- cross-posted to:
- technology@lemmy.ml
- cross-posted to:
- technology@lemmy.ml
FedRAMP first raised questions about GCC High’s security in 2020 and asked Microsoft to provide detailed diagrams explaining its encryption practices. But when the company produced what FedRAMP considered to be only partial information in fits and starts, program officials did not reject Microsoft’s application. Instead, they repeatedly pulled punches and allowed the review to drag out for the better part of five years. And because federal agencies were allowed to deploy the product during the review, GCC High spread across the government as well as the defense industry. By late 2024, FedRAMP reviewers concluded that they had little choice but to authorize the technology - not because their questions had been answered or their review was complete, but largely on the grounds that Microsoft’s product was already being used across Washington.



This shouldn’t be fucking legal.