Another Supply Chain Vulnerability
微软雇佣中国工程师维护国防部计算机系统,美国监督人员极少,致敏感数据易受攻击。"数字护送员"技术不足,工资低,微软已停止该做法。 2025-7-21 11:4:59 Author: www.schneier.com(查看原文) 阅读量:13 收藏

ProPublica is reporting:

Microsoft is using engineers in China to help maintain the Defense Department’s computer systems—with minimal supervision by U.S. personnel—leaving some of the nation’s most sensitive data vulnerable to hacking from its leading cyber adversary, a ProPublica investigation has found.

The arrangement, which was critical to Microsoft winning the federal government’s cloud computing business a decade ago, relies on U.S. citizens with security clearances to oversee the work and serve as a barrier against espionage and sabotage.

But these workers, known as “digital escorts,” often lack the technical expertise to police foreign engineers with far more advanced skills, ProPublica found. Some are former military personnel with little coding experience who are paid barely more than minimum wage for the work.

This sounds bad, but it’s the way the digital world works. Everything we do is international, deeply international. Making anything US-only is hard, and often infeasible.

EDITED TO ADD: Microsoft has stopped the practice.

Tags: , , ,

Posted on July 21, 2025 at 7:04 AM1 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/07/another-supply-chain-vulnerability.html
如有侵权请联系:admin#unsafe.sh