Submission + - Federal Cyber Experts Thought Microsoft's Cloud Was "a Pile of Shit." (propublica.org)
To move federal agencies to the cloud, the government created a program known as FedRAMP, whose job was to ensure the security of new technology.
FedRAMP first raised questions about Microsoft's Government Community Cloud High s security in 2020 and asked Microsoft to provide detailed diagrams explaining its encryption practices. But when the company produced what FedRAMP considered to be only partial information in fits and starts, program officials did not reject Microsoft’s application. Instead, they repeatedly pulled punches and allowed the review to drag out for the better part of five years. And because federal agencies were allowed to deploy the product during the review, GCC High spread across the government as well as the defense industry. By late 2024, FedRAMP reviewers concluded that they had little choice but to authorize the technology — not because their questions had been answered or their review was complete, but largely on the grounds that Microsoft’s product was already being used across Washington.