Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Nevilledog

(55,053 posts)
Wed Mar 18, 2026, 03:15 PM 19 hrs ago

Federal Cyber Experts Thought Microsoft's Cloud Was "a Pile of Shit." They Approved It Anyway.

https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government


In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings.

The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica.

Or, as one member of the team put it: “The package is a pile of shit.”

For years, reviewers said, Microsoft had tried and failed to fully explain how it protects sensitive information in the cloud as it hops from server to server across the digital terrain. Given that and other unknowns, government experts couldn’t vouch for the technology’s security.

Such judgments would be damning for any company seeking to sell its wares to the U.S. government, but it should have been particularly devastating for Microsoft. The tech giant’s products had been at the heart of two major cybersecurity attacks against the U.S. in three years. In one, Russian hackers exploited a weakness to steal sensitive data from a number of federal agencies, including the National Nuclear Security Administration. In the other, Chinese hackers infiltrated the email accounts of a Cabinet member and other senior government officials.

*snip*
6 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Federal Cyber Experts Thought Microsoft's Cloud Was "a Pile of Shit." They Approved It Anyway. (Original Post) Nevilledog 19 hrs ago OP
Many people may not know canetoad 19 hrs ago #1
I don't use anything but the basics. Faux pas 19 hrs ago #2
Unless you actively disable a bunch of "options"... dickthegrouch 15 hrs ago #3
Yeah, that's par for the course canetoad 15 hrs ago #5
Yes, No, Maybe. Igel 15 hrs ago #4
Still useful canetoad 15 hrs ago #6

canetoad

(20,714 posts)
1. Many people may not know
Wed Mar 18, 2026, 03:20 PM
19 hrs ago

That to run a Windows computer, contrary to Microsoft's instructions and exhortations, you do not need to sign up for a Microsoft account or utilise cloud storage and/or backup.

The options are very cunningly buried in the OS setup options and it appears to be compulsory. It is not.

dickthegrouch

(4,493 posts)
3. Unless you actively disable a bunch of "options"...
Wed Mar 18, 2026, 07:17 PM
15 hrs ago

Your system is nowhere close to “secure by design, and secure by default”.
I check all my disabled settings after every patch Tuesday because several mysteriously revert to enabled on a random basis. gpedit.msc on my home edition setup being a prime example of the opposite; it’s regularly disabled again after patch tuesdays and then I can’t disable other settings without it.

Latest Discussions»General Discussion»Federal Cyber Experts Tho...