How Microsoft's 'Little Workaround' Created a Major Threat to America's Defense Department (propublica.org) 34
This week Slashdot reader joshuark found the story of exactly how in 2025 ProPublica reporter Renee Dudley confirmed Microsoft was running tech support for the U.S. Defense Department through China, America's biggest cybersecurity adversary — and how that investigation ultimately changed U.S. government policy.
The reporter first found an ad offering $18 to $28 to hire Americans as "digital escorts" for China-based tech support, then just searched LinkedIn for people who apparently had answered the ad. They discovered that at the time "Behind the scenes, unseen by the users at the U.S. government, it's not just one person who responds," explains ProPublica's podcast. "It's two people... The China-based engineer is the one who knows how to fix the problem. On their end, they produce a block of code to solve it and send it over to the digital escort in the U.S. The digital escort then just copy-pastes it... All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data."
But amazingly to confirm it, ProPublica's researcher just had to input "Microsoft" and "escort" into the U.S. Patent Office search bar, and actually found patents related to digital escorts — along with names of the current and former Microsoft employees listed as inventors. Had the government signed off on the practice? "I could see what Microsoft actually told the government," the reporter says on the podcast, "And there was no mention of foreign engineers being used, and definitely no mention of China."
ProPublica's story was published on a Tuesday, according to the podcast, and by Friday "Microsoft said it had stopped using China-based engineers to support Defense Department cloud systems." And America's Defense Department "also opened up an investigation, looking into whether any of Microsoft's China-based engineers had compromised the government's national security.
The reporter first found an ad offering $18 to $28 to hire Americans as "digital escorts" for China-based tech support, then just searched LinkedIn for people who apparently had answered the ad. They discovered that at the time "Behind the scenes, unseen by the users at the U.S. government, it's not just one person who responds," explains ProPublica's podcast. "It's two people... The China-based engineer is the one who knows how to fix the problem. On their end, they produce a block of code to solve it and send it over to the digital escort in the U.S. The digital escort then just copy-pastes it... All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data."
But amazingly to confirm it, ProPublica's researcher just had to input "Microsoft" and "escort" into the U.S. Patent Office search bar, and actually found patents related to digital escorts — along with names of the current and former Microsoft employees listed as inventors. Had the government signed off on the practice? "I could see what Microsoft actually told the government," the reporter says on the podcast, "And there was no mention of foreign engineers being used, and definitely no mention of China."
ProPublica's story was published on a Tuesday, according to the podcast, and by Friday "Microsoft said it had stopped using China-based engineers to support Defense Department cloud systems." And America's Defense Department "also opened up an investigation, looking into whether any of Microsoft's China-based engineers had compromised the government's national security.
You're not paid for situational awareness (Score:3)
Re:And you know this how? (Score:5, Funny)
Calm down Satya.
Re: (Score:3)
I have never worked at MS, but I have been looking at how they do business for 30 years, and "stupidity" is not the correct word.
They are a malicious entity. Think Zuckerberg, but worse.
Re: (Score:2)
Sociopathic may be a better word. They are very unethical, and very greedy.
Re: And you know this how? (Score:2)
One interesting thing about them is that they think that doing bad things is only bad when you're caught.
Not specific to them, though.
Re: (Score:2)
At higher management levels MS is actively evil, so I'm not surprised. Is the DoD the same or is it just stupidity, not malice?
Re: (Score:1)
That's why nearly every single country in the world now reflects on the services of this company which became a security risk on many different levels.
Errr no I think they are doing that because the USA is now ally by name only.
New Heights (Score:5, Insightful)
This is a level of stupid that only Microsoft could pull off. Now, why has Microsoft not been charged with treason? Nadella is the definition of greedy bastard.
Re: (Score:3)
Nobody is that "stupid" in those departments.
The question should be what was the quid pro quo?
We can imagine what the PLA got out of it but what favor did Microsoft get?
And how high up the chain did it go? Who specifically approved the arrangement?
At least Microsoft probably has Windows 11 "backups" of the hard drives of anyone who might think of bringing charges.
Not sure if that strategy can be called stupid. Lots of other words apply.
"One Nation Under Blackmail" is a popular phrase.
Re: (Score:3, Informative)
This is a level of stupid that only Microsoft could pull off. Now, why has Microsoft not been charged with treason? Nadella is the definition of greedy bastard.
And if Trump was true to his own rantings, Nadella would be a "greedy bastard" with his head on a pike in the Oval Office.
But Trump only cares about China as a comic book villain. He uses 'evil' countries to distract MAGA from America's true enemies: oligarchs, corporations, and anyone else with enough cash to bribe politicians, flout the law, and steer the government.
Re: (Score:1)
I hear Rosie O'Donnell has a spare room for rent if you are interested.
Re: (Score:2)
I think it is comparable to the level of stupidity that MS displayed when they started blocking accounts by judges and prosecutor it the International Court of Justice. They could not have made it any clearer that they are not a reliable service provider. Or when the gave the personal identification of Swedish Regulators to the US congress, without even trying to fight that order. Yes, I know the actual extreme stupidity happened here when MS did not oppose the law that created this requirement on them.
Long
Re: (Score:2)
It's not treason unless you do it for the purpose of harming your country or aiding an adversary. This is "only" sharing confidential and potentially classified material out of scope, which is also serious but doesn't call for anyone to be hung by the neck until dead.
Re: (Score:2)
Re: (Score:2)
We'll have "digital escorts" for LLM coding tools (Score:5, Insightful)
DoD: "We have to follow Industry's lead" (Score:5, Insightful)
That's the argument I heard when a defense contractor about why so many DoD systems specified Microsoft products, particularly Active Directory.
Of course, "following industry standards" relieves one of the responsibility of actually thinking about what you're buying, including life-cycle costs and security & quality of the products. In that way, DoD was no different than all the other CIOs. Microsoft understood that CIOs were their real customer, and did everything to convince CIOs that Microsoft (regardless of cost) was 'the least risk alternative."
Re: (Score:2)
For CIOs like ours that inherited a 'best of breed, now make them work together' system, they preferred to spend a little more $$$ on product licensing to save on integration spend - and the consequent headaches every time anyone decided to release a new version of their product...
It's also easier to blame the one vendor you have rathe
Digital Escorts (Score:3)
So, these people hired as digital escorts are vetted for security clearances, right? Because they will be handling "sensitive data". And as a part of receiving that clearance, they will be informed of their duties and responsibilities when handling said "sensitive data". Or no?
All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data.
That's what we call a necessary condition. Not a sufficient condition.
Re: (Score:2)
This is what everyone needs to understand when they say "we should have a public..." or "why did we privatize this".
If you have actual experience doing any work from the government you know that huge portion of it is compliance costs, realistically it absolutely is something like 40% probably.
First there is the upfront bits of doing an RFP that looks like nobody else's
then there is proving you have the required mix of ethic and gender representation (if you actually want to win)
after that comes the recordin
Re: (Score:2)
I tried this out a while ago with my then-boss. We found that you need two (!) supervising engineers and they need to be significantly more competent that the one doing the work for this idea to actually deliver _and_ you need to slow down things massively. Say, one (!) command or line of code per hour or worse. He had no problems sneaking stuff past me, I had no problems sneaking stuff past him.
Distinction (Score:1)
There's a difference between asking an overseas consultant "what buttons do I push to un-jam the purple gizmo?" and between "Enter these new users for me."
Typical geeks (Score:2)
Re: Typical geeks (Score:2)
Unless you're very, very kinky.
White Monkey Jobs (Score:1)
China layoff (Score:2)
Microsoft had a layoff in China in June. I imagine this "workaround' isn't a thing anymore.
If they were working on opensource code, they could end up working on it upstream and still contributing.
So digital escorts for all other "normal" clients? (Score:2)
They stopped using Chinese engineers for US Gov related matters.
What about for other clients?
Deliberate wrongdoing (Score:2)