How Microsoft's 'Little Workaround' Created a Major Threat to America's Defense Department (propublica.org)
- Reference: 0184500330
- News link: https://yro.slashdot.org/story/26/07/18/0513229/how-microsofts-little-workaround-created-a-major-threat-to-americas-defense-department
- Source link: https://www.propublica.org/podcast/microsoft-digital-escorts-china-defense-department
The reporter first found an ad offering $18 to $28 to hire Americans as "digital escorts" for China-based tech support, then just searched LinkedIn for people who apparently had answered the ad. They discovered that at the time "Behind the scenes, unseen by the users at the U.S. government, it's not just one person who responds," explains ProPublica's podcast. "It's two people... The China-based engineer is the one who knows how to fix the problem. On their end, they produce a block of code to solve it and send it over to the digital escort in the U.S. The digital escort then just copy-pastes it... All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data."
But amazingly to confirm it, ProPublica's researcher just had to input "Microsoft" and "escort" into the U.S. Patent Office search bar, and actually found patents related to digital escorts — along with names of the current and former Microsoft employees listed as inventors. Had the government signed off on the practice? "I could see what Microsoft actually told the government," the reporter says on the podcast, "And there was no mention of foreign engineers being used, and definitely no mention of China."
[4]ProPublic's story was published on a Tuesday, according to the podcast, and by Friday "Microsoft said it had stopped using China-based engineers to support Defense Department cloud systems." And America's Defense Department "also opened up an investigation, looking into whether any of Microsoft's China-based engineers had compromised the government's national security.
[1] https://www.slashdot.org/~joshuark
[2] https://www.propublica.org/podcast/microsoft-digital-escorts-china-defense-department
[3] https://it.slashdot.org/story/25/07/25/1613250/microsoft-used-china-based-support-for-multiple-us-agencies-potentially-exposing-sensitive-data
[4] https://www.propublica.org/article/microsoft-digital-escorts-pentagon-defense-department-china-hackers
New Heights (Score:5, Insightful)
This is a level of stupid that only Microsoft could pull off. Now, why has Microsoft not been charged with treason? Nadella is the definition of greedy bastard.
Re: (Score:3)
Nobody is that "stupid" in those departments.
The question should be what was the quid pro quo?
We can imagine what the PLA got out of it but what favor did Microsoft get?
And how high up the chain did it go? Who specifically approved the arrangement?
At least Microsoft probably has Windows 11 "backups" of the hard drives of anyone who might think of bringing charges.
Not sure if that strategy can be called stupid. Lots of other words apply.
"One Nation Under Blackmail" is a popular phrase.
Re: (Score:1)
> This is a level of stupid that only Microsoft could pull off. Now, why has Microsoft not been charged with treason? Nadella is the definition of greedy bastard.
And if Trump was true to his own rantings, Nadella would be a "greedy bastard" with his head on a pike in the Oval Office.
But Trump only cares about China as a comic book villain. He uses 'evil' countries to distract MAGA from America's true enemies: oligarchs, corporations, and anyone else with enough cash to bribe politicians, flout the law, and steer the government.
Re: (Score:2)
I hear Rosie O'Donnell has a spare room for rent if you are interested.
We'll have "digital escorts" for LLM coding tools (Score:5, Insightful)
... and given the price difference, the LLM services behind the tools may be hosted in China, just like those "cheaper IT workers" were. And the "digital escorts" will be as incapable of actually reviewing the code as the ones that "escorted" human IT workers from China. There just is not a trace of conscience in corporations that could prevent this from happening time and again.
DoD: "We have to follow Industry's lead" (Score:5, Insightful)
That's the argument I heard when a defense contractor about why so many DoD systems specified Microsoft products, particularly Active Directory.
Of course, "following industry standards" relieves one of the responsibility of actually thinking about what you're buying, including life-cycle costs and security & quality of the products. In that way, DoD was no different than all the other CIOs. Microsoft understood that CIOs were their real customer, and did everything to convince CIOs that Microsoft (regardless of cost) was 'the least risk alternative."
Digital Escorts (Score:3)
So, these people hired as digital escorts are vetted for security clearances, right? Because they will be handling "sensitive data". And as a part of receiving that clearance, they will be informed of their duties and responsibilities when handling said "sensitive data". Or no?
> All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data.
That's what we call a necessary condition. Not a sufficient condition.
Distinction (Score:1)
There's a difference between asking an overseas consultant "what buttons do I push to un-jam the purple gizmo?" and between "Enter these new users for me."
You're not paid for situational awareness (Score:3)
At Microsoft, you're not paid for situational awareness, quite the opposite, on no level. That's why nearly every single country in the world now reflects on the services of this company which became a security risk on many different levels. Nobody wants that, nobody can afford that.
Re: (Score:3)
Calm down Satya.