9 ms·
> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees
by minisooftwin 2y ago
> “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the company’s CEO, Satya Nadella, told employees.
Satya's model of making security a priority at Microsoft:
- Cram ads in every nook and corner of Windows. Left, right, centre, back, front, everywhere. What else is an operating system for?
- Install a recorder which records everything you do. For the benefit of users of course - you know, what if a user missed an ad and wants to go back and see what they missed.
- Send a mail to your employees and tell them "Do security". Mission accomplished - Microsoft is now the most secure platform.
- VyseofArcadia 2y agoThe Microsoft bribes scandal broke not too long after I had to take the "hey don't do bribes" training at Microsoft. That event really drove home for me the fact that all of the trainings, emails, processes, etc. are mostly plausible deniability. There are people who care about security at MS. I know, I've met them, but for the most part all of this exists so that Satya can plausibly say in court or in front of congress, "well we told them to do security better. This is clearly the fault of product teams or individual contributors, not Microsoft policy and incentives."
- montjoy 2y agoI dunno, that’s a pretty cynical take. Isn’t it just as plausible that they became aware of the bribes internally and were trying to curtail them when the scandal broke out? Or maybe the “don’t do bribes” training actually worked enough for someone to whistleblow even if official internal channels failed? Those who are doing wrong often try to stymie others from making positive changes out of fear, greed, etc. Edit: I just want to add that there are things to be cynical about - I’m not completely naive. If it’s your legal department heading up the training then you can be pretty sure that there was a cause for it.
- blowski 2y agoYes, massive companies are a nest of conflicting priorities. The sales team wants to do whatever it takes to win the deal, and the legal team wants everyone to behave ethically at all times. The board wants to be shocked(!) when it turns out those goals are in conflict, with the ethical side sometimes losing out, to remove any personal risk to themselves.
- mistrial9 2y ago> legal team wants everyone to behave ethically at all times do you really believe that? compliance under scrutiny, more like it
- johnnyanmac 2y agoThe best job is sitting around and doing nothing. So ideally yes. But sure, ethically speaking when things get heated they will exploit every loophole they can find to avoid liability. So, lawful evil?
- sophacles 2y ago> The best job is sitting around and doing nothing. That sounds like a terrible job.
- johnnyanmac 2y agoWell you can take it as literally or figuratively as you wish. Depends on the person.
- mmcdermott 2y agoMost corporate law guidance is about risk mitigation, not about ethics. Less activity generally translates to less risk. You can see a similar phenomenon with security professionals. True, the only secure computer is one disconnected from the Internet, turned off, put in a Faraday cage, on the moon, under armed guard - but that's not useful.
- zxxh 2y ago[dead]
- lupusreal 2y agoThat doesn't seem plausible, because you can't stop bribery by telling people that bribery is against the rules. Everybody already knows that. If they became aware of bribery and genuinely wanted to stop it, the way is to publicly punish the culprits as harshly as they can, to demonstrate to others that enforcement of the rules can happen.
- ein0p 2y agoYes and no. You might not even realize that what you did constitutes giving or receiving a bribe. What cracks me up though is that all large US megacorps give tens of millions of dollars in thinly veiled bribes to officials each year, as they browbeat their employees into not accepting a god damn fruit basket from a thankful client.
- creaghpatr 2y agoProbably neither, "don't do bribes" training is standard onboarding procedure at any Fortune 500 company. Just ironic timing from OPs POV
- ein0p 2y agoNot just onboarding. Most, if not all, large companies waste at least an hour of their employees time on this per year, while themselves bribing politicians in DC.
- VyseofArcadia 2y agoIt was, in fact, a story arc in an at the time recent-ish season of SBC[0]. [0] Microsoft's yearly training that is done in the form of a TV drama about MS employees facing ethical dilemmas
- Arrath 2y agoAn hour? My annual training is typically about 6 hours of drudgery, and often about 2/3rds repeat courses from years previous. Great fun.
- NordSteve 2y agoThat's just the ethics training, depending on your role there's much more than that.
- tialaramex 2y agoBut this is exactly why it's standard procedure. I worked for a huge Credit Reference Agency and it was very obvious that this is ass covering. Sarah and Bob in the New York Office of Huge Corp must take the training so that the CEO can swear all his employees know not to bribe people. In the event that Manuel, who is given $100 000 per week of company money to bribe the locals in Melonistan so that they don't interfere with Huge Corp's operations is actually brought before the government and forced to spill the beans the CEO will insist they had no idea and some Huge Corp minion gets sacrificed. Manuel will be replaced, Melonistan will be assured quietly that his replacement will provide make up money ASAP. In Arms this is even worse, because there it's secretly government policy to bribe people, even though it's also illegal. So then sometimes even if you can prove there was a crime, the government will say "We'll take that evidence thank you very much" and poof, the crime disappears, if you make too much fuss you'll be made to disappear too.
- giobox 2y agoMaybe. However such training is essentially considered mandatory compliance at any publicly traded company once you reach a certain size, especially if you sell to the government, and IMO probably not related to any specific event they became aware of. I've had to do the same mandatory anti-bribing public officials training annually at US companies a fraction the size of Microsoft. The anti-bribe training is so common at large companies in the US, there are companies that sell ready made one-size-fits-all training videos specifically on this topic that are then usually the thing the employee has to sit through anually. In my experience, different cultures have different feelings on the moral failings of bribes. Some of my colleagues grew up in countries where it is a common business practice, it probably makes sense for large orgs with global employee base to have to establish some kind of baseline for acceptable business practices. Similarly, I know several people who came to study computer science in the US and tried to bribe police officers upon being pulled over for speeding, simply because it's how you handle the matter where they grew up.
- ClumsyPilot 2y ago> dunno, that’s a pretty cynical take Just days ago a major US corporation was found guilty of hiring Death Squads in Columbia. Literally to murder people. Why do we have this common illusions that corporation will not steep down to the dirtiest crimes they can get away with? https://www.bbc.com/news/articles/c6pprpd3x96o https://www.bbc.com/news/articles/c6pprpd3x96o
- mmierz 2y agoThe article you linked says that Chiquita was extorted into illegally paying money to a Colombian death squad, who also murdered people, and were ordered to pay restitution to the victims' families. It doesn't say that they paid the death squad to murder people on Chiquita's behalf.
- pjmlp 2y agoYes, hence why I take all those company values trainings as Bull******.
- doe_eyes 2y agoEh. For the most part, the trainings can be taken at face value. Even if the management's dealings with governments and partners are questionable, no company wants random employees accepting personal kickbacks from vendors. There's a liability avoidance component to trainings, but mostly for non-business misconduct. For example, for sexual harassment, the company will say they tried everything they could to explain to employees that this is not OK, and the perpetrator alone should be financially liable for what happened. That defense is a lot less useful in business dealings where the company benefits, though.
- tptacek 2y agoMicrosoft has for over two decades been one of the largest and most sophisticated employers of security talent in the industry, and for a run of about 8 years probably singlehandedly created the market for vulnerability research by contracting out to vulnerability research vendors. Leadership at Microsoft is different today than when the process of Microsoft's security maturation took place, but I'll note that through that whole time nerd message boards relentless accused them of being performative and naive about security.
- VyseofArcadia 2y agoIt would help if there weren't all these employees and ex-employees stepping forward to talk about how Microsoft is performative and naive about security. I won't go as far as to say that, but I will say I don't think my incentives as an IC lined up with the security-focused mindset that company execs tout publicly.
- tptacek 2y agoI don't think anything is going to help here; it's just a message board fixity that companies like Microsoft are unserious about security.
- bayindirh 2y agoSame Microsoft got their master authentication secret stolen and they still don't know how that happened. It's also turned out that it's impossible to revoke or cycle that secret. The whole issue is so hushed now, I don't know what happened at the end. Same Microsoft one of their license golden keys on some installation media, too. Even if they're serious about security, these events don't look good.
- tptacek 2y agoI don't know what "looks good" means. Every major tech company has had multiple bad things happen that would look very bad to people on message board.
- solatic 2y agoTo be fair, it's not really possible to come up with good policy to handle this at scale. It would be too intrusive to require employees to divulge their private financial accounts (and near impossible to audit that the employee has truly divulged all their financial accounts), and the more internal controls you put in place, the slower the deal-making gets, with no guarantee of good behavior.
- coffeemug 2y agoAt higher levels compensation is now tied to security outcomes. This is as committed as it gets. Definitely not theater.
- tomrod 2y agoIt will still be theater. Security outcomes will be gamed.
- deleted 2y ago[deleted]
- _heimdall 2y agoTo be fair to Satya, every leader should be judged on what they do not what they say. This isn't a Microsoft or Satya problem, pick a large corporstion and you'll find examples of this behavior everywhere. Words in an email hold absolutely no weight, when leaders choose to trade security for something else that's all employees need to know.
- progmetaldev 2y agoIn particular when you need to answer to shareholders and can be voted out of your position/company. I don't pretend that Microsoft's past hasn't been an issue, but if we compare the past to present, Satya has had somewhat of a positive impact (although know there's a lot behind the scenes that I'll never know about, as well as most). It's good to be critical of every company, otherwise the end users get rolled over.
- tombert 2y agoI have no broad evidence of this, but I suspect that the more beginner-friendly Linuxes are guilty of a lot of the sins that you laid out here. I seem to remember some controversy with Canonical recording your searches when hitting the super key, and Ubuntu having Amazon ads built in by default. People who love to geek out about computers can of course install Arch or Gentoo or NixOS Minimal and then audit the packages that they're installing to see that there's no obvious security violations, but it's unrealistic to think that most non-software-engineer people are going to do that. I really don't know how to fix this problem; there will always be an incentive for Microsoft (and every other company) to plaster as many ads as they think that can get away with, as well as collecting as much data as possible. I don't know that I would support regulation on this, but I don't know what else could be done.
- lupusreal 2y agoDebian is a perfectly reasonable choice for casual linux users. Ubuntu's supposed usability improvements over Debian are greatly exaggerated. It's mostly just marketting.
- tombert 2y agoFair enough. I haven't used Debian in quite awhile (I think since 2009 or so?), so I can't speak to current stuff, but I do remember it being pretty hard to install then. I'm sure they have refined it considerably since then, and of course I am fifteen years more experienced now than I was. Personally it's hard for me to go back after I accepted the dogma of NixOS, but maybe if I manage to talk my parents into using Linux I'll install Debian for them.
- 1oooqooq 2y agoinstall arch. not even kiding. make a "shutdown" button on the desktop that locks everything and do a full upgrade. any issue is solved with, try tomorrow after a reboot. you'd be surprised how fast fixes arrive at rolling distros
- HumblyTossed 2y agoSay one thing, do another.
- akira2501 2y ago> you know, what if a user missed an ad and wants to go back and see what they missed I have meetings with adtech guys and this gets pitched every time. Along with "a way to save ads so you can watch them again at home later!" And "alexa enable ads that you can talk to!"
- naikrovek 2y agoSheesh you guys are annoying. - I do not see ads in “every nook and corner of Windows” and neither do you. - I do not have a recorder installed on my Windows machines and neither do you. - no one qualified to make that statement has said that Microsoft is the most secure platform. It is so hard to listen to anyone who exaggerates at this level. If anything, it drives interest in Microsoft because these are all obviously false statements and some readers will wonder what your true motive is. You just raise suspicion in yourself. At least you used a new account to distance yourself from any other identities you may have here. In fact I would say that was the only smart move in your entire comment. Anyway, this is a damning revelation by the whistleblower and I hope Microsoft feels a good amount of pain because of it. NEVER make any decision with money as your sole input. It will always be a bad decision, and it’s just a matter of time until that decision bites you or someone you care about.
- throwaway610 2y agoHey Jer, please review the CELA policy about disclosing your employment connection to Microsoft.
- naikrovek 2y agoI don’t work for Microsoft, and I never have.
- josefresco 2y agoYou're getting downvoted for your tone most likely, but I agree with this statement: > - I do not see ads in “every nook and corner of Windows” and neither do you. As a professional "Windows user" logging 8+ hours a day on my PC, I see no ads. Unless you count "OneDrive" ads which in that case, would mean I see iCloud ads on my iPhone too. I'm fine with classifying these as ads, but I'm certainly not seeing them "in every nook". Are these ads only bundled with a certain versions of Windows? Disclaimer: I do not work for Microsoft or Apple.
- josephcsible 2y ago
- dtdynasty 2y agoFrom my experience in big tech they would be categorized as privacy concerns not security. Might just be different conceptual models here.
- _trampeltier 2y agoAbout an ad missed. Are I'm the only one who would rewatch an ad on Youtube? There is no easy way to do it
- BenFranklin100 2y agoI agree Microsoft is a problem. I just wish you tech guys took an equally critical stance towards Google, a genuine ad company.
- gigel82 2y agoAnd Apple, the upstart ("stealth mode") ad company.
- BenFranklin100 2y agoThe upstart ad company that spent years and tens of billions of dollars to develop a privacy focused AI in the cloud platform? The same upstart that offers encrypted cloud storage that even it can’t decrypt? Congrats on the false equivalency argument. Guys like you do yourself a disservice. No one takes your hyperbolic statements seriously. Keep posting this nonsense if it makes you feel better.
- gigel82 2y agoIt's not hyperbolic, I genuinely believe (and there is plenty of evidence suggesting it as well) that Apple is building a massive ad empire. BTW, related to all their "encrypted" cloud, if the CCP having the decryption key is not enough to convince you of the BS, they also clearly showed their hand a couple years back when they wanted to introduce local on-device scanning of customers' pictures and comparing against an opaque database of hashes produced by nameless government-connected entities, including uploading the unencrypted pictures for review by humans who'd later send them to authorities. It took massive uproar to change that direction (but not before the same Craig guy who's now talking about the "private cloud" took his time to educate us "screeching minority" about how we misunderstood the thing - e.g. "you're holding it wrong"). So yes, they have amazing PR, but they're just as bad (if not worse) than the likes of Microsoft and Google.
- fsflover 2y ago1. https://appleinsider.com/articles/24/04/10/apple-makes-it-really-hard-for-users-to-completely-stop-it-from-collecting-data https://appleinsider.com/articles/24/04/10/apple-makes-it-re... 2. https://sneak.berlin/20231005/apple-operating-system-surveillance/ https://sneak.berlin/20231005/apple-operating-system-surveil... 3. https://news.ycombinator.com/item?id=34299433 https://news.ycombinator.com/item?id=34299433
- whartung 2y ago> you know, what if a user missed an ad and wants to go back and see what they missed. Unrelated, and maybe this actually exists, but with the rise of LED billboards, there have been more than one occasion where a billboard was displaying something and it cycled too fast, or the print was too small. I would actually be interested in visiting the billboards website that lets me click on the geographical billboard location and show me what it’s been showing.