Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not defender of Microsoft, but I don't know if I could point to any company which does not put profit over security.


I guess the issue becomes when they say security is the top priority (and have been for two decades), yet all actions point towards it not being so.

> Bill Gates in 2002: "So now, when we face a choice between adding features and resolving security issues, we need to choose security."

https://www.wired.com/2002/01/bill-gates-trustworthy-computi...

> Satya Nadella in 2024: "If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security."

https://www.theverge.com/24148033/satya-nadella-microsoft-se...


Turns out businesses have a stated preference for "nice things for the customer/society" but a revealed preference for money.


Would that be securities fraud, because they're lying to investors?

(Going by Matt Levine's "everything is securities fraud" logic here to see if that might actually change behavior…)


Investors are very happy with profit over security choices. Moreover, decisions to maximize profitability thinking only in short term is also not bad for them if they perceive that can sell their shares before the consequences. A company that do not place profit above other things is not a good company to invest money and see it grow. A company will invest in security only as long as it increases profitability. Doing otherwise is not maximizing profits and lose investors. If you are a "security company", surely this means that you need the security to sell the product and get profitability. Other companies will have other tradeoffs to choose how much they invest in security to maximize profitability.


I think securities law usually only applies to things you tell investors? I could be wrong here though, I am not a lawyer.


then the laws need to change so bad security costs companies money.


Obviously, nobody is going to outright admit they put profits above security; indeed, they will often state the opposite. But their closely-held beliefs will shine through when it comes time to make decisions and the outcomes of those decisions are exposed to their customers and to the public.


Does Bill or Satya write code anymore? It could very well be that they consider security the top priority but it's a moot point because they're so removed from operations.

Although I would suspect that you're effectively right in that they either don't have it as a top priority or think they do but have a reveal preference of they don't. For example, an engineer that does rigorous security testing and finds nothing as well as launches one project gets promoted less often than an engineer that launches two projects and doesn't do rigorous security testing.


Profit is an implicitly assumed first priority for basically every business, otherwise the business wouldn't be around.

I don't know of any company that has profit in their slogan, or in the core values statement, etc.


I don’t put “breathe” at the top of my TODO list, either.


Related to the GPs point, do you know of any company that publicly admits that they chose profit above all else?


Unless you care about your review and promotion, in which case do features.


I genuinely think Proton as a company would prefer to cease to exist rather than offer insecure products. In fact there's a lot of offerings I would use (and pay more for) and they could make but choose not to (like a calendar that is not over an airtight protocol and could integrate with my regular calendar clients).


counter point: nordvpn

from day one everyone knew they were fsb pupets, and people are still giving them money.


They are rare, but Mullvad comes to mind immediately. They have made several decisions that directly impacted their bottom line (no recurring subscriptions where they need to keep the customer's credit card on file) to the benefit of their customer's security.


I'm sure there are some companies that realise security (or rather the critical lack of some important aspect of it) can impact profits, but that depends a lot on who their customers are too. Ultimately, if the customers who pay for a vendor's products and services don't value it, then the vendors won't value it either, short of any regulatory or legal requirements that might compel them otherwise. However, given that many large organizations (including governments) are Microsoft customers, it's strange to see in this case. Maybe there's a kind of "it can't happen to us" or "nobody will find out about it" arrogance going on, but they must now be seeing that the reputational damage is likely to have negative impacts, including hurting future profits, down the road.


Microsoft possesses, to put it lightly, a number of government contracts. I think this puts them in a bit of a pickle.


If no company can make security the priority then maybe no company can be trusted with OS development.


Isn’t there a point when a company becomes so big and so impactful to multiple layers of our life, that it should be impossible for them to continue focusing on profit alone?

I’m not talking about regulation per se, but holding humans in charge of such corps more accountable.


I don't think it's going to happen unless we decide to nationalize private services that are vital to people.

Why don't we have a public maps system, or a content sharing platform? Services like google maps/search or youtube by now are part of the infrastructure of our society.

The same way as roads/railways or energy production are publicly owned in many countries the same should happen for digital services. In good parts of Europe railways are publicly built and maintained while the trains are privately owned.


today that means "too big to fail". in wall st it's called "jackpot"


https://en.wikipedia.org/wiki/Lavabit famously shut down rather than compromise its security.


Let's Encrypt

Google Trust Services

Disclaimer: I've worked in both of these :)


Any company with sufficient size will fail to incentivise the things they claim at the top, unfortunately the impacts of decisions (especially during austerity) are poorly understood, so even the supposedly best intending will fail once you reach a size


What products do those two companies sell?


Let's Encrypt and Google Trust Services are both CAs.

LE is of course, a non-profit, so maybe this doesn't apply there.

Google Trust Services operates under Google, and is technically "for profit". But no, we did not put profits over security.


they sell market protection. to google.

it makes crawlers much more expensive. makes everyone depend on their CDNs etc.


Are you referring to google trust services? I don't see how that applies to let's encrypt otherwise.


go make a cost analysis of crawling the entire internet once or twice a day on http vs https and report back


lol are you claiming that https is done to make web crawling more expensive?

Wild.


the most pressing to google at the time was telecom abusing monopoly of mistyped urls to dictate search engine of their choice. but that too.


I'm deeply confused by this?


Agreed it’s deliver value for shareholders >>>>>>>>> everything else


This isn't about Microsoft, per se. This is about the fact that there's no risk for companies who do, even if they're bidding for government work. Hopefully whistleblowers making these things public will lead to the public putting pressure on their elected officials to actually make some regulations with teeth in this area. I'm not holding my breath, but it is something I consider in the voting booth.


In other words, when faced with an existential threat...

* go bankrupt because we can't be secure

* be less secure and stay in business

...guess which one will almost always win.

Microsoft of course, as a multi-trillion-dollar company has no such threat and there's no reasonable excuse for this.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: