Get the latest tech news

Microsoft faulted for ‘cascade’ of failures in Chinese hack


The independent Cyber Safety Review Board’s forthcoming report knocks the tech giant for shoddy cybersecurity, lax corporate culture and a deliberate lack of transparency.

The Cyber Safety Review Board’s report, a copy of which The Post obtained before its official release, takes aim at shoddy cybersecurity practices, lax corporate culture and a deliberate lack of transparency over what Microsoft knew about the origins of the breach. Microsoft’s initial statement about the intrusion was made in July, noting that a China-based adversary had somehow obtained a “signing” key — or digital certificate — allowing the hackers to forge users’ credentials and steal Outlook emails. “It took the creation of something like this board to produce a credible and unbiased assessment of Microsoft’s behavior, which is a necessary step to accountability,” said Jason Kikta, former head of private-sector partnerships at U.S. Cyber Command and now chief information security officer at the IT software firm Automox.

Get the Android app

Or read this on r/technology

Read more on:

Photo of Microsoft

Microsoft

Photo of Chinese

Chinese

Photo of failures

failures

Related news:

News photo

Microsoft's quantum computer may be the most reliable yet

News photo

Microsoft may have finally made quantum computing useful

News photo

Microsoft reveals how much businesses will have to pay to keep using Windows 10 securely