news.volyx.in

Microsoft Chose Profit over Security, Whistleblower Says (propublica.org)

676 points by tyleroconnell · 791 days ago · 305 comments on HN

Article summary

A whistleblower, a former Microsoft employee, claims that the company prioritized profit over security, ignoring his warnings about a critical flaw in one of its products, which was later exploited by Russian hackers in a major cyberattack. The flaw, discovered in 2016, allowed attackers to masquerade as legitimate employees and access sensitive data without tripping alarms. Microsoft allegedly dismissed the warnings to avoid jeopardizing a potential multibillion-dollar deal with the federal government. The company's security culture has been criticized, with some arguing that it prioritizes profit over security.

Main themes

  • Microsoft security flaws
  • Profit over security
  • Cyberattacks and hacking
  • Whistleblower allegations
  • Corporate culture and accountability

What commenters say

  • Microsoft's prioritization of profit over security is a long-standing issue, with some arguing that it has become a cultural problem within the company.
  • The company's claims of prioritizing security are contradicted by its actions, which suggest that profit is the primary concern.
  • No company publicly admits to prioritizing profit over security, but their actions often reveal their true priorities.
  • Some companies, such as Proton and Mullvad, prioritize security over profit, but these cases are rare.
  • Regulatory changes are needed to hold companies accountable for their security practices and make them prioritize security over profit.
  • Investors often prioritize short-term gains over long-term security concerns, which can incentivize companies to compromise on security.
  • The lack of transparency and accountability in the tech industry makes it difficult to determine whether companies are truly prioritizing security or just paying lip service to the idea.