<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I teach cybersecurity.]]></title><description><![CDATA[<p>I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f510.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--closed_lock_with_key" style="height:23px;width:auto;vertical-align:middle" title="🔐" alt="🔐" /> That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:</p><p>🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself<br /><img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f46e.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--cop" style="height:23px;width:auto;vertical-align:middle" title="👮" alt="👮" /> "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f926.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--face_palm" style="height:23px;width:auto;vertical-align:middle" title="🤦" alt="🤦" /><img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3fb.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--skin-tone-2" style="height:23px;width:auto;vertical-align:middle" title="🏻" alt="🏻" />‍<img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️ </p><p>The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy </p><p>If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.</p><p><a href="https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/" rel="nofollow noopener"><span>https://</span><span>arstechnica.com/information-te</span><span>chnology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/</span></a><br /><a href="https://infosec.exchange/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/Microsoft" rel="tag">#<span>Microsoft</span></a> <a href="https://infosec.exchange/tags/FedRAMP" rel="tag">#<span>FedRAMP</span></a> <a href="https://infosec.exchange/tags/Leadership" rel="tag">#<span>Leadership</span></a> <a href="https://infosec.exchange/tags/RiskManagement" rel="tag">#<span>RiskManagement</span></a> <a href="https://infosec.exchange/tags/security" rel="tag">#<span>security</span></a> <a href="https://infosec.exchange/tags/privacy" rel="tag">#<span>privacy</span></a> <a href="https://infosec.exchange/tags/cloud" rel="tag">#<span>cloud</span></a> <a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a></p>]]></description><link>https://forum.fedi.dk/topic/46cdfecd-9c0a-4c1b-8b51-7cdb28b97baa/i-teach-cybersecurity.</link><generator>RSS for Node</generator><lastBuildDate>Tue, 07 Apr 2026 14:32:50 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/46cdfecd-9c0a-4c1b-8b51-7cdb28b97baa.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 29 Mar 2026 23:52:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 05:40:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> THANK YOU for saying this out loud and explaining it so clearly.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/fifonetworks/statuses/116316519089028961</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/fifonetworks/statuses/116316519089028961</guid><dc:creator><![CDATA[fifonetworks@infosec.exchange]]></dc:creator><pubDate>Mon, 30 Mar 2026 05:40:29 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 05:38:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> I call it: <a href="https://media3.giphy.com/media/v1.Y2lkPTZjMDliOTUydG5jcWVjNGdhbzd3dWJzYTBtMGtoMW01enAwNW9zbXJxa3luejJhNSZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw/R9cQo06nQBpRe/giphy.gif" rel="nofollow noopener"><span>https://</span><span>media3.giphy.com/media/v1.Y2lk</span><span>PTZjMDliOTUydG5jcWVjNGdhbzd3dWJzYTBtMGtoMW01enAwNW9zbXJxa3luejJhNSZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw/R9cQo06nQBpRe/giphy.gif</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/Dj4n90/statuses/116316512011176350</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/Dj4n90/statuses/116316512011176350</guid><dc:creator><![CDATA[dj4n90@mastodon.social]]></dc:creator><pubDate>Mon, 30 Mar 2026 05:38:41 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 05:03:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> Social engineering is the ultimate tool to break any security.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.gamedev.place/users/Chagrins/statuses/116316374296438911</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.gamedev.place/users/Chagrins/statuses/116316374296438911</guid><dc:creator><![CDATA[chagrins@mastodon.gamedev.place]]></dc:creator><pubDate>Mon, 30 Mar 2026 05:03:39 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 04:17:19 GMT]]></title><description><![CDATA[<p><a href="/user/brian_greenberg%40infosec.exchange">@brian_greenberg@infosec.exchange</a> I am going to be sooooo mad if we have to bring it all back in house... Well, my workplace probably won't. But yikes 🫠 I am afraid of how cooked our infrastructure is <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f635.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--dizzy_face" style="height:23px;width:auto;vertical-align:middle" title="😵" alt="😵" /></p>]]></description><link>https://forum.fedi.dk/post/https://mypocketpals.online/notes/akg8qx3iel</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mypocketpals.online/notes/akg8qx3iel</guid><dc:creator><![CDATA[crazypedia@mypocketpals.online]]></dc:creator><pubDate>Mon, 30 Mar 2026 04:17:19 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 03:50:47 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> You are supposed to disclose AI-generated content.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/ap/users/116316072903296778/statuses/116316087727669921</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/ap/users/116316072903296778/statuses/116316087727669921</guid><dc:creator><![CDATA[unboundcelestial@mastodon.social]]></dc:creator><pubDate>Mon, 30 Mar 2026 03:50:47 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 03:49:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> you do not have, like, any of your own voice in this post at all. you just shat this out with Claude or whatever. you should feel embarrassed trying to get other people to read this</p>]]></description><link>https://forum.fedi.dk/post/https://yiff.life/users/tael/statuses/116316082647240721</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://yiff.life/users/tael/statuses/116316082647240721</guid><dc:creator><![CDATA[tael@yiff.life]]></dc:creator><pubDate>Mon, 30 Mar 2026 03:49:29 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 03:44:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> AI-written post</p>]]></description><link>https://forum.fedi.dk/post/https://yiff.life/users/tael/statuses/116316064875720892</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://yiff.life/users/tael/statuses/116316064875720892</guid><dc:creator><![CDATA[tael@yiff.life]]></dc:creator><pubDate>Mon, 30 Mar 2026 03:44:58 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 03:32:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> Alternatively, seeing this:</p><p>"FedRAMP’s ruling—which included a kind of “buyer beware” notice to any federal agency considering GCC High—helped Microsoft expand a government business empire worth billions of dollars."</p><p>...That makes me think that we're about to find out that they "Put the warnings after the spells.".</p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.ca/users/AT1ST/statuses/116316015326160495</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.ca/users/AT1ST/statuses/116316015326160495</guid><dc:creator><![CDATA[at1st@mstdn.ca]]></dc:creator><pubDate>Mon, 30 Mar 2026 03:32:22 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 03:27:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> Satya Nadella is getting prime usage out of the documents Bill Gates have him about Trump in the Epstein Files, I presume. I presume Bill Gates gave them those documents in an "In case of emergency, break glass" way, but instead...he's using it to get the U.S. government to say "It's not the best choice, but we can't *not* use it.".</p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.ca/users/AT1ST/statuses/116315994725783435</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.ca/users/AT1ST/statuses/116315994725783435</guid><dc:creator><![CDATA[at1st@mstdn.ca]]></dc:creator><pubDate>Mon, 30 Mar 2026 03:27:08 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Mon, 30 Mar 2026 01:16:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span><br />Critical support to Microsoft for undermining the US gov!</p>]]></description><link>https://forum.fedi.dk/post/https://mstdn.io/users/mikefordays/statuses/116315482108098162</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mstdn.io/users/mikefordays/statuses/116315482108098162</guid><dc:creator><![CDATA[mikefordays@mstdn.io]]></dc:creator><pubDate>Mon, 30 Mar 2026 01:16:46 GMT</pubDate></item><item><title><![CDATA[Reply to I teach cybersecurity. on Sun, 29 Mar 2026 23:55:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/brian_greenberg%40infosec.exchange">@<span>brian_greenberg</span></a></span> the government has always been years behind in defense and right at the edge in offense.  Guess what's easier?</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/noplasticshower/statuses/116315163616279678</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/noplasticshower/statuses/116315163616279678</guid><dc:creator><![CDATA[noplasticshower@infosec.exchange]]></dc:creator><pubDate>Sun, 29 Mar 2026 23:55:46 GMT</pubDate></item></channel></rss>