96
top 4 comments
sorted by: hot top controversial new old
[-] sylver_dragon@lemmy.world 17 points 6 days ago

Redmond’s previous system relied on digital escorts — American employees with proper security clearances — to monitor the foreign engineers working on the systems. However, it’s been noted that some of these U.S. citizens weren’t knowledgeable enough to determine if the person they were monitoring was doing regular work or putting in a backdoor.

This is a problem all over the FedGov. I've been on both sides of this situation. I've been a contractor escorted into spaces I was not cleared to be in. And, I've escorted contractors in cleared spaces. I can kinda see how the situation developed. When I was a contractor being escorted, the folks escorting me were great folks, but most knew fuck all about computers. I could have been up to some pretty shady stuff, and they likely would not have recognized it. Also, as physical escorts who were comfortable with me, they weren't exactly monitoring the screens all that closely. Even when it was me escorting contractors, I wasn't always completely knowledgeable about their work. Sure, I might know more about computers than some folks, but I don't know everything about everything, and it's possible that they could have slipped one past me.

All that said, when I was doing this stuff, I was subject to background checks on the regular. While they didn't quite go to the level of stuffing a microscope up my arse, I wouldn't have been surprised if they asked about it. So, how the fuck did Microsoft end up with Chinese nationals working on DoD systems? While I'm sure there's some great IT folks over there who just do their jobs and wouldn't get involved in spying/sabotage, this is just plain stupid. We're putting systems for our military in the hands of folks under the direct influence of once of the US's main adversaries.

[-] 0_o7@lemmy.dbzer0.com 5 points 5 days ago

They're going to be using a Chinese company registered in Vietnam now.

[-] Thedogdrinkscoffee@lemmy.ca 4 points 6 days ago
[-] Onomatopoeia@lemmy.cafe 3 points 6 days ago

Nah, I bet their driver was reversal of section 174, which means using overseas engineers costs a lot more tax wise.

this post was submitted on 21 Jul 2025
96 points (100.0% liked)

Cybersecurity

7904 readers
7 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS