Asian-News.net is your go-to online destination for comprehensive coverage of major news across Asia. From politics and business to culture and technology, we bring you the latest updates, deep analyses, and critical insights from every corner of the continent. Featuring exclusive interviews, high-quality photos, and engaging videos, we keep you informed on the breaking news and significant events shaping Asia. Stay connected with us to get a 24/7 update on the most important stories and trends. Our daily updates ensure that you never miss a beat on the happenings in Asia's diverse nations. Whether it's a political shift in China, economic development in India, technological advancements in Japan, or cultural events in Southeast Asia, Asian-News.net has it covered. Dive into the world of Asian news with us and stay ahead in understanding this dynamic and vibrant region.

Contacts

  • Owner: SNOWLAND s.r.o.
  • Registration certificate 06691200
  • 16200, Na okraji 381/41, Veleslavín, 162 00 Praha 6
  • Czech Republic

Whistleblower says Microsoft left US govt hackable

by Renee Dudley, with research by Doris Burke

This story was originally published by ProPublica, a Pulitzer Prize-winning investigative newsroom.

Microsoft hired Andrew Harris for his extraordinary skill in keeping hackers out of the nation’s most sensitive computer networks. In 2016, Harris was hard at work on a mystifying incident in which intruders had somehow penetrated a major US tech company.

The breach troubled Harris for two reasons. First, it involved the company’s cloud — a virtual storehouse typically containing an organization’s most sensitive data. Second, the attackers had pulled it off in a way that left little trace.

He retreated to his home office to “war game” possible scenarios, stress-testing the various software products that could have been compromised.

Early on, he focused on a Microsoft application that ensured users had permission to log on to cloud-based programs, the cyber equivalent of an officer checking passports at a border. It was there, after months of research, that he found something seriously wrong.

The product, which was used by millions of people to log on to their work computers, contained a flaw that could allow attackers to masquerade as legitimate employees and rummage through victims’ “crown jewels” — national security secrets, corporate intellectual property, embarrassing personal emails — all without tripping alarms.

To Harris, who previously had spent nearly seven years working for the US Defense Department, it was a security nightmare. Anyone using the software was exposed, regardless of whether they used Microsoft or another cloud provider such as Amazon. But Harris was most concerned about the federal government and the implications of his discovery for national security.

Read more on asiatimes.com