cheapskate! Now stay here for a few minutes, we've called the 🚓🚨 police.
Things like this that make me wish we still had the pillory punishment.
Look at his smug little smile. He knows they are not going to do shit. The smile would fade quickly if he faced 6 hours locked up being pelted with rotting vegetables and fruit in 90° heat.