Rob Hooft

@rwwh
313 Followers
500 Following
1.2K Posts

RE: https://aus.social/@mojo/116321714247825786

En Wero draait op (tadaa) het Amerikaanse Amazon Web Services. Van de regen in de drup.

I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. 🔐 That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:

🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
👮 "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks 🤦🏻‍♂️

The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy

If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.

https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/
#Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec

Federal cyber experts called Microsoft's cloud a "pile of shit," approved it anyway

One Microsoft product was approved despite years of concerns about its security.

Ars Technica

as of yesterday, i cannot use my own phone, which i own and paid for in cash, to visit websites on the Internet or to send and receive text messages.

unless i "verify my age" with Apple, i am considered a "teen" and do not own my own device.

anyone who voted for this nonsense: fuck you.

For many people, the #Linux vs #Windows vs #Mac debate is a privilege — it assumes you can choose. But working with the Computer Upcycle Project, I've seen the real choice is often Linux vs no computer at all.

~95% of donated computers are "too old" for Windows 11 or macOS. Linux installs on them anyway, adding 10+ years of life to machines #Microsoft and #Apple called trash.

This isn't Linux vs Windows. It's Linux vs e-waste.

The intake form
at the doctor’s office
included the question
“are you feeling
down, depressed, or hopeless?”
which seemed to me
like a rather rude way of asking
“are you paying attention
to the state of the world?”

Perhaps I am some kind of dangerous computer radical these days, thinking that one should be able to buy or make a computer, install one's choice of OSs and software, create a local user account, and get on with one's affairs, privately and without interference.

Quiet enjoyment of one's computer.

* No age or ID verification

* No jumping through hoops to install software, or third parties restricting the software that one can run

* No third party accounts

Ik nam een kijkje op de website van #ProgressiefNederland.

Hoe progressief is dit nu eigenlijk?

Een deelknop voor #Mastodon ontbreekt. Wel vier deelknoppen voor #bigtech-platforms.

Echt progressieve politieke partijen zijn te vinden op de #Fediverse:

- @PartijvoordeDieren
- @Piratenpartij
- @BIJ1

#PracticeWhatYouPreach

Ik help graag.

#GroenLinks #PvdA #GroenLinksPvdA #PubliekeWaarden

In line with the Amsterdam bike store with an empty showcase selling “pre-stolen bicycles”, future AI for vibe-coding will be creating pre-enshittified code.
How long will it take before vibe-coding can only generate software that traces its users and generates advertising-revenue not for the creator but for the owner of the AI company? #ai #autonomy #enshittification