Hacker News new | ask | show | jobs
by throwoutway 89 days ago
Yesterday ProPublica and ArsTechnica published a takedown of Azure: "Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway" ...

https://arstechnica.com/information-technology/2026/03/feder...

4 comments

In which one expert called the documentation provided "a pile of shit", which propublica took the liberty of extending to Azure itself
In those types of reviews/audits, documentation is the first indicator of whether a security organization has their act together. It's about building a trust relationship between the accreditor and contractor that will have to endure for years, as nation-state level actors throw their resources at finding vulnerabilities. MS couldn't do this or couldn't be bothered to do this. So shit documentation -> shit security processes and operations -> shit security -> shit cloud product in a government context. So the title wasn't that much of a stretch.
And they weren’t wrong
They still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that.

I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.

In this case, it’s just yet another design-level vulnerability in Microsoft cloud’s services. There isn’t much room for nuance.
It's true, they lied. But, paradoxically, in this case, while they lied about details, the conclusion is still true: Azure is very far from AWS and GCP as far as security is concerned. I have my own suspicions why it is so, but the reasons are not important, what counts is the final conclusion: if you really care for security, you'd better chose one of the other two.
“Fake but accurate.”

ProPublica has an agenda, and they slant their reporting to push it.

You can like their agenda and support this effort, but it’s not journalism.

What is their agenda?
If a slop engine calls a slop company slop, has anyone really lost?
We lost, for one of us got tricked to bring it here.
Titles are editorialised and space limited. The first couple lines in the article linked above make the nuance pretty clear.

[edit: 'pretty' instead of 'perfectly']

You are defending not just clickbait, but libelous clickbait.
I doubt this reaches the bar for libel by a long shot.
It's only libelous if it's not true. This vulnerability says otherwise.
Every security engineer I know working at Azure is on the verge of self-harm because of the current situation, or is the dumbest IC I've ever met and somebody I think should have never become a security engineer. Sample size ~12.
That is quite the indictment.
I am not very close with every one of these engineers, and some no longer work at MSFT, but yes talking to employees in Seattle working on security made me never want to use Azure.
Last I heard, the CO+I org has some pretty serious cultural problems that contribute to this, and which will not be easily solved.
Ars just republished it under license
Bloomberg and CNBC don't seem to have reported about this, maybe someone with contacts could make them aware?