3 ms·
Yesterday ProPublica and ArsTechnica published a takedown of Azure: "Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway" ... h
by throwoutway 7mo ago
Yesterday ProPublica and ArsTechnica published a takedown of Azure: "Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway" ...
https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/ https://arstechnica.com/information-technology/2026/03/feder...
- charles_f 7mo agoIn which one expert called the documentation provided "a pile of shit", which propublica took the liberty of extending to Azure itself
- hsbauauvhabzb 7mo agoAnd they weren’t wrong
- bulbar 7mo agoThey still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that. I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.
- hsbauauvhabzb 7mo agoIf a slop engine calls a slop company slop, has anyone really lost?
- lostmsu 7mo agoWe lost, for one of us got tricked to bring it here.
- bigfatkitten 7mo agoIn this case, it’s just yet another design-level vulnerability in Microsoft cloud’s services. There isn’t much room for nuance.
- benterix 7mo agoIt's true, they lied. But, paradoxically, in this case, while they lied about details, the conclusion is still true: Azure is very far from AWS and GCP as far as security is concerned. I have my own suspicions why it is so, but the reasons are not important, what counts is the final conclusion: if you really care for security, you'd better chose one of the other two.
- twoodfin 7mo ago“Fake but accurate.” ProPublica has an agenda, and they slant their reporting to push it. You can like their agenda and support this effort, but it’s not journalism.
- toomuchtodo 7mo agoWhat is their agenda?
- twoodfin 7mo agoCompare 600+ stories tagged for the Trump administration: https://www.propublica.org/topics/trump-administration https://www.propublica.org/topics/trump-administration …with 16(!!) since 2020 on Biden’s term: https://www.propublica.org/topics/biden-administration https://www.propublica.org/topics/biden-administration My favorite missing Biden story that should have been right in their wheelhouse: The unprecedented $36 billion bailout of the Teamsters’ pension fund. https://www.statesman.com/story/news/politics/politifact/2022/12/15/kevin-brady-biden-teamsters-bailout-private-pension-politifact/69729204007/ https://www.statesman.com/story/news/politics/politifact/202...
- toomuchtodo 7mo agoWell, yeah, their agenda is reporting on fraud and illegal actions. If you do more fraud or illegal actions, you will have more stories about you. Trump does more fraud and illegal actions, objectively. If you’re a Trump supporter, reality may make you sad and angry when in conflict with the mental model. I don’t mind pension bailouts, compared to tax cuts for the very wealthy and unnecessary military action in the Middle East (which has cost ~$50B as of this comment). Compare the costs.
- rithdmc 7mo agoTitles are editorialised and space limited. The first couple lines in the article linked above make the nuance pretty clear. [edit: 'pretty' instead of 'perfectly']
- panzagl 7mo agoIn those types of reviews/audits, documentation is the first indicator of whether a security organization has their act together. It's about building a trust relationship between the accreditor and contractor that will have to endure for years, as nation-state level actors throw their resources at finding vulnerabilities. MS couldn't do this or couldn't be bothered to do this. So shit documentation -> shit security processes and operations -> shit security -> shit cloud product in a government context. So the title wasn't that much of a stretch.
- int0x29 7mo agoArs just republished it under license
- DetroitThrow 7mo agoEvery security engineer I know working at Azure is on the verge of self-harm because of the current situation, or is the dumbest IC I've ever met and somebody I think should have never become a security engineer. Sample size ~12.
- jacquesm 7mo agoThat is quite the indictment.
- DetroitThrow 7mo agoI am not very close with every one of these engineers, and some no longer work at MSFT, but yes talking to employees in Seattle working on security made me never want to use Azure.
- bigfatkitten 7mo agoLast I heard, the CO+I org has some pretty serious cultural problems that contribute to this, and which will not be easily solved.
- g-b-r 7mo agoBloomberg and CNBC don't seem to have reported about this, maybe someone with contacts could make them aware?