Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wasn’t Microsoft just recently using Chinese people living in China to administer DOD servers? I would guess they use Sharepoint inside the DOD?


Says this in the article:

> A programming flaw in its cloud services also allowed China-backed hackers to steal email from federal officials. On Friday, Microsoft said it would stop using China-based engineers to support Defense Department cloud-computing programs after a report by investigative outlet ProPublica revealed the practice, prompting Defense Secretary Pete Hegseth to order a review of Pentagon cloud deals.


Absolutely insane. Especially in light of their layoffs. Should be criminal. According to another comment in the thread, it is?


Microsoft only has a market cap if 3.7 trillion. They can't afford to hire domestically.

Anyway, from what I can tell being in this industry, a lot of things need to be explicitly illegal to stop companies from doing it.

Edit: The penalities also have to be meaningful. There's a lot of "technically not legal, but sue us lol" going on.

"Hey, this is a really really stupid idea." Isn't going to stop a middle manager from trying to come in under budget.

At most MS will pay a nominal fine, and proceed to learn nothing.


> "Hey, this is a really really stupid idea." Isn't going to stop a middle manager from trying to come in under budget.

Neither is "you can go to jail" when it comes to export controls training


Maybe instead of fines, large companies should be forbidden to do any new contracts for some months. That would be a larger incentive and also comprehensible to sales people.


In which magical country do you suspect this would be enforced ?

Microsoft also has a captive market here. Realistically you aren't going to migrate millions of employees and servers to another tech stack, even over something egregiously bad.

Something like storing cleared data really should be handled 100% internally with an open source stack that's regularly audited.

But that sounds really difficult, even if it would be cheaper or the same price in the long run.


One can dream.

I didn't suggested preventing the fulfillment of existing contracts. Nobody would change for all costumers. They just wouldn't get any new contractors.

Sanctions already exist.


Ok.

So after the current contract do you switch stacks, or just have a 3rd partner Microsoft shop maintain your existing stack?

Regardless, I don't think our current legal system has any real ability to hold a company like Microsoft accountable.


If you happen to be unlucky and Microsoft just got convicted, you either need to wait some months or go to a competitor. The state shouldn't care about that, when your mechanic just went to prison, what you're gonna do?

But yeah I don't know any party who has such ideas.


Excuse me??



That is... crazy.

Would the CCP allow their cloud infra to be administrated by US staff in the US? Never.


The US doesn't either. Someone didn't comply with existing law here. I've been on a program where uncleared people from another business unit were used as internal labor loan for export controlled work. One of them was belatedly discovered to be a Canadian citizen and they were retasked the next day. There are strict rules in this domain. It's just that nobody gives a fuck about paying for an IT cost center to do things securely. Chalk up another win for outsourcing and moving to the cloud for cost savings.


There is a DoD version of M365 which has SPO, but that isn't what the article is discussing.


Revert to the typewriters for security





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: