• “dedicating the equivalent of 34,000 full-time engineers to what has become the single largest cybersecurity engineering project in the history of digital technology,”

    What does this mean? Are they having it done by 50,000 part timers? Or are they just asking bing chat to churn out security solutions for them?

    • The non-cynical answer is that they’re counting contractor/vendor time in this full time equivalent answer. Which would probably be a good thing, because I imagine that the best people in cybersecurity aren’t actually employees of Microsoft.

  • In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.

    Hopefully this doesn’t go the Apple direction where “security” becomes the catch-all defence for anti-consumer business practices.

    • I just installed Linux Mint for the first time. As a life long Windows user it’s more intuitive than Windows 11, the install and setup was easier than I’ve ever had doing a fresh install off windows, and I was able to connect to my media tower (still running Windows 10) faster and with less hassle than using a Windows machine.

      The only thing that was more difficult was having to look up where to find the setting in Steam for “please provide me Linux versions of games that don’t officially support it.”

    • Honestly they’ll probably redo it with a different name & hide that they’re doing it. A year from now when the PR crisis blows over. (LOOK OLYMPICS!) Let’s be honest. The cost of these things for a tech giant is a fine they can pay, 10y from now

    • Means nothing to Recall.

      His testimony comes after Microsoft admitted that it could have taken steps to prevent two aggressive nation-state cyberattacks from China and Russia.

      According to Microsoft whistleblower Andrew Harris, Microsoft spent years ignoring a vulnerability while he proposed fixes to the “security nightmare.” Instead, Microsoft feared it might lose its government contract by warning about the bug and allegedly downplayed the problem, choosing profits over security, ProPublica reported.

  • 🤖 I’m a bot that provides automatic summaries for articles:

    Click here to see the summary

    Instead, Microsoft feared it might lose its government contract by warning about the bug and allegedly downplayed the problem, choosing profits over security, ProPublica reported.

    This apparent negligence led to one of the largest cyberattacks in US history, and officials’ sensitive data was compromised due to Microsoft’s security failures.

    Even Microsoft itself was breached, with a Russian group accessing senior staff emails this year, including their “correspondence with government officials,” Reuters reported.

    Smith described the SFI as “a multiyear endeavor” focusing all of Microsoft’s efforts developing products and services “on achieving the highest possible standards for security.”

    He warned that online threats are always evolving but said that Microsoft was committed to grounding projects in core cybersecurity tenets that would prioritize security in product designs and ensure that protections are never optional and always enabled by default.

    In 2021, Smith told Congress that “there was no vulnerability in any Microsoft product or service that was exploited” in that cyberattack, while arguing that “customers could have done more to protect themselves,” ProPublica reported.


    Saved 79% of original text.