{"id":28956,"date":"2023-07-20T11:25:26","date_gmt":"2023-07-20T15:25:26","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=28956"},"modified":"2023-07-20T11:29:15","modified_gmt":"2023-07-20T15:29:15","slug":"calling-the-wakeman-microsoft-shills-for-cmmc-but-cant-manage-its-own-cybersecurity","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/calling-the-wakeman-microsoft-shills-for-cmmc-but-cant-manage-its-own-cybersecurity\/","title":{"rendered":"Calling The Wakeman! Microsoft Shills for CMMC, But Can&#8217;t Manage Its Own Cybersecurity"},"content":{"rendered":"<p>The Wakeman isn&#8217;t the hero Gotham needs, but he is the hero it deserves.<\/p>\n<div id=\"attachment_28958\" style=\"width: 135px\" class=\"wp-caption alignright\"><a href=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/wakemanappearnances.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-28958\" class=\"wp-image-28958\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/wakemanappearnances.jpg\" alt=\"\" width=\"125\" height=\"488\" \/><\/a><p id=\"caption-attachment-28958\" class=\"wp-caption-text\">Just some of Wakeman&#8217;s CMMC appearances over the past few years.<\/p><\/div>\n<p>Anyone paying attention to the <a href=\"https:\/\/www.oxebridge.com\/emma\/?s=cmmc\">CMMC debacle<\/a> for more than five minutes has undoubtedly been exposed to the endless shilling by Microsoft&#8217;s <a href=\"https:\/\/www.linkedin.com\/in\/wakeman\">Richard Wakeman<\/a>, a guy who pulled off a neat career trick by apparently being first at MS to jump into the CMMC scene, thus ensuring his top spot at MS as their go-to expert. Wakeman convinced Microsoft to go all-in on CMMC, and is now the &#8220;<em>Senior Director of Aerospace and Defense for\u00a0Azure Global<\/em>&#8221; at MS. He&#8217;s also been present at nearly every CMMC convention ever held since the dinosaurs roamed the Earth, and was a constant, <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/public-sector-blog\/neosystems-ciso-ed-bassett-and-microsoft-senior-director-richard\/ba-p\/2660865\">near-nagging voice<\/a> telling people to adopt CMMC as soon as they could.<\/p>\n<p><span style=\"font-size: 14pt;\"><strong>The Jokes Write Themselves<\/strong><\/span><\/p>\n<p>To those of us with functioning critical thinking faculties, it&#8217;s always been a matter of when, not if, the punchline would write itself. There&#8217;s no company whose products are more hacked than those of Microsoft, and their billion-year history is an ongoing, real-time case example of how <em><strong>not<\/strong> <\/em>to release secure products. For decades, IT professionals around the world have insisted the best way to secure a Microsoft-based system was to<em><strong> switch to Linux<\/strong><\/em>. (Like here in <a href=\"https:\/\/wideangle.co\/blog\/privacy-security-linux-desktop\">2022<\/a>, or here in <a href=\"https:\/\/bigstep.com\/blog\/windows-linux-challenges-benefits-making-change\">2015<\/a>, or here in <a href=\"http:\/\/www.win3x.org\/win3board\/viewtopic.php?t=1103\">2001<\/a>, or here in <a href=\"https:\/\/www.tech-insider.org\/linux\/research\/1999\/0216-a.html\">1999<\/a>, or here in <a href=\"https:\/\/www.linuxjournal.com\/article\/2734\">1994<\/a>, or&#8230; well,\u00a0 you get the point.)<\/p>\n<p>Now, in 2023, nearly four years after Katie Arrington slurred her words and promised CMMC was imminent any day now, we see that Microsoft&#8217;s Azure platform &#8212; you know, the one that <em><strong>WAKEMAN IS SENIOR DIRECTOR OF<\/strong><\/em>, was <a href=\"https:\/\/thehackernews.com\/2023\/07\/microsoft-bug-allowed-hackers-to-breach.html\">hacked by China<\/a>.<\/p>\n<blockquote><p>Microsoft on Friday said a validation error in its source code allowed for Azure Active Directory (Azure AD) tokens to be forged by a malicious actor known as\u00a0Storm-0558\u00a0using a Microsoft account (MSA) consumer signing key to breach two dozen organizations.<\/p>\n<p>The attacks singled out approximately 25 organizations, including government entities and associated consumer accounts, to gain unauthorized email access and exfiltrate mailbox data.<\/p><\/blockquote>\n<p>In case you missed the subhead, I said that <a href=\"https:\/\/techcrunch.com\/2023\/07\/17\/microsoft-lost-keys-government-hacked\/\"><em><strong>China hacked Microsoft Azure:<\/strong><\/em><\/a><\/p>\n<blockquote><p>Microsoft still doesn\u2019t know \u2014 or want to share \u2014 how China-backed hackers stole a key that allowed them to stealthily break into dozens of email inboxes, including those belonging to\u00a0several federal government agencies.<\/p><\/blockquote>\n<p>It gets <em><strong>worse<\/strong><\/em>. According to <a href=\"https:\/\/www.cnn.com\/2023\/07\/19\/tech\/microsoft-free-cybersecurity-tools-china-hack\/index.html\">CNN<\/a>, &#8220;<em>the email accounts of Commerce Secretary Gina Raimondo and State Department officials were breached in the activity.<\/em>&#8221; That same report reveals that it wasn&#8217;t even Microsoft that discovered the hack &#8212; presumably because Wakeman was too busy on the CMMC speaking circuit &#8212; but the US State Department, which &#8220;<em>detected the cyber activity in June and reported it to Microsoft<\/em>.&#8221;<\/p>\n<p>This comes as a surprise to maybe one person (Wakeman, I presume) and no one else.<\/p>\n<p>Did I mention that China hacked Azure?\u00a0Now remember that the Dept. of Defense gave oversight authority over the CMMC scheme to the IAAC, a <a href=\"https:\/\/www.iaac.org.mx\">group out of Mexico<\/a>, which itself answers to the IAF, which counts as one of its executives a <em><strong>literal member of the Chinese Communist Party<\/strong><\/em>, <a href=\"https:\/\/iaf.news\/2020\/06\/30\/iaf-chairs-message\/\">Xiao Jianhua<\/a>:<\/p>\n<div id=\"attachment_28960\" style=\"width: 510px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/IAFtaxreturnxiao2021.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-28960\" class=\"wp-image-28960\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/IAFtaxreturnxiao2021.jpg\" alt=\"\" width=\"500\" height=\"270\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/IAFtaxreturnxiao2021.jpg 974w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/IAFtaxreturnxiao2021-150x81.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/IAFtaxreturnxiao2021-200x108.jpg 200w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/07\/IAFtaxreturnxiao2021-768x414.jpg 768w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/a><p id=\"caption-attachment-28960\" class=\"wp-caption-text\">Capture from official IAF tax return for 2021 showing CCP member Xiao Jianhua as an officer. The DoD has put the IAF in charge of the CMMC Accreditation Body. Source: <a href=\"https:\/\/projects.propublica.org\/nonprofits\/organizations\/391952160\"><em>Nonprofit Explorer.<\/em><\/a><\/p><\/div>\n<p>That means that any complaint filed in the CMMC system will eventually be adjudicated by foreign actors, potentially from China itself.<\/p>\n<p><span style=\"font-size: 14pt;\"><strong>Here There Be Shysters<\/strong><\/span><\/p>\n<p>The reality is that nearly no one &#8212; <em><strong>not a single person<\/strong><\/em> &#8212; involved in the CMMC scam is trustworthy. In nearly every case, we find they are wholly unqualified or untalented or just boozy gimps who you wouldn&#8217;t trust lending your car to, never mind relying on for cybersecurity advice. These people are self-promoting bottom feeders, whose only chance at success relies on finding some Ponzi scheme or multi-level-marketing scam to propel their career, which inevitably comes falling back down to earth like the meteor because eventually people see through it. Look at the giant crater left by Arrington&#8217;s fall from grace, for example. Do you know how many mammals were killed in that extinction event?<\/p>\n<p>If I was Bob Metzger or Jacob Horne, I&#8217;d be seriously considering switching to selling Amway or Cayman Island timeshares right about now. I mean, hell, they are certainly qualified, and <a href=\"https:\/\/variety.com\/2022\/film\/news\/armie-hammer-hotel-concierge-caymans-1235310475\/\">Armie Hammer could probably use the company<\/a>.<\/p>\n<p>But this won&#8217;t stop Wakeman from shilling for a product that his own company hasn&#8217;t even utilized, nor from joining the increasingly-ridiculous chorus of idiots claiming that CMMC is the cure for everything from Chinese hacks to toenail cancer. Oh, no, he&#8217;s all set to walk on stage and brave full-on public humiliation at <a href=\"https:\/\/www.businesswire.com\/news\/home\/20230606005285\/en\/Stay-Ahead-of-CMMC-2.0-Registration-Opens-for-CyberSheath%E2%80%99s-CMMC-CON-2023\">&#8220;CMMC Con&#8221; this September<\/a>, where &#8212; like Comic Con &#8212; apparently there will be lots of cosplay, where nerds with <a href=\"https:\/\/memory-alpha.fandom.com\/wiki\/Spock_(mirror)\">Evil Spock Beards<\/a> dress up as serious cybersecurity professionals.<\/p>\n<p>The only question anyone should be asking Wakeman at any event is this: <em><strong>if CMMC is so great, why does China have the keys to Microsoft Azure?<\/strong><\/em><\/p>\n<p>I&#8217;d ask him personally, but the delicate flower has me blocked on LinkedIn, like nearly every other CMMC mouthpiece, because God forbid they should hear anything that would upset their flimsy worldview.<\/p>\n<p><span style=\"font-size: 14pt;\"><strong>Hey, DoD: Fix This!<\/strong><\/span><\/p>\n<p>CMMC cannot succeed because it is based on faulty principles and was launched as a corrupt scheme to reward a few DoD flunkies and their private-sector pals. Worse, it&#8217;s been proven not to have any effect on China&#8217;s ambitions, and it doesn&#8217;t matter because the morons at DoD have already decided that <em><strong>China should oversee the entire CMMC program anyway<\/strong><\/em>. (And, no, <a href=\"https:\/\/www.oxebridge.com\/emma\/the-8-solution-for-cmmcs-china-problem\/\">I am not kidding<\/a>.) The DoD must dismantle this nightmare as soon as possible, and look at real ways to ensure the nation&#8217;s defense on the cyber front, without the cronyism, corruption, and collusion. By doing so, we might finally free ourselves of idiots like Wakeman.<\/p>\n<p>And if you&#8217;re wondering why I&#8217;m upset about this, consider the millions of dollars being spent right now by companies and individuals buying useless CMMC credentials and preparing for unlikely CMMC &#8220;assessments.&#8221; You think Wakeman is going to reimburse you?<\/p>\n<p><em>[In case it needs to be repeated, the above is my <strong>opinion<\/strong> and must be treated that way. So be sure to include this footer in any copy you send to your attorney.]\u00a0<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft&#8217;s Richard Wakeman is head of Azure, which was hacked by China. Awkward.<\/p>","protected":false},"author":2,"featured_media":28959,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[7774,5],"tags":[7679,938,7683,939,8348,7681,8347,8346,8233],"class_list":["post-28956","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cmmc","category-opinion","tag-cmmc","tag-cybersecurity","tag-cybersecurity-maturity-model-certification","tag-hack","tag-jacob-horne","tag-katie-arrington","tag-microsoft","tag-richard-wakeman","tag-robert-metzger","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/28956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=28956"}],"version-history":[{"count":4,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/28956\/revisions"}],"predecessor-version":[{"id":28964,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/28956\/revisions\/28964"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/28959"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=28956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=28956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=28956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}