Advertisement · 728 × 90

Posts by Renee Dudley

10) “We stand by our products and the comprehensive steps we’ve taken to ensure all FedRAMP-authorized products meet the security and compliance requirements necessary,” a Microsoft spokesperson said.

3 weeks ago 19 1 1 0

9) Rogers declined to be interviewed, but Microsoft said she stands by her decision to approve GCC High. Monaco did not respond to requests for comment. Microsoft said their hirings had “absolutely no connection” to GCC High and complied with all rules and regulations.

3 weeks ago 22 2 1 0
Preview
Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway. A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive dat...

8) Here’s my full investigation:
www.propublica.org/article/micr...

3 weeks ago 40 14 1 2

7) Rogers now works for Microsoft. So does former deputy AG Monaco, who became the company’s head of global affairs last year.

3 weeks ago 32 5 1 0

6) FedRAMP ultimately authorized GCC High in late 2024, even though reviewers thought it was a vast wilderness of untold risk.

Today, key parts of the federal government use GCC High to protect highly sensitive data.

3 weeks ago 27 3 1 0

5) It was the “opinion of the staff and the contractors that she simply was not willing to put heat to Microsoft on this” and that DOJ “was too sympathetic to Microsoft’s claims,” a former GSA official told me.

3 weeks ago 25 2 1 0

4) Rogers had approved the product, called GCC High, for DOJ’s use in 2020. Although federal cyber evaluators at FedRAMP later raised concerns about its potential risks, Rogers pressed them to authorize it anyway.

3 weeks ago 23 2 1 0

3) At the same time, Melinda Rogers, a top official at the Justice Department, was showing a remarkable deference to Microsoft, which was struggling to answer basic cybersecurity questions about one of its cloud products.

3 weeks ago 28 7 1 1

2) In 2021, Deputy AG Lisa Monaco pledged to get tough on tech companies that “fail to follow required cybersecurity standards — because we know that puts all of us at risk.”

3 weeks ago 27 2 2 0

1) In my latest investigation into @microsoft.com's business with the federal government, the revolving door is in full swing. THREAD 🧵

3 weeks ago 128 51 1 4
Advertisement

12) But we found there aren’t many people left at FedRAMP to work with, and the program is essentially a rubber stamp. The General Services Administration, which houses FedRAMP, defended the program, saying it has undergone “significant reforms.” It did not answer questions about GCC High.

3 weeks ago 48 7 0 0

11) Microsoft acknowledged the yearslong confrontation with FedRAMP but also said it provided “comprehensive documentation” throughout the review and would “continue to work with FedRAMP to continuously review and evaluate our services for continued compliance.”

3 weeks ago 42 2 2 0

10) In response to questions, a Microsoft spokesperson told me: “We stand by our products and the comprehensive steps we’ve taken to ensure all FedRAMP-authorized products meet the security and compliance requirements necessary.”

3 weeks ago 42 2 2 0

9) “This is not a happy story in terms of the security of the U.S.,” said Tony Sager, who spent more than three decades as an NSA computer scientist and now is an executive at the Center for Internet Security. “This is not security,” he said. “This is security theater.”

3 weeks ago 63 9 2 0
Preview
Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway. A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive dat...

8) Yet my investigation — drawn from internal memos, logs, emails, meeting minutes, and interviews with 7 former/current gov employees & contractors — found breakdowns at every juncture of that process, as well as a remarkable deference to Microsoft.
www.propublica.org/article/micr...

3 weeks ago 150 40 2 5

7) This was not the type of outcome federal policymakers envisioned years ago when they embraced the cloud and created the FedRAMP program to help protect US cybersecurity. It was supposed to ensure that providers like Microsoft could be entrusted with government secrets.

3 weeks ago 57 4 3 0
Post image

6) FedRAMP’s ruling helped Microsoft expand a government business empire worth billions. “BOOM SHAKA LAKA,” Richard Wakeman, one of the company’s chief security architects, boasted online, celebrating with a meme of Leonardo DiCaprio in “The Wolf of Wall Street”

3 weeks ago 98 12 1 1
Post image

5) The government ultimately authorized Microsoft’s product not because its review was complete, but because it felt it had little choice.

3 weeks ago 142 27 4 2

4) What I discovered is that government officials had painted themselves into a corner.

Agencies were allowed to deploy GCC High during the review process. So even as reviewers were raising red flags about the product, the Justice Department and others were already using it.

3 weeks ago 66 5 1 1
Advertisement

3) The federal government could be exposed if it couldn’t verify the cybersecurity of the cloud product in question: Microsoft’s Government Community Cloud High, or GCC High.

So why did it bestow its seal of approval?

3 weeks ago 62 2 2 0

2) By late 2024, Microsoft’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence,” an internal government report said.

It wasn’t a one-off. For years, reviewers said, Microsoft failed to fully explain how it protects sensitive info in the cloud.

3 weeks ago 74 6 1 1
Post image

1) THREAD: Federal cybersecurity reviewers said this @microsoft.com cloud package was “a pile of shit.”

They gave it their seal of approval anyway.

Here’s how it happened 👇

3 weeks ago 254 110 7 18

This is a long article, but very much worth your time.

It also tells the story of how FedRAMP has turned into a rubber stamp for well funded software vendors.

And yet it still serves as a barrier to entry for new contenders.

Meanwhile, the USG suffers massive tech debt, despite massive spending.

1 month ago 27 14 2 0
Preview
Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway. A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive dat...

Expert: “This is not a happy story in terms of the security of the U.S. This is not security. This is security theater." Incredible reporting from @propublica.org 's @reneedudley.bsky.social with research by Doris Burke www.propublica.org/article/micr...

1 month ago 210 71 1 5
Preview
Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway. A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive data.

NEW: Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.

A program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive data.

1 month ago 789 315 13 34
Preview
Pentagon Bans Tech Vendors From Using China-Based Personnel After ProPublica Investigation The Defense Department has tightened cybersecurity requirements for its cloud services providers. The changes come after ProPublica revealed how Microsoft’s use of China-based engineers left sensitive...

NEW: The Defense Department has tightened cybersecurity requirements for its cloud services providers. The changes come after ProPublica revealed how Microsoft’s use of China-based engineers left sensitive government data vulnerable to hacking.

By @reneedudley.bsky.social

7 months ago 496 139 27 7
Advertisement
Preview
Microsoft Failed to Disclose Key Details About Use of China-Based Engineers in U.S. Defense Work, Record Shows The tech giant is required to regularly provide U.S. officials with its plan for keeping government data safe from hacking. Yet a copy of Microsoft’s security plan obtained by ProPublica makes no refe...

BREAKING: Microsoft failed to disclose key details about its use of China-based engineers in Defense Department IT work, according to security document obtained by @propublica.org: www.propublica.org/article/micr...

8 months ago 182 60 6 3
Preview
Microsoft Failed to Disclose Key Details About Use of China-Based Engineers in U.S. Defense Work, Record Shows The tech giant is required to regularly provide U.S. officials with its plan for keeping government data safe from hacking. Yet a copy of Microsoft’s security plan obtained by ProPublica makes no refe...

www.propublica.org/article/micr...

8 months ago 3 3 1 0
Preview
Microsoft Used China-Based Support for Multiple U.S. Agencies, Potentially Exposing Sensitive Data Microsoft says it will no longer use China-based engineers to support the Pentagon. But ProPublica found that the tech giant has relied on its global workforce for years to support other federal…

In addition to its work for the Pentagon, Microsoft has used overseas employees, including China-based personnel, to support the cloud systems of federal departments such as parts of the DOJ, Treasury and Commerce, ProPublica has learned.

By @reneedudley.bsky.social, w/ research by Doris Burke

8 months ago 226 64 10 7
Preview
A few thoughts on this excellent article by Renee Dudley, in which I’m quoted: | John B. Sherman A few thoughts on this excellent article by Renee Dudley, in which I’m quoted: 1. To say I was floored by these revelations would be an understatement. I was too measured in my comments, and I’ll cla...

Very thoughtful response to great @propublica.org reporting by @reneedudley.bsky.social and Doris Burke: www.linkedin.com/feed/update/...

9 months ago 4 2 0 0