3 ms·
Is it Nelson again with his shenanigans? For reference: https://www.wsj.com/articles/microsoft-employees-are-hooked-on-the-companys-training-videos-c8684a1 htt
by speps 2y ago
Is it Nelson again with his shenanigans?
For reference: https://www.wsj.com/articles/microsoft-employees-are-hooked-on-the-companys-training-videos-c8684a1 https://www.wsj.com/articles/microsoft-employees-are-hooked-...
- alternatex 2y agoSecurity trainings just that, trainings. Some teams and even EMs don't pay enough attention to actually following them. Also, in many orgs within Microsoft there's a lot of legacy setup that was there before the trainings or before the org became a part of Microsoft and sometimes there is no capacity within the teams to address/fix this legacy setup. And if they're unlucky enough, someone will exploit it. In some of the orgs and products there are zero career incentives for addressing legacy setups and there are big incentives for pushing out new features and initiatives. I've never heard of anyone being promoted for driving an initiative to fix obscure technical debt like this. It's a systemic issue that won't be resolved with security trainings.
- AtlasBarfed 2y agoBecause corporate security is about "compliance" and "training", not solutions. Awareness is one weapon, but really security is so technically complex to do well is that security needs to offer good solutions. Think of it like a GPT prompt: "give me a test harness for user profiles" "give me a secure login process" "give me a SSO service" Instead security groups want to "review"/"approve" which is just shitty compliance overhead. Because of course they don't want to be the ones to blame for bad security code. They want their compliance review checkbox, and everything else was the "evil rogue programmer/hacker" to blame. And alas, the security people I've seen in large corporations I've worked at have been almost morons. Internal support portals for enterprise passwords? Dumb password rotation rules, 6-8 character limits, and chrome complaining about obsolete ssl suite usages. Degrees from specious Florida universities that mostly seem to be about tuition collection and beach access than actual academics. Asking them about major breaches and the technical basis of them and getting blank stares. No idea what the vaunted Amazon or Microsoft do, hopefully it is better. Amazon abuses its employees, so that opens them to a rich array of social attacks and leaking, in addition to the high probability that Amazon farms its customers for business strategy. Microsoft has always been about monopolistic sociopathy trumping technical concern. Cloud providers are a high customer support business and it is resoundingly obvious that Amazon and Microsoft view those in as high regard as most SV organizations and really all corps in general: low paid and overworked, if any. Corporate management will only invest in things they see are worth the reduction in managerial bonus payout, kinda shareholder value, kinda risk reduction (at least within the period of time their stock grants are active). There's really no good aligned incentive, just like environmentalism because it is an unquantifiable risk to the great religion of economics and finance, and therefore doesn't exist.
- jabroni_salad 2y ago>"give me a test harness for user profiles" "give me a secure login process" "give me a SSO service" > Internal support portals for enterprise passwords? Dumb password rotation rules, 6-8 character limits, and chrome complaining about obsolete ssl suite usages. I'm curious as to why these would require some outside security group to deal with? These all seem like issues that should be solved either by someone in the devops category. Update your dependencies, disable unused protocols, have a QA guy find your improper memory glitches, and now 99% of the security establishment is irrelevant to you. These are operational issues. Most security issues are just operational issues.
- darknavi 2y agoMicrosoft employee here and I actually really enjoy the standards of business training. Generally I find that I mirror the effort I put into training to the effort the creators put in. If a training is just 20 slides of text to speech, I will put that on 2x on a background thread. If the training is a well-produced video series I'll watch the full thing at normal speed.
- sergiomattei 2y agoApparently people do watch parties for Trust Code around these parts!