Marcel

@Marcelatwork
58 Followers
488 Following
31 Posts
Civil servant, European, Netherlands, all opinions are my own, retweets are endorsements, pro civilisation, pro human rights, pro common sense

I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. 🔐 That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:

🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
👮 "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks 🤦🏻‍♂️

The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy

If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.

https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/
#Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec

Federal cyber experts called Microsoft's cloud a "pile of shit," approved it anyway

One Microsoft product was approved despite years of concerns about its security.

Ars Technica
Kannie wachten!

RE: https://mastodon.social/@EuromaidanPress/116301763946124202

Cijfers moeten soms in perspectief worden geplaatst. Mooi voorbeeld. #werkaandewinkel

Things I do not want my operating system to do:

1) Spy on me.
2) Sell my information to people who spy on me.
3) Advertise to me.
4) Force me to use tools I regard as evil.

RE: https://mastodon.world/@muz4now/116290602584824400

Interessante manier om de dominante rol van appstores te verminderen.

Mit dem Tod von Jürgen #Habermas verliert die politische Philosophie eine Stimme, die darauf beharrte, dass demokratische Legitimität nicht aus Macht, sondern aus vernünftiger Verständigung entsteht. Sein Denken erinnerte daran, dass Demokratie mehr ist als Mehrheiten: Sie lebt vom Streit der Gründe – und vom Vertrauen darauf, dass Sprache mehr sein kann als ein Instrument der Durchsetzung.

RE: https://lgbtqia.space/@m/116222680806173310

Longread over de lobby achter 'age verification'.
De moeite waard.

🇪🇺 1/7 🌍 Foreign-funded lobby groups from outside the EU are pushing #ChatControl with misleading propaganda. They want to #PassTheLaw to scan your chats, but who are they and who's paying them? Let's expose the network.
Thread 👇
https://share.joinmastodon.org is a tool that allows you to put a "Share to Mastodon" button on your website.
Share to Mastodon

What's Certbot? It's EFF's free, open source tool for automatically using Let’s Encrypt certificates on millions of domains across the web. It's also part of a growing number of EFF technology projects designed to protect your freedom online. Help support this work today! https://eff.org/support-certbot
Defend Privacy and Free Speech

We're building a better web together. Donate to help out Certbot and all of the Electronic Frontier Foundation's public interest software development, activism, and legal work. Your support...

Electronic Frontier Foundation