Hacker News new | ask | show | jobs
by ok123456 17 days ago
They're motivated not by the actual loss, but the checkmark of having attestation for a compliance framework.

So the fact that Microsoft let remote hands-on-keyboards in the PRC fix problems on GCC-High Azure nodes used by DoD contractors doesn't matter, since they're too big to censure in any meaningful way without impacting tens of thousands of businesses that rely on them to get a letter that satisfies a compliance assessor.

Actually knowing what you're doing, or being able to critically assess the risks of using a specific provider, doesn't matter.