The Register Home Page

back to article Pentagon ends Microsoft's use of China-based support staff for DoD cloud

The Pentagon has formally kiboshed Microsoft's use of China-based employees to support Azure cloud services deployed by US government agencies, and it's demanding Microsoft do more of its own digging to determine whether any sensitive data was compromised.  Defense secretary Pete Hegseth announced the change in policy Thursday …

  1. cookieMonster
    Facepalm

    Ha ha ha ha

    FFS !!!

    I just cannot comprehend the level of stupidity that must be everywhere in that company

    1. Yet Another Anonymous coward Silver badge

      Re: Ha ha ha ha

      Imagine being a European country and outsourcing your vital IT to American software company

      1. Gary Stewart Silver badge

        Re: Ha ha ha ha

        Never been a big fan of horror flicks.

      2. M.V. Lipvig Silver badge

        Re: Ha ha ha ha

        That is a different problem Similar, but different. In this case it is a European company outsourcing their defense stuff to an American company using Chinese programmers - only without someone with a clearance supposedly watching and understanding every keystroke.

      3. Anonymous Coward
        Anonymous Coward

        Re: Ha ha ha ha

        … or off-shoring/outsourcing your companies Crown Jewels to Bangalore and fucking off your domain knowledge legacy ‘too expensive’ staff without even a thanks.

    2. Anonymous Coward
      Anonymous Coward

      Re: Ha ha ha ha

      Only someone Microsoft in the head could have thought this was ok. And I don't appreciate having to take the same side as Pete Keggerseth.

    3. Gary Stewart Silver badge

      Re: Ha ha ha ha

      And over the years it has only gotten worse. Completely boggles the mind. Oh wait, I live in the US, mind double boggled.

    4. Anonymous Coward
      Anonymous Coward

      Re: Ha ha ha ha

      I hear they replaced the Chinese devs with Russian and North Korean ones.

    5. Anonymous Coward
      Anonymous Coward

      Re: Ha ha ha ha

      First sensible thing Hegsegh has said as SecDef. Still a broken clock is right twice a day.

      I struggle to see in any world why Microsoft would allow anyone outside the US to support DoD systems. They should all be security vetted too.

      I guess they are doing similar for other countries Defence and Government contracts from Five Eyes theu UK NHS to pretty much anyone on the Azure bandwagon.

  2. Andy Non
    Facepalm

    Microsoft responded

    that it has now resolved the issue and will henceforth outsource any DoD software roles to North Korea.

  3. Doctor Syntax Silver badge

    "Microsoft designed its policy of using staff based behind the Great Firewall to comply with government contracting rules"

    The letter but not the spirit it seems. Even so, they should have realised it couldn't possibly be acceptable.

    I suppose anyone but Microsoft would have found it galling to be lectured on common sense by Mr Signal Leak with him having the right of it.

    1. Roland6 Silver badge

      > “Microsoft designed its policy of using staff based behind the Great Firewall…”

      Note the word “designed”. Microsoft did this deliberately to avoid using US security cleared personnel.

  4. Blackjack Silver badge

    Why do governments hate using Linux so much?

    1. tfewster

      If it's not Capitalist then it must be Communist?

    2. YetAnotherXyzzy

      That's a good question. Many years ago I was a consultant to a local government. I wasn't just proposing stuff and cashing my check; I got to implement them too, which I really enjoyed about that gig. One thing I wanted to do there was move them from Windows to Linux, but I didn't tell anyone that. Instead I was going to first move everyone to applications available on Linux, one at a time, starting with MS Office to LibreOffice. Dear mother of God what a hornet's nest that was. People just don't want to change. I had other fish to fry so I backed down from that idea and made other improvements instead.

      At the same time I was the owner/operator of the town's first internet café (which tells you how long ago this was). The machines were all Linux, albeit with a DE that had a Win95-like start button and taskbar. In all the years of operation only one customer even commented on it.

      I guess the conclusion to be drawn from those two examples is, get the OS and applications right from the beginning, and users will take what they're given. But heaven help you if you ever dare change those choices later.

      1. Anonymous Coward
        Anonymous Coward

        Change of OS

        Which of course begs the question, why do people willingly accept Microsofts complete upheaval of the desktop and modus operandi of the whole computer every few years.

      2. LBJsPNS Silver badge

        "People just don't want to change."

        You'd be amazed how quickly that attitude evaporates when those same people are told to learn the tools necessary to do their job or find another job. Fire the loudest whiners and see how quickly the rest suddenly are able to learn.

        1. TimMaher Silver badge
          Coat

          Re: “Fire the loudest whiners”

          After they have failed their PIP.

          Are you a management consultant @LBJ?

          Just asking for a fiend.

  5. alain williams Silver badge

    Why is DoD outsourcing at all ?

    It means that sensitive data will be maintained by staff that are unknown to DoD and prolly not security vetted. Working from who knows where using computers (desktops) of unknown security status (maybe some at their home).

    Yes: the agreement might say all sorts of fine things but anyone with any experience in this sort of thing will know that over time security agreements will erode ... eg: the relevant security cleared expert is ill/on-holiday/... so another expert, as a one off, temporarily brought in; temporary slides into often and long term.

    On the DoD side: there could be restrictions on what sort of documents/... are put into the MS cloud. Again: that might start well, but sensitive stuff will end up there by accident or as a one off as it is easier than the correct, secure system.

    The DoD is big enough to create its own cloud and employ their own staff to keep it working.

    1. has been

      Re: Why is DoD outsourcing at all ?

      For that matter, is the DoD using cloud platforms for anything at all that is protectively marked/classified? If so, why?

    2. DS999 Silver badge

      Re: Why is DoD outsourcing at all ?

      Because for decades the DoD has mostly existed for private profit. It favors big weapons systems where they can divide up the work so nearly every congressional district has some money coming in for it, that makes it almost impossible to kill even when it is a boondoggle like F35.

    3. martinusher Silver badge

      Re: Why is DoD outsourcing at all ?

      The DoD is a huge animal with tentacles all over the place so not everything it does is Most Secret. Or even Somewhat Slightly Secret. They're also pretty much exclusively Microsoft based so a lot of their work's going to be inside the Microsoft ecosystem, especially if its boring Not Really Secret At All stuff.

      When an organization's data goes off to the cloud it should be an amorphous blob. At least it should be. Whether that data is stored within reach of an 'adversary' or not should be unimportant, all that's important is that its secure -- multiple copies and solidly encrypted.

      This is unlikely to register with a recycled sportscaster (for that's who our Defense Secretary is). Their understanding of the world, data security and so on is firmly rooted in comic strips and superhero movies.

      1. Anonymous Coward
        Anonymous Coward

        Re: Why is DoD outsourcing at all ?

        Microsoft will happily charge you through the nose for a GCC High or Gov Cloud tenant, so we can keep DoD contracts satisfied.....alarming (but not surprising) to find out they've not even got their own house in order.

        Good work by Pete MegaDeath for once.

  6. Tron Silver badge

    he considers Microsoft to be a national security threat

    Loads of Americans consider the Trump regime to be a national security threat.

    I guess the USG could roll out a Trumpian version of the Nuremberg Race Laws to define those who are American enough to support government tech. Three American grandparents, American partners, etc

    1. has been
      Coat

      Re: he considers Microsoft to be a national security threat

      Make it even more strict:- Three American parents!

      1. Anonymous Coward
        Anonymous Coward

        Re: he considers Microsoft to be a national security threat

        What, you mean you even the sperm/egg donor need’s to be American?

    2. DS999 Silver badge

      Re: he considers Microsoft to be a national security threat

      But it isn't as though the objection was American citizens of Chinese descent working on this. They were having Chinese citizens who have probably never set foot in the US working on it! I don't even know how that happens, given all the requirements for obtaining clearance to do even the simplest stuff on a DoD project.

      There ought to be some consequences to Microsoft for knowingly and blatantly violating US government citizenship and clearance requirements for working on defense related projects. If this was a "small contractor" that only did a billion dollars or so of business a year they'd have all their contracts canceled and end up bankrupt in no time. But Microsoft is told "hey don't do that" while they continue to feed at the taxpayer trough to the tune of billions a year.

    3. Gary Stewart Silver badge

      Re: he considers Microsoft to be a national security threat

      There is no consider to consider. He is a proven security threat several times over and is completely dedicated to doubling (tripling, quadrupling?) down on that.

      1. Anonymous Coward
        Anonymous Coward

        Re: he considers Microsoft to be a national security threat

        Honestly, Microsoft and Hegseth, is a perfect match. Swipe right and f-up a storm on the puke stained carpet.

  7. Wdstarr57

    It's about the $$$

    Microsoft is not stupid, naive, or gullible. What Microsoft is is aware that money spent on security issues is money not spent on executive salaries and shareholder dividends.

    1. Eclectic Man Silver badge
      Facepalm

      Re: It's about the $$$

      I was the security consultant to a bid to manage a UK Government system, and the 'sales person' was adamant that I must not be permitted to tell them they could not use support staff and systems based in India. He even went up, across and down the management chains to get my direct line manager (also a security consultant) to tell me that a specific named senior manager, had said to tell me that. Otherwise the price would be too high and we would lose the bid.

      Well, the data being at the time RESTRICTED, and being contractually obliged by my contract with GCHQ/CESG to prevent said offshoring of support, the bid was not a happy one.

      I wonder if they will find out who actually approved this monumentally stupid idea and see if they cannot sue or prosecute them.

      I need a drink, and I don't mean water.

      1. Anonymous Coward
        Anonymous Coward

        Re: It's about the $$$

        "and being contractually obliged by my contract with GCHQ/CESG to prevent said offshoring of support, the bid was not a happy one"

        Well done! Unfortunately we've had GCHQ recruiting dodgy interns, and negligently allowing them to take classified data out of the place which is pretty damning on management. And that's the one they caught.

  8. ecofeco Silver badge
    Facepalm

    I'll say it again

    How are U.S. fed systems being constantly breached?

    Because they are effing stupid.

    1. chivo243 Silver badge
      FAIL

      Re: I'll say it again

      US is a big target, and has low hanging fruit*. Yep, that sums it up.

      *M$ products and the desire for the dollar-hence outsourcing.

  9. powershift

    Except it probably isn't an accident

    No room to give the benefit of the doubt since China has infiltrated MS. But whatever, lets act like its an oversight and sloppy.

    1. Anonymous Coward
      Anonymous Coward

      Re: Except it probably isn't an accident

      They should actually be more worried about pissing off Modi. Indians have near total control of US IT at every level.

      1. Anonymous Coward
        Anonymous Coward

        Re: Except it probably isn't an accident

        I've been banging this drum for ages!!!! Cheap Indian IT / engineering labour is purely a honeypot to ensure the west is entirely compromised when the rubber hits the road and everyone has to pick a side.

        Mind boggling that nobody else can see it, profit and margins are making corporations blind to the seemingly obvious risk.

  10. Eclectic Man Silver badge
    Unhappy

    Flag: I don't want to worry anyone, but

    On the screen image for the story, the stars in the 'Star Spangled Banner' aka the flag of the United States of America, do not appear to be quite right.

    See, e.g., https://www.britannica.com/topic/flag-of-the-United-States-of-America

    Of course as a 'limey' I am probably not allowed to comment on another country's flag, but as their Supreme Leader has just signed an EO banning the burning of said flag, I think the USAfolk might want to check.

    1. tfewster
      Trollface

      Re: Flag: I don't want to worry anyone, but

      Just 48 stars - Maybe Trump is deporting a couple of undesirable States?

    2. WolfFan Silver badge

      Re: Flag: I don't want to worry anyone, but

      It’s the old, pre-1959, flag. Alaska and Hawaii became states in 1959.

      It’s a common error. The other way, using the 50-star flag when deplicting events prior to 1959, has happened on several tv shows and movies. And at least one Western epic set just after the American Civil War has used the 48-star flag, which amused me no end, as the 48-star flag dates from 1912. (I was told to shut up, it’s just a movie. It also had the Colt Single Action Army 0.45 revolver, despite being set in 1867 when the Colt was designed in 1872 and adopted by the US Army in 1873. And the Winchester 73, also from 1873. I had _fun_ spotting anacronisms in that thing.)

      1. Excused Boots Silver badge

        Re: Flag: I don't want to worry anyone, but

        Although should there not be 13 stripes rather than 11?

  11. M.V. Lipvig Silver badge

    Is Satya in jail awaiting trial yet?

    No? Then the US government is not taking this seriously either. This should never have been allowed to happen, but I guess it was easier than letting highly visible "weather" balloons cross the country.

    1. Anonymous Coward
      Anonymous Coward

      Re: Is Satya in jail awaiting trial yet?

      What about the DoD procurement offer who accepted the contract and the DoD manager who signed it?

  12. druck Silver badge
    Mushroom

    What next?

    Are they going to find Russian nationals maintaining the nuclear arsenal?

    Completely OK as long as a US Citizen is responsible for showing them to the silo canteen at lunchtime.

    1. Fruit and Nutcase Silver badge
      Joke

      Re: What next?

      Are they going to find Russian nationals maintaining the nuclear arsenal?

      Or may be even commanding the subs

      icon: I hope that's the right icon

    2. Fruit and Nutcase Silver badge

      Re: What next?

      Are they going to find Russian nationals maintaining the nuclear arsenal?

      Is that a Russian asset in charge of our nuclear button?

    3. Fruit and Nutcase Silver badge
      Joke

      Football

      Have they checked inside the football/satchel recently? Or have the codes been swapped out by Putin?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like