top | item 39936579

(no title)

jokab | 1 year ago

> ...cites cost, security, and digital sovereignty...

With the recent XZ Utils backdoor fiasco, I would really think twice with this decision.

Might be worth sticking to MS for a little bit longer, who knows if the backdoor code has been reused somewhere else? Besides, wasnt it a MS employee who uncovered this backdoor?

discuss

order

Alupis|1 year ago

What makes you believe Microsoft Source Code is somehow more immune to bad actors?

antx|1 year ago

It's wasn't just "an MS employee". It was an experienced postgres developer. Someone who understands the benefits of open-source.

We simply don't know how many backdoors there are in closed-source software... do you prefer to live with your head in the sand?

adhamsalama|1 year ago

As if Microsoft never got hacked before...

mairusu|1 year ago

Because the absolute amateur hour of Microsoft using null IV in cryptography (ZeroLogon) and telling you that "it's all fine trust me bro" certainly works better. Yeah. And this isn't the sole example of sheer incompetence from this company, we got like 4 decades of stupidity to go back to.

Also: https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review...

> Microsoft’s decision not to correct, in a timely manner, its inaccurate public statements about this incident, including a corporate statement that Microsoft believed it had determined the likely root cause of the intrusion when in fact, *it still has not*

Anyone still using O365 is absolutely irresponsible.

Shorel|1 year ago

I WannaCry after reading this comment.

redder23|1 year ago

Ridiculously silly to say. Because ONE recent security flaw in open source fucking M$ is better? That is laughable.

But yes, open source is used more by private users and even in government the hackers may target it more. BUT Linux is already in use for like 99% of the internet, all datacenters, everything runs on it. Every big company, even M$ is involved in it heavily, they have their own Linux called Azure Linux or something like that. So it makes zero sense to claim using some shitty close source software they want way too much money for is better. M$ 365 bullshit might as well connect to some online services run by M$ ON LINUX that have bugs exactly that you mention that somehow then also make it to users of office that connects to the net for no reason. I think it's some software as a service crap now.