{"id":4094,"date":"2024-06-18T09:00:00","date_gmt":"2024-06-18T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/software-licensing-disease-infecting-our-nations-cybersecurity"},"modified":"2024-06-18T09:00:00","modified_gmt":"2024-06-18T14:00:00","slug":"the-software-licensing-disease-infecting-our-nations-cybersecurity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/18\/the-software-licensing-disease-infecting-our-nations-cybersecurity\/","title":{"rendered":"The Software Licensing Disease Infecting Our Nation&#8217;s Cybersecurity"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt7175a6bf352b31df\/66718d43b01d0eff69461c14\/Capitol%281800%29_Michael_Urmann_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last month, Microsoft president Brad Smith was confronted by the US House Committee on Homeland Security, in a&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/homeland.house.gov\/2024\/05\/21\/chairman-green-ranking-member-thompson-announce-microsoft-president-will-testify-on-companys-security-shortcomings-following-hack-of-government-accounts\/\" rel=\"noopener\">hearing over the cybersecurity woes<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;that have plagued the government as a direct result of the company&#8217;s security shortcomings. These issues, however, don&#8217;t just come down to insecure products. They&#8217;re symptoms of a larger disease \u2014 a lapse in market and competition policy that has allowed Microsoft to dominate virtually all of the public sector technology market. And the US government&#8217;s failure to properly diagnose the deeper cause puts us all at risk.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2024-04-15\/microsoft-beset-by-hacks-grapples-with-problem-years-in-the-making\" rel=\"noopener\">Microsoft, by its own admission<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, is&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/microsoft-falls-victim-russian-midnight-blizzard-cyberattack\" rel=\"noopener\">ground zero for state-sponsored hacking groups<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and flaws in the company&#8217;s software have been responsible for a huge proportion of cyber breaches affecting the US government in recent memory. Our country&#8217;s cyber watchdogs \u2014 the Department of Homeland Security&#8217;s Cybersecurity and Infrastructure Security Agency (CISA) and Cyber Safety Review Board (CSRB) \u2014 have spent considerable resources assessing these incidents and trying to assess and address Microsoft&#8217;s vulnerabilities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s a fundamental problem with this process. The government is confusing symptoms \ufffd\ufffd\u2014 persistent hacks, breaches, and vulnerabilities \u2014 with an underlying disease: the lack of competition around cybersecurity. Microsoft has systematically exploited weaknesses in procurement processes to stifle competition and lock government customers into its insecure technology. That confusion ultimately leaves the government&#8217;s tools to enhance competition on the sidelines, when those tools are the best remedy for cyber insecurity.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Problem With Microsoft's Market Share\">The Problem With Microsoft&#8217;s Market Share<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft holds an&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/omdia.tech.informa.com\/-\/media\/tech\/omdia\/marketing\/commissioned-research\/pdfs\/monoculture-and-market-share-the-state-of-communications-and-collaboration-software-in-the-us-government-v3.pdf?rev=8d41cc2d16de491b9f59d2906309fdaa\" rel=\"noopener\">85% market share<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;of government collaboration and communications technology and now is awarded at least&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.theregister.com\/2023\/02\/01\/oracle_microsoft_us_government\/\" rel=\"noopener\">a quarter of its contracts<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;without any meaningful competition. It&#8217;s reached this position through a series of&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/omdia.tech.informa.com\/-\/media\/tech\/omdia\/marketing\/commissioned-research\/pdfs\/monoculture-and-market-share-the-state-of-communications-and-collaboration-software-in-the-us-government-v3.pdf?rev=8d41cc2d16de491b9f59d2906309fdaa\" rel=\"noopener\">deliberate, anticompetitive moves<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;the government has largely neglected. Stretched government procurement officers and chief information security officers (CISOs) are taking the path of least resistance. That&#8217;s not their fault; it&#8217;s a difficult consequence of their job. But Microsoft exploits this by making it&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/docs.servicenow.com\/en-US\/bundle\/utah-it-asset-management\/page\/product\/software-asset-management2\/reference\/byol-license-rules.html\" rel=\"noopener\">expensive and difficult<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to run its software on a competitor&#8217;s cloud, including&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/azure.microsoft.com\/en-us\/pricing\/azure-vs-aws\/cost-savings\/\" rel=\"noopener\">charging a five-times premium<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;just to use Word on Amazon&#8217;s cloud instead of its own Azure cloud service. Microsoft bundles&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/enterprise\/compare-office-365-plans\" rel=\"noopener\">dozens of ancillary applications<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;with its Office productivity apps in its licenses (including Access, Delve, Viva, and others), which stifles competition by linking basic, widely used services with less popular ones and pricing them as free.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The result? A software monoculture with a simple attack surface for the United States&#8217; adversaries with nearly a single point of failure: Microsoft. This is a major threat to national security. The potential harm is real and expensive.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.statista.com\/statistics\/1003402\/us-cybersecurity-spending-cfo-act-agencies\/\" rel=\"noopener\">The US government spent more than $11.1 billion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on cybersecurity in 2023, in large part trying to compensate for and respond to the Microsoft incidents that left it vulnerable to intrusion.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some lawmakers are ready to take action.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.wyden.senate.gov\/news\/press-releases\/wyden-releases-draft-legislation-to-end-federal-dependence-on-insecure-proprietary-software-in-response-to-repeated-damaging-breaches-of-government-systems\" rel=\"noopener\">Senator Ron Wyden recently drafted legislation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\ufffd&nbsp;that would require the government to set new standards for collaboration software in response to a CSRB report. It&#8217;s a good step, but it solves only part of the problem. Even if the government&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">can<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;collaborate with other providers while using Microsoft&#8217;s software, the company&#8217;s licenses still make it very expensive, all at a major cost to the taxpayer.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Better Solution Is Needed\">A Better Solution Is Needed<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The government must use all the tools at its disposal to create a more comprehensive solution that immediately targets the root cause of its cybersecurity woes:&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/microsoft-wants-you-to-watch-what-it-says-not-what-it-does\" rel=\"noopener\">Microsoft&#8217;s anticompetitive licensing restrictions<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. These tools include using the General Services Administration (GSA) to modify procurement processes as a means of bolstering national security. The GSA is responsible for providing agencies with cost-effective, high-quality products from diverse vendors, and the evidence is clear that Microsoft doesn&#8217;t meet these standards. The GSA can take action by either negotiating better licensing conditions with the company or by looking at other vendors to help diversify the government&#8217;s tech infrastructure. That would be a strong and timely step to set the stage for more comprehensive and sweeping competition policy action by the Federal Trade Commission (FTC) or the Department of Justice. It&#8217;s also a step that wouldn&#8217;t take years to implement \u2014 which is vital given the current and future costs of Microsoft&#8217;s efforts to lock government customers into long-term contracts. The longer the government waits, the harder the lock-in will be to reverse.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It can&#8217;t settle for identifying symptoms. Microsoft&#8217;s licensing is responsible for a debilitating disease that has infected our government&#8217;s tech infrastructure. Allowing major government contracts to be awarded to any one company \u2014 in this case, Microsoft \u2014 is only plausible if procurement officials believe they really don&#8217;t have any other choice. But we already have the remedies necessary to level the playing field and make enterprise software vendors accountable for weak cybersecurity. Forcing Microsoft to compete fairly is the most important next step to build a better defense against foreign actors. We have multiple tools to create a level playing field. We just need to use them.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/software-licensing-disease-infecting-our-nations-cybersecurity\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Last month, Microsoft president Brad Smith was confronted by<\/p>\n","protected":false},"author":12,"featured_media":4095,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4094","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=1804%2C1021&ssl=1",1804,1021,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=300%2C170&ssl=1",300,170,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=640%2C363&ssl=1",640,363,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=640%2C363&ssl=1",640,363,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=1536%2C869&ssl=1",1536,869,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=1804%2C1021&ssl=1",1804,1021,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=1024%2C580&ssl=1",1024,580,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/the-software-licensing-disease-infecting-our-nations-cybersecurity.jpg?fit=1804%2C1021&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4094"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4094\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4095"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}