Microsoft in damage-control mode, says it will prioritize security over AI (arstechnica.com)
from otter@lemmy.ca to technology@lemmy.world on 14 Jun 08:58
https://lemmy.ca/post/23152707

#technology

threaded - newest

autotldr@lemmings.world on 14 Jun 09:00 next collapse

This is the best summary I could come up with:


The company has invited the Cybersecurity and Infrastructure Security Agency to attend a “detailed technical briefing” on SFI and Microsoft’s other engineering objectives to explain “the specific ways we are implementing the CSRB’s recommendations,” Smith said.

Although he acknowledged that Microsoft has “by far the first and greatest responsibility” to heed the CSRB’s report, “no single company can protect a country and other nations from what is emerging as a cyberwar waged by four aggressive governments,” Smith said.

Smith suggested that the committee members could “do more in support of cyber defense” by funding critical cybersecurity programs, strengthening countermeasures, and “imposing appropriate punishment” and heavy fines to deter malicious activity.

The spokesperson further explained that Microsoft historically has prioritized its "security response work by considering potential customer disruption, exploitability, and available mitigations.”

“We continue to listen to the security research community and evolve our approach to ensure we are meeting customer expectations and protecting them from emerging threats,” Microsoft’s spokesperson said.

“We accept responsibility for the past and are applying what we’ve learned to help build a more secure future,” Smith said, vowing that Microsoft would soon “establish stronger multi-layered defenses to counter the most sophisticated and well-resourced nation-state actors.”


The original article contains 541 words, the summary contains 200 words. Saved 63%. I’m a bot and I’m open source!

b3an@lemmy.world on 14 Jun 10:49 next collapse

<img alt="" src="https://lemmy.world/pictrs/image/ef4d3eca-85a2-4a7b-aedb-ecf665a3bf32.jpeg">

nulluser@programming.dev on 14 Jun 11:57 next collapse

Link is to the second page of the article. I thought it was odd how it kept saying “Smith said” without identifying who Smith is.

Proper link: arstechnica.com/…/microsoft-in-damage-control-mod…

otter@lemmy.ca on 14 Jun 11:59 collapse

Oops, should be fixed now

Thanks!

gravitas_deficiency@sh.itjust.works on 14 Jun 12:47 next collapse

I’ll wait until they demonstrably prioritize security. Corporations will say literally anything to avoid negative PR.

Edit:

But also, this isn’t actually about Recall:

Microsoft is pivoting its company culture to make security a top priority, President Brad Smith testified to Congress on Thursday, promising that security will be “more important even than the company’s work on artificial intelligence.”

Satya Nadella, Microsoft’s CEO, “has taken on the responsibility personally to serve as the senior executive with overall accountability for Microsoft’s security,” Smith told Congress.

His testimony comes after Microsoft admitted that it could have taken steps to prevent two aggressive nation-state cyberattacks from China and Russia.

According to Microsoft whistleblower Andrew Harris, Microsoft spent years ignoring a vulnerability while he proposed fixes to the “security nightmare.” Instead, Microsoft feared it might lose its government contract by warning about the bug and allegedly downplayed the problem, choosing profits over security, ProPublica reported.

Holy fuck. This is like National Security level shit. As in, potentially dire implications on supposedly-secure SCI-related systems. There will probably be Very Fucking Serious criminal charges of the type that you can’t rub money on to get out of.

Say it with me now: this is what happens when you let the business and finance idiots run the show.

nick@midwest.social on 14 Jun 13:52 next collapse

I hope you’re right, but at this point I suspect the lobbyists will just bribe whoever they need to.

MataVatnik@lemmy.world on 14 Jun 14:57 collapse

This shit should be left at the hands of the state.

Ephera@lemmy.ml on 14 Jun 14:33 next collapse

You mean like how they told their employees to prioritize security above all else and then had effectively none in Recall?

atrielienz@lemmy.world on 14 Jun 15:17 next collapse

Do they not have an active leak where people’s outlook account information is just out there and accounts are getting stolen?

nutsack@lemmy.world on 14 Jun 15:18 collapse

how about suck my balls mode