Jan de Muijnck-Hughes

344 Followers
237 Following
3K Posts
Lecturer of type-driven approaches to trustworthy-systems (CyberSecurity) at Strathclyde. Professionally interested in PL & FM Methods; socially interested in coffee, politics, music, the outdoors, sci-fi, high fantasy, & much much more! My work doesn’t define me; it is not my identity.
wwwhttps://tyde.systems/
Pronoun’she/his
Locations🇳🇱 🏴󠁧󠁢󠁷󠁬󠁳󠁿 🇬🇧 🇪🇺

I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. 🔐 That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:

🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
👮 "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks 🤦🏻‍♂️

The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy

If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.

https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/
#Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec

Federal cyber experts called Microsoft's cloud a "pile of shit," approved it anyway

One Microsoft product was approved despite years of concerns about its security.

Ars Technica

I gave a research lecture to students today at #TypeSig #Triple. #UoE The topic was that of my #TYPES2025 talk: Being Positively Negative About Dependent Types.

Great range of speakers from organisers, even though it was @mspstrath heavy! One student came at the end to say they enjoyed the talk as it was accessible to them. I like that.

Also nice to see the other talks in the tracks I attended. Especially those that are related! (Two sided type systems)

The journey home even gave me space to think about research…

From the other site, but too good to not share:

https://x.com/robertgraham/status/2036208633814639088

There is a post about the importance of the BBC’s ‘pips’ arising form commenting on someone demonstrating a plugin that plays the BBC news countdown (that includes the ‘pips’) as the countdown to a teams meeting. I wish I could get this before all meetings I have to attend…

Robert Graham (@robertgraham) on X

These beeps started in 1924. Back then, people could get "astronomical time" by telescopes looking at the stars. You knew when it was 12am by the exact time when a certain star appeared overhead. The Greenwich Observatory would calculate this time daily, and have a ball drop at

X (formerly Twitter)

Vandaag (#DocumentFreedomDay) online: de volledig vernieuwde keuzehulp Open Publiceren: https://openpubliceren.nl/

Open Publiceren (@openstate en @forumstandaardisatie) is een praktische keuzehulp bij het kiezen van het juiste bestandsformaat voor open en leveranciersonafhankelijk publiceren van overheidsinformatie en -data.

Lees het nieuwsbericht: https://www.forumstandaardisatie.nl/nieuws/keuzehulp-open-publiceren-volledig-vernieuwd

#OpenOverheid, #OpenStandaarden, #Woo, #Who, #DigitaleAutonomie

@minbzk @developer @opennl

Open Publiceren

Op donderdag 26 maart vindt de eerste bijeenkomst van Platform Internetstandaarden van dit jaar plaats.

Op de agenda staan onder andere:

1. E-Mail-Sicherheitsjahr 2025 van @bsi (https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Leistungen-und-Kooperationen/EMSJ/EMSJ_node.html)

2. DMARCaroni / @dmarcaroni (https://dmarcaroni.org/)

3. Accreditatieaanpak en Dutch Alternatives-website van #DutchCloudCommunity (https://dutch-alternatives.nl/)

1/2

E-Mail-Sicherheitsjahr

Bundesamt für Sicherheit in der Informationstechnik

RE: https://mstdn.social/@swheritage/116272142405742756

"France and Germany are moving beyond the “altruism” of the early open-source movement, reframing it as a matter of national autonomy. Stéphanie Schaer, The Interministerial Directorate for Digital Affairs in France (DINUM), highlighted Tchap—a secure messaging app used by 400,000 civil servants—as proof that the state can break its dependency on “monopolistic IT solutions” by investing in the digital commons."

#OpenSource #SWH10

At least everything else appears to be working and I have freed up a bit more space….

well...

+ had to install new nix
+ first I ran out of diskspace...
+ nix-env to delete old generations
+ commented out most of home.nix
+ nix-collect-garbage
+ nix-store --optimise
+ watched my diskspace go up and down like a yoyo

Now nix commands do not have man pages...

lets do `nix-channel --update` and see if everything still works....

Oracle Databases 0; /me 2

That is two Universities that, for some reason, have core systems that do not like my surname....