7 ms·
“I want to note our appreciation for the reporting of the Guardian,” [Microsoft’s vice-chair and president, Brad Smith] wrote, noting that it had brought to lig
by codeulike 1y ago
“I want to note our appreciation for the reporting of the Guardian,” [Microsoft’s vice-chair and president, Brad Smith] wrote, noting that it had brought to light “information we could not access in light of our customer privacy commitments”. He added: “Our review is ongoing.”
Its interesting that they seem to be saying they dont know the full details of how their customers are using Azure, due to privacy commitments.
- AnonymousPlanet 1y agoIt could also mean "now that someone else has seen it, we can finally act on what we have only privately seen but couldn't admit seeing"
- scuff3d 1y agoMore likely MS was well aware of what was going on and didn't care until the Guardian forced their hand.
- ms7m 1y ago> The disclosures caused alarm among senior Microsoft executives, sparking concerns that some of its Israel-based employees may not have been fully transparent about their knowledge of how Unit 8200 used Azure when questioned as part of the review. Highly likely, or at least a bit naive -- Completely reasonable to have local staff for a contract this big, but Microsoft should have independently 'double-checked' sooner
- scuff3d 1y agoThe head of that Israeli unit met directly with the CEO of MS. I don't buy a second the execs at MS didn't know what was going on. Blaming the local contractors is just MS throwing people under the bus. I've worked for big corporations for nearly 20 years, I've seen this more times then I can count. Higher ups always happy to turn a blind eye to a bad situation as long as it's making the company money, and then immediately throwing subordinates under the bus when it bites them in the ass.
- AlfredBarnes 1y agoA tale as old as time.
- lazide 1y agoIf they weren’t intended to be thrown under the bus, they’d be called… superordinates? I guess?
- lazide 1y ago‘I’m shocked! shocked! that there is gambling in this establishment! This is unacceptable!’ ‘Your winnings sir’
- williamdclt 1y agoI don't know if it's _true_, but it seems right? I don't want Microsoft to have this level of visibility into my usage of Azure, just like I don't want my phone provider to eavesdrop on my conversations. I'm no privacy ayatollah, but this seems like a reasonable amount of privacy from Microsoft
- ngcazz 1y agoWell, the average org isn't out there literally committing genocide
- dotancohen 1y ago[flagged]
- buellerbueller 1y agoThe UN says differently. Should I just take Israel's word for it?
- dotancohen 1y ago[flagged]
- madaxe_again 1y agoPrivacy ayatollah? Is that like an infosec shah?
- Etheryte 1y agoThe whole point of confidential computing is that the cloud provider can't access your data and can't tell what you're doing with it. This is a must have requirement in many government contracts and other highly legislated fields.
- IlikeKitties 1y agoI've personally never seen anything requiring confidential computing in anything. Is this required in the USA? I find that hard to believe, because the technology on a cloud level is still very beta-feeling. I think that Microsoft just never looked because they did not want to know.
- hnlmorg 1y agoThey have services literally dedicated to things like health data records. But you don’t even need to go that sensitive, literally any type of online service might run the risk of handling PII. Which is why CIS, NIST et al have security frameworks that cover things like encryption at rest.
- IlikeKitties 1y agoBut encryption at rest is not confidential compute. And Confidential compute is pretty new in terms of tech and i would be genuinely suprised if it's already required for some stuff. I am genuinely interested though, if you have any links about it please enlighten me.
- hnlmorg 1y agoAhhh I hadn’t realised that was a new term. I’ve got something new to learn. Thank you
- jiggawatts 1y agohttps://learn.microsoft.com/en-us/azure/confidential-computing/ https://learn.microsoft.com/en-us/azure/confidential-computi...
- braiamp 1y agoThat comment is... weird, considering they disabled the accounts of certain International Court of Justice that were individually targeted.
- lazide 1y agoThe reality is that no one can tell whose ass it is safe to kiss now a days, so it’s all scandal driven actions. Unless someone can create a big enough scandal, no one is going to do squat.
- covercash 1y agoWeird, pretty sure employees brought this to their attention a few times already… https://apnews.com/article/microsoft-azure-gaza-palestine-israel-8820200cec5996987d49fbb669322b22 https://apnews.com/article/microsoft-azure-gaza-palestine-is... https://apnews.com/article/microsoft-azure-gaza-israel-protests-49a0dd5905a1cf16eb3e19a98ca17d50 https://apnews.com/article/microsoft-azure-gaza-israel-prote... https://apnews.com/article/microsoft-build-israel-gaza-protest-worker-fired-a395ac137b74002886b2ad727b5ae5c2 https://apnews.com/article/microsoft-build-israel-gaza-prote... https://apnews.com/article/microsoft-protest-employees-fired-israel-gaza-50th-anniversary-c5b3715fa1800450b8d0f639b492495e https://apnews.com/article/microsoft-protest-employees-fired...
- cl0ckt0wer 1y agoIf they act on information their employees report, they are violating their commitments.
- sc68cal 1y agoThere have been public reports by major news organizations on the subject of Israel using big tech companies to surveil the West Bank and Gaza, for a decade. This isn't an issue of customer privacy.
- meowface 1y agoThe difference is that pre-2023 it could at least have some plausible excuse of trying to detect terrorist activity. With Israel's current actions in Gaza, there is no longer any plausible excuse or defense for any security action Israel is conducting towards Palestinians.
- deleted 1y ago[deleted]
- Aarostotle 1y agoDid something happen in 2023 that makes it _less_ relevant for Israel to try to prevent terrorist activity?
- kevin_thibedeau 1y agoThey should ask their Chinese engineers in charge of sensitive Azure servers.
- filoleg 1y agoThat’s the best part, they cannot. Well, they technically can, but the answer from the company that runs chinese azure servers is gonna be “none of your business.”
- slt2021 1y agoJIDF and Unit 8200 have infiltrated a lot of US tech companies. This is a very significant issue for American tech companies, they either need to restore the trust of global customers, or they will lose it completely.
- nashashmi 1y agoWhat is interesting is they gave some privacy while others they strip away.