News: 0180503199

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Trump Signs Defense Bill Prohibiting China-Based Engineers in Pentagon IT Work (propublica.org)

(Friday January 02, 2026 @04:30PM (msmash) from the moving-forward dept.)


President Donald Trump signed into law this month a measure that prohibits anyone based in China and other adversarial countries [1]from accessing the Pentagon's cloud computing systems . From a report:

> The ban, which is tucked inside the $900 billion defense policy law, was enacted in response to a ProPublica investigation this year that exposed how Microsoft used China-based engineers to service the Defense Department's computer systems for nearly a decade -- a practice that left some of the country's most sensitive data vulnerable to hacking from its leading cyber adversary.

>

> U.S.-based supervisors, known as "digital escorts," were supposed to serve as a check on these foreign employees, but we found they often lacked the expertise needed to effectively supervise engineers with far more advanced technical skills. In the wake of the reporting, leading members of Congress called on the Defense Department to strengthen its security requirements while blasting Microsoft for what some Republicans called "a national betrayal." Cybersecurity and intelligence experts have told ProPublica that the arrangement posed major risks to national security, given that laws in China grant the country's officials broad authority to collect data.



[1] https://www.propublica.org/article/trump-law-microsoft-digital-escort-ban-china



nice job keep the PHB's in the USA while the real (Score:2)

by Joe_Dragon ( 2206452 )

nice job keep the PHB's in the USA while the real tech people are offshored

Wait, what? (Score:5, Insightful)

by molarmass192 ( 608071 )

"ProPublica investigation this year that exposed how Microsoft used China-based engineers to service the Defense Department's computer systems for nearly a decade"

MS let foreign employees service DoD systems? I can't even begin to fathom how this is even remotely possible. Is there a CCP mule leading services at MS? If not, there should be a congressional hearing on this, because this level of incompetence is really inexcusable.

Re: (Score:3)

by ffkom ( 3519199 )

> MS let foreign employees service DoD systems?

Yes, and they will do it again, because it earns them a little more profit, and that is the only thing that counts for corporations of that size. May may hide the outsourcing a little better next time for PR reasons, like adding another layer of "domestic person A being the contractor, but relaying everything to/from N cheaper employees abroad".

Re:Wait, what? (Score:4, Insightful)

by djinn6 ( 1868030 )

From [1]ProPublica [propublica.org]:

> The arrangement, which was critical to Microsoft winning the federal government’s cloud computing business a decade ago, relies on U.S. citizens with security clearances to oversee the work and serve as a barrier against espionage and sabotage.

> But these workers, known as “digital escorts,” often lack the technical expertise to police the work of foreign engineers with far more advanced skills, ProPublica found.

So there was a loophole in the rules. And of course they're doing this to save money, so the Americans they hired weren't highly technical and probably can't identify attempts at subterfuge.

I mean even if someone very technical was there the perform the supervision, it would still be hard to defend against a persistent attacker.

[1] https://www.propublica.org/article/defense-department-pentagon-microsoft-digital-escort-china

Re: (Score:2)

by ArchieBunker ( 132337 )

The bar really has been lowered for fucking up.

Re: Wait, what? (Score:2)

by kenh ( 9056 )

Uh, to be clear, the current administration is stopping the practice.

> President Donald Trump signed into law this month a measure that prohibits anyone based in China and other adversarial countries from accessing the Pentagon's cloud computing systems.

How about foreign nationals living in ANY adversarial country (including China) not be allowed to work on anything related to national defense? If they can't even bother to move to the U.S. let's keep them away from our defense systems? OK?

Re: (Score:2)

by geekmux ( 1040042 )

> "ProPublica investigation this year that exposed how Microsoft used China-based engineers to service the Defense Department's computer systems for nearly a decade"

> MS let foreign employees service DoD systems? I can't even begin to fathom how this is even remotely possible. Is there a CCP mule leading services at MS? If not, there should be a congressional hearing on this, because this level of incompetence is really inexcusable.

NIST 800-53 pre-dates NIST 800-171 pre-dates CMMC. And I'd have to believe that Controlled Unclassified Information (CUI) is the bare minimum standard when talking about "Pentagon" related InfoSec guardrails.

Microsoft's GC Cloud mandating US citizen based support has been around for years now. I have no idea why the hell the Pentagon of all places would be skimping on these mandates, but I can tell you that skimping is quite rampant among defense contractors. Two years after implementing 800-171, a stud

So I've got good news and bad news (Score:2)

by rsilvergun ( 571051 )

The good news is there's no actual security risk there.

The bad news is that the reason there is no security risk is the modern ruling class is a global class and they're all working together to fuck you in the ass. So there isn't any actual risk among major countries because they're all in the same club together.

You are not in that club. Statistically you probably believe that you are. And even if intellectually you know you're not you probably vote like you are. Again statistically.

Wait! What? (Score:2)

by PPH ( 736903 )

Aren't jobs like these reserved for H-1B Indian contractors?

But... (Score:2)

by dskoll ( 99328 )

But Russia's OK.

Re: (Score:2)

by ffkom ( 3519199 )

> But Russia's OK.

I know Fortune 500 companies that are outspoken against Russia's war against Ukraine in public, and at the same time hire cheap Russians that reached western countries mere months ago (and they are certainly not "fugitives"). Virtue signaling is cheap, but there is money to save on wages, morals and security be damned.

I am surprised ... (Score:2)

by Alain Williams ( 2972 )

that this was not already the case.

Re: (Score:2)

by EvilSS ( 557649 )

Apparently many in the government were also surprised.

Off-topic, but... (Score:3)

by jargonburn ( 1950578 )

Shouldn't it really be called a "War Bill", now?

So USA only? (Score:3)

by ukoda ( 537183 )

> President Donald Trump signed into law this month a measure that prohibits anyone based in China and other adversarial countries from accessing the Pentagon's cloud computing systems.

So that would be every country on the planet, except the USA and maybe Russia?

ITAR (Score:2)

by JBMcB ( 73720 )

Not sure how this is allowed as ITAR covers a lot of this ground already.

[1]https://en.wikipedia.org/wiki/... [wikipedia.org]

[1] https://en.wikipedia.org/wiki/International_Traffic_in_Arms_Regulations

Probably a good idea! (Score:2)

by end rant ( 7141579 )

China chips so easily. One good drop and the whole thing shatters.

Actor Real Name

Boris Karloff William Henry Pratt
Cary Grant Archibald Leach
Edward G. Robinson Emmanual Goldenburg
Gene Wilder Gerald Silberman
John Wayne Marion Morrison
Kirk Douglas Issur Danielovitch
Richard Burton Richard Jenkins Jr.
Roy Rogers Leonard Slye
Woody Allen Allen Stewart Konigsberg