4 ms·
Funny how I've heard from an Azure employee who worked with many big clients that very few among them cared about security - the incentives were just not there.
by dinvlad 2y ago
Funny how I've heard from an Azure employee who worked with many big clients that very few among them cared about security - the incentives were just not there.
Seems like they're finally doing something about that, to set an example for the rest of the industry.
- magicalhippo 2y agoWe're getting drowned by security checklist by clients now. A lot of them don't make much sense for us, we primarily make a Win32 B2B program hosted by these customers themselves and a lot of the checklists are all about more generic web SaaS things (because we charge like SaaS). But the person on the other end wants all the questions answered regardless. Seems that as long as you can put a checkmark in a box that you follow various "best practices" and whatnot, actual details don't matter. You put a checkmark in a box, you did your best.
- Atotalnoob 2y agoThis is basically what I have experienced. My current place, there are developers still using like node 10 and other ancient software, but god forbid you not fill out a checklist.
- kstrauser 2y agoFrom being on the buying side, it's likely that the person sending you that questionnaire knows a lot of it is irrelevant to your situation, but they're personally reviewing 100 vendors this year (no, seriously) and there aren't enough hours in the week for them to make exceptions for everyone. Very often the best answer would be like: > Q: Do you use multi-tenant databases? > A: N/A: you'll be deploying our product on your own server. That's actually a perfectly fine answer! The person reading it doesn't have to explain large gaps in the answers to their boss. It documents why this isn't relevant in a way their successor can easily understand next year when they're reviewing those 100 vendors as part of their annual Vendor Management Policy™ process.
- Terr_ 2y agoSometimes it feels like: "Which controls exist for medical data?" "Sir, this is a Wendy's™ app."
- kstrauser 2y agoI get it! I’ve been on both sides of that table many times. If you see the same questions over and over and over again, consider filling out a SIG LITE questionnaire and offering that to buyers from the start. If you can give them all or most of the info they need in a common format, you might be able to head off a lot of follow-up questions.
- delusional 2y agoYou can write whatever you want. Nobody is ever looking at that document again. By the time the annual process rolls around the process has already changed so much that it's now insufficient. The mandate from management will be to "do it right for future vendors, but blanket approve the previously signed agreements" It's the same thing every time because the actual security is in the details, but details are so fucking boring.
- dinvlad 2y agoFWIW from my own experience with auditors, the process is really kind of superficial. Yes, they can identify the most common checklist-based gaps, and that's what tends to be the low-hanging fruit for attackers as well. But they would never go deep enough to identify something that a determined attacker could exploit.
- dinvlad 2y agoYep, it's all about checkmarks now :-)
- kstrauser 2y agoI doubt that's the case. I've been working in/near enterprise sales for quite a while now. Security is considered unglamorous table-stakes: companies won't buy your stuff because you're doing all the right things, but they'll definitely not buy your stuff if you're not. Giant products like AWS and Azure are too big to grill about their security controls. If you try to ask an AWS rep about something, they'll direct you to their security portal where you can download a SOC2 report and a few other things. That's about all you'll get from them unless you're equally huge. The most you can really go by is their reputation. If you trust AWS, buy their product. If you don't, don't. That's all the prior research a typical < 10,000 employee business can possibly do. My suspicion is that your friend is only talking to clients who've vetted Azure and figured "it's Microsoft: they're big so they probably know more about it than I do". It's not that they don't care. It's that there's nothing they can do about it. The people who don't already trust Azure would never have gotten as far as talking to your friend in the first place.
- cjk2 2y agoIt's not even that. Everyone has someone else to blame now so they give less of a shit about being accountable for picking a platform provider.
- dinvlad 2y agoIn principle, it's always been about "shared responsibility principle". But in practice, yes many clients probably assume that by running in the cloud, they're "secure" (thus, failing their end of the bargain).
- MichaelZuo 2y agoYou can also just pay more for their HIPAA compliant offerings, which stand a very good chance of having decent security?
- voidfunc 2y agoIt really depends on the Team. Trying to broad stroke anything about Microsoft engineering is impossible because it's a patchwork of business units and teams that rarely communicate and work together unless forced. Some Teams are very visible and have top talent on them that prioritize and think about security. Some services do not... problem is security is very much a "you're only as strong as your weakest link" kinda thing. This is a step in the right direction to get the top-layer prioritizing security.
- beoberha 2y agoCouldn’t agree more. I can’t emphasize enough how BIG Microsoft is and how many dimensions of security there are. Nobody has as many attack vectors as we do. I’m pretty confident in saying that. It’s a super hard problem and nearly impossible to enforce all of them from an organizational standpoint. But this is a great step in trying to do so.
- dinvlad 2y agoThat's true - he was talking about clients though, if my memory serves well. The main challenge he highlighted is there're no financial incentives for most companies in the industry to stay secure (unless you're a security company) - the punishment (including reputational risk) is just way too small.
- beefnugs 2y agoHow could you possibly secure anything when the other half of the company is shoving ads into the start menu and implementing "ai search" to record every keystroke and screen text into perpetuity? Even the good people at microsoft will forever be undermined by this shit, complete demoralization and throwing their hands up to doing anything properly