On Microsoft’s Lousy Cloud Security
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。好的,我先仔细读一下文章。 文章主要讲的是ProPublica揭露了微软的云服务在2024年底被联邦政府的网络安全评估者评为不达标。问题出在微软缺乏详细的安保文档,导致评估者对系统的整体安全性缺乏信心。甚至有团队成员用“一堆shit”来形容这个情况。 接着,政府专家无法保证技术的安全性,而联邦政府却仍然批准了微软的Government Community Cloud High服务,授予了联邦政府的网络安全认证。这使得联邦政府可能面临更大的风险。 用户的需求是用中文总结,控制在100字以内。所以我要抓住关键点:微软云服务未通过评估、缺乏安保文档、联邦政府仍批准、存在安全隐患。 然后组织语言,确保简洁明了。可能的结构是:微软云服务未达标,因缺乏安保文档;联邦政府仍批准使用,存在安全隐患。 检查一下字数是否符合要求。大概控制在80字左右,这样比较合适。 </think> 微软云服务未通过联邦政府安全评估,因缺乏详细安保文档导致信心不足;尽管如此,政府仍批准其使用,引发安全隐患。 2026-4-9 10:51:36 Author: www.schneier.com(查看原文) 阅读量:7 收藏

ProPublica has a scoop:

In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings.

The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica.

Or, as one member of the team put it: “The package is a pile of shit.”

For years, reviewers said, Microsoft had tried and failed to fully explain how it protects sensitive information in the cloud as it hops from server to server across the digital terrain. Given that and other unknowns, government experts couldn’t vouch for the technology’s security.

[…]

The federal government could be further exposed if it couldn’t verify the cybersecurity of Microsoft’s Government Community Cloud High, a suite of cloud-based services intended to safeguard some of the nation’s most sensitive information.

Yet, in a highly unusual move that still reverberates across Washington, the Federal Risk and Authorization Management Program, or FedRAMP, authorized the product anyway, bestowing what amounts to the federal government’s cybersecurity seal of approval. FedRAMP’s ruling—which included a kind of “buyer beware” notice to any federal agency considering GCC High—helped Microsoft expand a government business empire worth billions of dollars.

Tags: , , , ,

Posted on April 9, 2026 at 6:51 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2026/04/on-microsofts-lousy-cloud-security.html
如有侵权请联系:admin#unsafe.sh