<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://piotrmackowski.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://piotrmackowski.com/" rel="alternate" type="text/html" /><updated>2026-03-23T22:01:54+01:00</updated><id>https://piotrmackowski.com/feed.xml</id><title type="html">Piotr’s Blog</title><author><name>Piotr Maćkowski</name></author><entry><title type="html">There is no convenient sovereign cloud</title><link href="https://piotrmackowski.com/There-is-no-convenient-sovereign-cloud/" rel="alternate" type="text/html" title="There is no convenient sovereign cloud" /><published>2026-01-05T00:00:00+01:00</published><updated>2026-01-05T00:00:00+01:00</updated><id>https://piotrmackowski.com/There%20is%20no%20convenient%20sovereign%20cloud</id><content type="html" xml:base="https://piotrmackowski.com/There-is-no-convenient-sovereign-cloud/"><![CDATA[<p>For years, Europeans have lived comfortably, storing and processing data on servers located in the EU, i.e. on servers physically in the EU, but legally controlled by foreign entities. We celebrated compliance audits and built data centers across the continent, believing that physical location equaled digital safety. But what good is data residency compliance if you cannot be certain you can access your data tomorrow?</p>

<h2 id="the-sovereign-lie">The Sovereign Lie</h2>
<p>Usually, when we talk about sovereign cloud, we tend to think in terms of confidentiality. Can someone get to our data? Let’s store it on a public cloud server in a data center in the EU, then it will be safe and the compliance folks will be happy. There were concerns with this approach, so the providers introduced the so-called sovereign clouds to protect their market share:</p>
<ul>
  <li><a href="https://www.microsoft.com/en-us/ai/sovereign-cloud">Microsoft</a></li>
  <li><a href="https://aws.eu/">AWS</a></li>
  <li><a href="https://cloud.google.com/sovereign-cloud">GCP</a></li>
</ul>

<p>Seemingly the same cloud, but sovereign. True sovereignty requires complete independence. A US tech company selling a ‘sovereign’ cloud in the EU is a contradiction in terms. Often the wording is chosen carefully, such as ‘operational sovereignty’ - maybe the operations are independent when Azure is deployed on-prem, but there is no control over the supply chain security and this is somehow conveniently forgotten by the marketing and sales teams, and their clients.
In reality, the US CLOUD Act overpowers any local regulations - the US can force any US-based cloud provider (or their foreign subsidiaries) to disclose data, no matter where the data is stored. Jurisdiction follows the provider, not the server - data residency doesn’t matter. This directly conflicts with the GDPR requirements and renders the aforementioned sovereignty claims useless. Thorough analysis has been done on this topic - I recommend <a href="https://www.igorslab.de/en/us-laws-allow-access-to-european-cloud-data-internal-report-by-interior-ministry-confirms-risks-to-digital-sovereignty/">the report for the German Federal Ministry of the Interior</a> for a deep dive. It’s worth noting that it is not just the US - <a href="https://bezprawnik.pl/chinskie-samochody-moga-nas-szpiegowac-i-to-wcale-nie-jest-teoria-spiskowa/">China has a similar law</a>, which can force companies to hand over data collected outside China.</p>

<p>US hyperscalers attempt sovereign washing and even though it <a href="https://www.forbes.com/sites/emmawoollacott/2025/07/22/microsoft-cant-keep-eu-data-safe-from-us-authorities/">backfired under oath</a>, their efforts are maintained nevertheless. E.g. Microsoft’s partners are encouraged to specialize in Digital Sovereignty - <a href="https://partner.microsoft.com/en-us/asset/collection/digital-sovereignty-specialization-assets#/">here</a> is the learning path in case you are interested. <a href="https://www.thomasmaurer.ch/2025/11/introducing-the-digital-sovereignty-specialization-for-the-microsoft-ai-cloud-partner-program/">This blog post</a> repeats the narrative. AWS even established <a href="https://www.datacenterdynamics.com/en/news/aws-establishes-european-sovereign-cloud-as-separate-company/">a separate entity</a> to muddy the PR waters, while pretending the Cloud Act doesn’t affect its subsidiaries. 
Besides the regulatory misconceptions, the obvious must be stated: those sovereign cloud products are fairly new and considering that the public concern in Europe is growing, the demand is likely not sufficient to offset the development costs. As a result, some sovereign clouds lack features that you are used to in global clouds, and simply switching to a ‘sovereign’ endpoint will break your workflows. Don’t be surprised if a solution architect advises against the sovereign cloud way, if you are not obliged to use it.</p>

<p>Governments spying on each other and their citizens is not something we haven’t seen before. Fern has recently published an excellent documentary on <a href="https://www.youtube.com/watch?v=qqJSXoa5ZtQ">NSA’s Spy Hub, the 33 Thomas Street Building</a>, which started tapping lines 50 years ago. In 2003, when faced with public outcry because of mass surveillance (wiretapping without a warrant) concerns, US renamed its <a href="https://en.wikipedia.org/wiki/Information_Awareness_Office">Total Information Awareness</a> program to Terrorism Information Awareness. 
The Snowden files revealed you don’t have to be a terrorist for NSA to keep an eye on you - German Chancellor Angela Merkel and French President Emmanuel Macron found out <a href="https://www.forbes.com/sites/jonathanponciano/2021/05/31/macron-and-merkel-condemn-us-spying-after-new-wiretapping-report/">the hard way</a>.</p>

<h2 id="the-kill-switch-its-not-theoretical-anymore">The Kill Switch: It’s Not Theoretical Anymore</h2>
<p>If confidentiality is not a given, what about availability or in the event of an unavailable cloud, the increasing dependency for core services? Consider how availability shapes policy making, while Big Tech strengthens its grip on our society.
Unavailability can be either intended or not intended. Recent years were eventful in both cases. As easy as public cloud scales, it can also scale down.
Not intended global incidents like Azure, AWS and Cloudflare displayed clearly how dependent many services are. Downdetector now has its own <a href="https://downdetectorsdowndetector.com/">downdetector</a>. If your web application is not stable, just generate a fake <a href="https://github.com/donlon/cloudflare-error-page">Cloudflare error page</a> and blame it on them. 
Intended unavailability happened on a smaller scale, though it was enough to give food for thought:</p>
<ul>
  <li>Six judges and three prosecutors at the International Criminal Court have been <a href="https://www.heise.de/en/news/How-a-French-judge-was-digitally-cut-off-by-the-USA-11087561.html">sanctioned by the Trump administration</a> for calling out <a href="https://www.bbc.com/news/articles/cde3eyzdr63o">the genocide in Gaza</a> and issuing arrests warrants. Being sanctioned by the US means that you are cut off from the banking system and US companies must close your accounts. You cannot even book a hotel in Europe through a US intermediary website. <a href="https://nltimes.nl/2025/05/20/microsofts-icc-email-block-triggers-dutch-concerns-dependence-us-tech">Microsoft has blocked the email accounts of ICC members</a> and later denied doing it. This resulted in <a href="https://www.handelsblatt.com/technik/it-internet/software-strafgerichtshof-ersetzt-microsoft-durch-deutsche-loesung/100166382.html">ICC switching to the German office suite Open Desk</a>. For context, the ICC is <a href="https://en.wikipedia.org/wiki/International_Criminal_Court">recognized only by a part of the world as a court</a> and considered a rather political instrument. E.g. China, Russia, the US and India do not recognize the ICC - this limits its impact drastically. Of those superpowers, only the US has the ability to effectively impose sanctions if the ICC does something that does not please the US. Given that the ICC has not been recognized by the US since George Bush, it is weird that such an international organization still had core suppliers in that country.</li>
  <li>YouTube has <a href="https://theintercept.com/2025/12/07/youtube-deleted-journalist-israel-palestine-censorship/">deleted the account of an independent British journalist</a>.</li>
  <li><a href="https://www.chamber-international.com/news/latest-news/solvent-but-bankrupt-how-sanctions-felled-amsterdam-trade-bank/">The Amsterdam Trade Bank</a>, which was partially owned by Russian oligarchs, had to declare bankruptcy even though it was solvent, as Russia invaded Ukraine and the sanctions forced Microsoft to block the accounts of all employees. The bank also lost access to payment systems.</li>
</ul>

<h2 id="the-munich-saga">The Munich Saga</h2>
<p>While it’s easy to go into the solution mode and debate how to fix the current situation, looking at few cases helps to understand what we’re dealing with in terms of vendor lock-ins and strategies employed by providers to win and/or keep the market share. Germany is interesting to start with, as their view on data, and who can access what and why, is stricter than that of the rest of the world. This applies not only to the government but also to the citizens themselves.</p>

<p>In 2003, the city of Munich was the first to attempt freeing itself from Microsoft’s grip. The project, coined LiMux, aimed to migrate 15,000 workstations to Linux and LibreOffice and was <a href="https://www.theregister.com/2013/12/16/munich_signs_off_on_open_source_project/?ref=itsfoss.com">successfully completed in 2013</a>. Christian Ude, Munich’s mayor at the time, supported the project for more than a decade. Back in the day when the decision to migrate to Linux was first made, he was famously <a href="https://interoperable-europe.ec.europa.eu/collection/open-source-observatory-osor/document/limux-it-evolution-open-source-success-story-never?ref=itsfoss.com">targeted by Microsoft CEO Steve Ballmer and Bill Gates</a>:</p>
<ul>
  <li>Steve Ballmer, who called Linux a cancer, attempted to win Ude over by offering a large discount on licensing costs, though it is unknown for how long those licenses would be discounted. Supposedly, Ballmer even sacrificed his ski trip in Switzerland to visit Ude in person.</li>
  <li>Bill Gates gave Ude a ride from a conference to the airport in his limousine solely to talk to him about his motivations behind choosing free software.</li>
</ul>

<p>Christian Ude was a problematic mayor for Microsoft, to say the least. In 2014 Dieter Reiter assumed office as mayor of Munich. Before the election, he happened to refer to himself as a Microsoft fan. Not surprisingly, Reiter was also against open-source software. In 2017 Munich witnessed <a href="https://fsfe.org/news/2017/news-20170301-01.html">a change in strategy</a> - the city council voted to return to Windows by 2020, i.e. to create a Windows 10 client. This decision was rather political. <a href="https://itsfoss.com/munich-linux-failure/">Allegedly</a>, as part of the deal Microsoft was to move its German headquarters to Munich, which it did. Reiter, the new mayor, helped with the move and was proud of his involvement. 
Fast forward to 2020, Munich’s newly elected officials believe in the principle of <a href="https://publiccode.eu/en/">public money, public code</a> and take a U-turn: <a href="https://www.zdnet.com/article/linux-not-windows-why-munich-is-shifting-back-from-microsoft-to-open-source-again/">the city will use open-source software after all</a>.</p>

<p>Very conveniently, Microsoft placed its headquarters just next to the headquarters of the CSU, Germany’s biggest party at the time.</p>

<p><img src="/assets/images/aws-ms-csu.jpg" alt="CSU-MS-AWS" /></p>

<p>Additionally, Microsoft has <a href="https://www.microsoft.com/de-de/berlin/default.aspx">an office in Berlin</a> , which is seemingly only dedicated to lobbying, and they are very honest about it on their main page:
<code class="language-plaintext highlighter-rouge">"In the heart of Berlin, we bring digitalization to life and engage with current issues in digital policy. This makes Microsoft Berlin a meeting point for anyone interested in politics and technology."</code> 
In November 2025, Amazon has opened its new MUC21 office just across the street. It’s hard to pinpoint the exact date, as no official press release about this can be found, but there are multiple LinkedIn posts from people happy to work 5 days a week from their new office. 
The physical proximity of these headquarters to Germany’s politicians underscores the lobbying weight US hyperscalers place on politics - influence that European providers might struggle to match.
Google isn’t sitting quietly either. In September 2024, it launched an <a href="https://cloud.google.com/blog/de/topics/inside-google-cloud/eroffnung-des-experience-centers-im-cloud-space-munchen?hl=de">Experience Center in Munich</a> - the Google Cloud Space has 900 m2. The market needed sovereignty, and Google is here to save the day - their first <a href="https://www.googlecloudpresscorner.com/2025-11-12-Google-Cloud-Launches-First-Sovereign-Cloud-Hub-in-Munich-to-Accelerate-European-Innovation?linkId=17703050">Sovereign Cloud Hub</a> was opened last year and celebrated by hosting <a href="https://cloud.google.com/events/digital-sovereignty-summit-munich?hl=de">the Digital Sovereignty Summit</a>. Google mentions it’s co-located with an existing security hub, so this looks more like a rebranding than a new investment.</p>

<p>There is of course nothing wrong with the marketing machine of big companies doing its work, but the narrative is of questionable character - especially when you compare the PR measures of Microsoft, Amazon and Google to the relatively limited resources, knowledge and power European players have. On one hand it is understandable that those providers are trying to respond to our market needs - it’s a chunk of their revenue - but on the other hand, just being honest about the legal limitations is also an option.</p>

<p>I do wonder what the location criteria of Microsoft, Amazon and Google are, when they pick one for a digital sovereignty experience initiative. For instance, Germany and France are proactively investing in autonomy, with examples such as <a href="https://www.opendesk.eu/en/">OpenDesk</a> and <a href="https://opencode.de/en">OpenCode</a> from <a href="https://www.zendis.de/">the German Center for Digital Sovereignty</a>, or the French <a href="https://lasuite.numerique.gouv.fr/en"><em>La Suite Numérique</em></a> for the civil service. These are developed as open source and available in English. The French state allowing its software to be developed in English is extraordinary.</p>

<h2 id="beyond-munich">Beyond Munich</h2>
<p>The German state of Schleswig-Holstein has been working on <a href="https://www.theregister.com/2025/10/15/schleswig_holstein_open_source/">a Microsoft exit</a> since 2021 and has so far successfully offboarded Exchange and Outlook, i.e. 40,000 accounts. There’s appetite for more - the rest of the Office suite and Windows are next. It is a truly great initiative - it takes courage to launch something like this. Breaking the hegemony of Big Tech is impossible, yet at the same time highly desirable. Their strategy is published <a href="https://www.schleswig-holstein.de/DE/landesregierung/themen/digitalisierung/linux-plus1/Service/Downloads/_dateien/open-source-strategy_EN.pdf?__blob=publicationFile&amp;v=3">here</a>. It includes a beautiful overview of the key pillars, much like the Well Architected Framework of any non sovereign cloud provider.</p>

<p><img src="/assets/images/Schleswig-Holstein-strategy-pillars-sovereign.png" alt="Schleswig-Holstein strategy pillars" /></p>

<p>Please note, this state did not pick a few open-source solutions to implement without a second thought. The state has an <a href="https://nextcloud.com/government/">enterprise version of Nextcloud</a> and they collaborate with Nextcloud to prioritize specific functionalities, which drives among others Nextcloud’s <a href="https://nextcloud.com/blog/nextcloud-releases-assistant-2-0-and-pushes-ai-as-a-service/">AI strategy</a>. They use a version of LibreOffice powered by <a href="https://www.allotropia.de/">Allotropia</a> to have enterprise level support. Their Nextcloud integration is based on <a href="https://www.collaboraoffice.com/collabora-online/">Collabora Office Online</a>, and is also supported by Allotropia. If you do it, you have to do it right. Even partially using Microsoft products means you will remain stuck with interoperability issues. Only by adapting your ecosystem you become the one that calls the shots. If you adapt your organization to Microsoft’s ecosystem, they determine the rules and the costs.</p>

<p>Recently, Denmark has declared that their government will <a href="https://www.zdnet.com/article/why-denmark-is-dumping-microsoft-office-and-windows-for-libreoffice-and-linux/">ditch Microsoft in favor of LibreOffice and Linux</a> - a move rather unsurprising considering Trump wants to own Greenland. If Denmark was to be sanctioned due to being too reluctant to give up their control over Greenland, they can wake up with no access to their email tomorrow, just like the ICC did. 
In Austria, the Austrian Armed Forces <a href="https://itsfoss.com/news/austrian-forces-ditch-microsoft-office/">migrated 16,000 workstations</a> from Microsoft Office to LibreOffice. Austrian Ministry of Economy migrated 1,200 employees to <a href="https://nextcloud.com/blog/press_releases/bmwet-austria-digital-sovereignty/">Nextcloud</a>, though some critique this move as the operations are supported by Atos, an IT services megacorp with <a href="https://www.cio.com/article/3550228/french-govt-leaves-1-1-billion-hole-in-atos-refinancing-plan-atos-says-dont-worry.html">financial issues</a>.</p>

<p>While some find a way to break free, e.g. <a href="https://tweakers.net/nieuws/242126/40000-belastingdienstwerknemers-werken-nog-niet-met-microsoft-365.html">the Dutch government sticks to M365</a> as they were not able to find a suitable alternative, publicly acknowledging the inconvenient, growing dependency. It’s not like they suddenly realised there’s a problem - <a href="https://www.theregister.com/2022/02/23/dpia_microsoft/">the Dutch Ministry of Justice and Security had issued already warnings twice</a>, once in 2019 and the second time in 2022. So what went wrong in this case? 
They inflicted this situation upon themselves. E.g. if the Dutch government had stuck to <a href="https://www.forumstandaardisatie.nl/open-standaarden/odf">their self-imposed standards</a> and used ODF, document formats and the associated interoperability issues wouldn’t be such a problem. Some of their solutions natively support the ODF format, but people use OOXML simply because it is the default in Microsoft Office. Everyone does it, so why shouldn’t we? Often people simply don’t know any better.</p>

<p>Microsoft, being no stranger to vendor lock-in practices, turned OOXML, <a href="https://fsfe.org/activities/msooxml/msooxml.en.html">a pseudo-standard that pretends to be open</a>, into an ISO standard through various <a href="https://www.linuxjournal.com/content/microsoft-ooxml-and-iso">lobbying efforts</a> and a fast tracked ISO process, which helped to bypass objections voiced by opposing members. Though they admitted openly that offering to reward partners for joining the bodies deciding on ISO recognition of OOXML was a mistake:</p>
<ul>
  <li><a href="https://www.thelocal.se/20070829/8324">Controversy Mars Swedish OOXML Vote</a></li>
  <li><a href="https://www.zdnet.com/article/microsoft-accused-of-rigging-ooxml-votes/">Microsoft accused of rigging OOXML votes</a></li>
  <li><a href="https://www.peterkrantz.com/2007/hijacked-ooxml-vote/">How the Swedish OOXML Vote Was Bought for $57,000</a>
In 2001, Microsoft lost an antitrust lawsuit, known as <a href="https://en.wikipedia.org/wiki/United_States_v._Microsoft_Corp.">United States v. Microsoft Corp.</a>, which condemned the bundling of Internet Explorer with Windows. Today we see the same patterns with applications that can only be opened with Edge. Even if you try to uninstall Edge, it will be back with the next update.</li>
</ul>

<p>Often the argument is made, that even though a government department would like to use ODF, this would cause issues with the collaboration with external parties. However, as a government, you can and should require your suppliers to deliver documents in ODF, even if those suppliers work with Microsoft products. The human element unwilling to change is the only limitation. LibreOffice has significantly improved its support for OOXML, if you must use it. Though OOXML support is maintained to facilitate transition. New documents should be ODF, as the OOXML standard contains built-in Microsoft-only functionality that other solutions cannot handle. Even if compatibility is claimed, often only a subset of OOXML is supported.</p>

<h2 id="the-education-loophole">The Education Loophole</h2>
<p>When we take a look outside of the enterprise world, it is hard not to notice that the education sector is heavily targeted. Stimulating adoption at a young age and getting children used to your ecosystem makes a lot of sense from a business perspective. So much, that the Office packages are <a href="https://www.microsoft.com/en-us/education/products/office#tabs-pill-bar-oc3c0f_tab0">heavily discounted</a>. This wouldn’t be so bad considering it is done under the pretext of enabling the education sector, but the schools and universities are left with the responsibility of managing the users like they are an enterprise. Often they are not aware that they should handle e.g. data insight requests and scholars end up in a loop being sent back and forth between Microsoft and their school. There’s some <a href="https://www.barrons.com/news/austria-finds-microsoft-illegally-tracked-students-privacy-campaign-group-7b3e5c05">pushback in Austria</a> against this issue. Austria’s data protection authority found that Microsoft was tracking students and that Microsoft must provide users access to their personal data, not to shift all the responsibility to local schools.
The Warsaw School of Economics (SGH), a Polish university, deploys desktops with a default desktop background, which displays ‘Microsoft - SGH: Partners in Digital Transformation’. It seems they don’t have the sovereign package yet.</p>

<p>The Polish government has recently <a href="https://apnews.com/article/google-poland-ai-innovations-investment-475ad8b95cb3f3060e352be8720008bd">partnered with Google</a> to develop AI capabilities. For the education sector, this means:</p>
<ul>
  <li>access to Google Workspace for Education for everyone,</li>
  <li>Google AI training for 30,000 teachers,</li>
  <li>an update to Chrome OS Flex for 200,000 devices.</li>
</ul>

<p>Somewhat worryingly, <a href="https://www.gov.pl/web/edukacja/porozumienie-ministerstwa-edukacji-narodowej-i-google-cloud-inwestycja-w-nowoczesna-szkole-i-kompetencje-al-30-000-nauczycieli">the supposedly strategic partnership</a> includes consultations of the use of AI in schools, as well as the analysis of data concerning device usage in schools.
Google has also joined forces with SGH, and launched <a href="https://gazeta.sgh.waw.pl/en/research-and-scienc/google-and-ai-lab-sgh-boost-ai-skills-smes">The ‘Skills of Tomorrow: AI’ campaign</a> under the honorary patronage of the Ministry of Digital Affairs, which was a PR success. It was a ‘free’ 5 weeks course after all. While it’s beneficial for everyone that people have learned new skills, the downside is that those are rather Google AI skills, not just any AI skills. Google has also partnered with Kaggle and launched together a <a href="https://www.kaggle.com/learn-guide/5-day-agents">5-Day Gen AI Intensive Course</a>, which I have attended. The technology is great, but the sovereignty gap is widening. 
Vendors are increasingly aware of the power of a skilled workforce - after all, even if you have the greatest technology, companies need people who are capable of using it. Any course that is offered for free by a vendor, is not free - you pay with your time and the missed opportunity to learn something else, perhaps something vendor agnostic. Getting thousands of people certified in a product increases mainly the value of that product, which gets easier to sell and to adopt by organizations, as they can find people with skills more easily and/or cheaper.</p>

<p>For instance, Microsoft has <a href="https://learn.microsoft.com/en-us/">Microsoft Learn</a>, the <a href="https://esi.microsoft.com/">Enterprise Skills Initiative</a>) (the same as MS Learn, but with live training) and Customer Connection Programs. Google’s alternative is called <a href="https://www.skills.google/">Google Skills</a>, previously also known as Cloud Skills Boost, and has the additional benefit of hands-on labs on a free sandbox account in the GCP console, whereas Microsoft does not. <a href="https://skillbuilder.aws/">AWS</a> is an exception in this case. While they offer free foundational training, many features are hidden behind a paywall.
In the CSP world, the larger your bill is, the higher is your budget to upskill your employees, i.e. have them attend courses and pass exams on the cost of the provider. This is a race to the bottom for employees: the more people get certified, the lower the value of those certificates. To compensate for the decreasing value there is no other way than to get more certificates. 
As this progresses, it becomes harder and harder to find independent consultancies that are capable of evaluating different, sovereign solutions. If everyone specializes in Microsoft solutions, it is unlikely they will recommend something else.</p>

<p>Established vendors have various advantages, one of them is using the momentum of existing customers to generate new ones. This is done by making the customer the hero. You convince a director (or someone with purchasing power) he or she needs your Zero Trust product to be resilient in today’s dangerous world. After the implementation, you put them on stage to present their transformation during your own conference, like a <a href="https://www.snowflake.com/events/data-for-breakfast/">Data for Breakfast</a> meeting or any local Azure, AWS day. Their peers see the success and buy. Rinse and repeat, and the director in question is even happy to do it: the exposure and the personal brand building offset the products’ shortcomings, which somehow were forgotten on stage.
Prospects trust their peers more than salespeople, so you let your customer do the actual selling by sharing their transformation story.</p>

<h2 id="the-way-out">The Way Out</h2>
<p>When the topic of coordination of common software projects across the EU is raised, often there’s a dilemma to solve - should everyone own their own cloud, or can I trust my neighbours to develop a cloud together, so that we share the costs and the benefits? Perhaps a distributed model, in which countries collaborate on the software, but own their own data centers, makes the most sense. We need a federated model where a country can leave without crashing the system.
We must acknowledge that both the EU and its member countries can change how they operate over time, thus there is no perfect answer to this. Especially, as social media algorithms serve the masses with content that generates outrage to maximize engagement with the platform. While this maximizes their revenue, it drives citizens apart either to the far left or the far right. For instance, in Myanmar, <a href="https://time.com/6217730/myanmar-meta-rohingya-facebook/">a military dictatorship used Facebook</a> to help stir up a genocide. We have also had the <a href="https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Analytica_data_scandal">Facebook–Cambridge Analytica data scandal</a>, which enabled micro targeting of US voters with customized messages about Trump during his presidential campaign in 2016.
Regardless of the course of politics in the EU, it will benefit from its own technology. Even if entire Europe was to become a dictatorship, we don’t want to fear that sanctions can shut down our critical services, defense systems and the government.</p>

<p>The question of how to make it happen is not a question anymore - a letter from the industry is on the table, begging the EU for a commitment to sovereign infrastructure. The initiative is called <a href="https://eurostack.eu/">EuroStack</a> and has <a href="https://www.euractiv.com/news/european-industry-big-win-germany-france-both-support-sovereign-eu-based-tech-infrastructure/">won the political support of Germany and France</a>. EuroStack focuses on both physical and logical infrastructure, and proposes concrete measures so that Europe becomes more technologically independent across all layers. To quote a key proposal:
<code class="language-plaintext highlighter-rouge">"Creating demand – industry will invest if there are adequate demand prospects. The business case for investment must be supported by clear, objective and strong procurement obligations - with a formal requirement for the public sector to “Buy European” – i.e. source their needs from European-led and assembled solutions (while recognising these may involve complex ecosystems and supply chains). The private sector needs appropriate incentives and inducements to steer a portion of their demand towards European suppliers enabling sovereign solutions."</code></p>

<p>The idea is as simple as stimulating appropriate demand, which generates cash flow to European companies, which in turn enables them to build out their technology over the years to come. 
Appropriate incentive for the private sector can be as simple as tax benefits for buying European products. While migrations are inconvenient, at the end of the day money is the deciding factor. If it is cheaper and more convenient to pay for not sovereign technology, then there is no business case to even consider switching. A last measure can be the regulatory way, though if implemented right away, currently many governments would need to fine themselves first.</p>

<h2 id="the-battle-for-infrastructure">The Battle for Infrastructure</h2>
<p>One of the policy measures Europe could take is to block acquisitions of its critical companies by e.g. US companies. In November last year, Kyndryl had acquired Solvinity, which means that they now hold a kill switch for the Dutch digital identity, justice, regulatory, and intelligence systems, together with the ‘sovereign cloud’ of the City of Amsterdam. <a href="https://roethof.net/posts/2025/11/kyndryl-solvinity-sovereignty-kill-switch/">Ronny Roethof’s blog post</a> explains this case in detail.</p>

<p><a href="https://nltimes.nl/2025/10/07/dutch-economy-faces-billions-losses-amsterdam-data-center-expansion-halts">A blocker the Dutch government faces</a> is the lack of space and capacity on the power grid to build more data centers. Even if they would like to invest in a sovereign cloud - there is no place to host it locally. There are more than 200 data centers in the Netherlands - should the government buy some of them back? 
Existing data centers also pose a difficult ethical dilemma - should anyone be able to use servers located in another country for whatever purposes they please? <a href="https://www.theguardian.com/world/2025/aug/06/microsoft-israeli-military-palestinian-phone-calls-cloud">Israel has used a data center in the Netherlands</a> for mass surveillance of Palestinians. Their phone calls were intercepted and analyzed - allegedly also used to identify bombing targets. This stands in stark contrast to <a href="https://www.government.nl/topics/israel-and-the-palestinian-territories/dutch-policy-on-the-situation-in-israel-and-the-palestinian-territories">the Dutch policy on the situation in Israel and the Palestinian Territories</a>.</p>

<p>Another battle with no end in sight are the product bundles. If <a href="https://www.techradar.com/pro/microsoft-will-have-to-sell-teams-separately-from-the-rest-of-365-or-face-a-huge-fine">Teams can be sold separately</a>, then it would be beneficial to have that option also for other products, which come together as a package. 
In terms of policing vendors, the case of Broadcom is one to keep in mind. Broadcom had acquired VMware in 2023 and increased the licensing costs <a href="https://www.itpro.com/cloud/cloud-computing/broadcoms-harsh-vmware-contracts-are-costing-customers-up-to-1-500-percent-more">exorbitantly</a> to better their bottom line. For a Dutch government agency, the Rijkswaterstaat (RWS), that meant that their new subscription licenses would cost 85% more on a year basis. RWS wanted to migrate away, but Broadcom offered no transitional help. <a href="https://openrijk.nl/en/rijksinstellingen/rijkswaterstaat/artikel/rijkswaterstaat-wint-kort-geding-tegen-broadcom-over-voortzetting-van-support/rijkswaterstaat-wins-summary-proceedings-against-broadcom-over-continuation-of-support">RWS took the case to court</a> and won, setting an important precedent for other impacted customers. The court ruled that Broadcom must provide exit support (updates, patches, assistance) for up to two years or face penalties up to a max of €25 million. According to the court, Broadcom has a duty of care - they cannot just quit on their customer.</p>

<p>Also noteworthy, the European Commission is <a href="https://www.bloomberg.com/news/articles/2025-11-17/tech-giants-cloud-power-probed-as-eu-weighs-inclusion-in-dma">considering whether AWS, Azure, and Google Cloud should fall under the Digital Markets Act</a>, which was e.g. used to force Apple to allow alternative appstores in iOS. A problem here is the user count. For a company like Meta or Apple, it is relatively easy to determine their impact in terms of active users, but for a business service like Azure or AWS, it is not. The number of business customers is relatively small, but indirectly, the number of end users is high due to the scale.</p>

<p>While there’s no denying the EU has a lot to catch up upon, the grass isn’t necessarily perfect on the other side. Just last year, Microsoft stopped <a href="https://www.reuters.com/world/us/microsoft-stop-using-engineers-china-tech-support-us-military-hegseth-orders-2025-07-18/">hiring engineers in China</a> to work on the cloud systems of the US Department of Defense. This was done under supervision of digital escorts with a security clearance, people who merely copy pasted commands provided by the Chinese engineers, without understanding what they were doing.</p>

<p>We have discussed some success stories earlier, but there are many more. Nextcloud has <a href="https://nextcloud.com/customers/">a dedicated page to case studies</a>. Existing European alternatives are available at <a href="https://european-alternatives.eu/">european-alternatives.eu</a>. Just to list a few we haven’t discussed:</p>
<ul>
  <li>Open-Xchange - Email &amp; Groupware</li>
  <li>Univention - Identity Management</li>
  <li>Gaia-X - European Cloud Federation</li>
  <li>Sovereign Cloud Stack - FOSS Infrastructure</li>
  <li>OVHcloud  - a CSP from France</li>
</ul>

<p>One of the short-term measures Europe could implement to mitigate the risks of foreign technology is the mandatory use of a software escrow. It would require non-EU vendors to deposit their source code, build documentation, and proprietary assets with a trusted third party physically located within the EU, under European jurisdiction. By mandating that the code can be released under specific trigger events, such as political embargoes, bankruptcy, or a breach of the duty of care, the EU would regain some leverage in this asymmetrical relationship. However, relying on escrow is merely a survival tactic, not a long-term strategy. Possessing the source code is one thing -  having the people to maintain a massive, proprietary platform is another. It buys time to migrate to a sovereign solution, but it does not buy independence.</p>

<h2 id="the-long-road-to-independence">The Long Road to Independence</h2>
<p>Dependency on other people, companies, or countries has always been a problem. If it wasn’t about money, then it was about power and accountability. Companies and organizations went to the cloud because it was financially attractive. In reality it makes important business processes dependent on people and companies that are merely hired. They report to others and listen to others. The practice itself isn’t new and it was well established long before the cloud became a buzzword, like AI is today. For years, it has been a habit for some decision makers to consider the financial benefit of outsourcing and being dependent more important than making the effort themselves. Therefore, we shouldn’t be surprised that they stick to that concept by pretending that they are taking enough responsibility themselves.</p>

<p>Awareness about the dependency within Europe is rising, but a boiling point has not yet been reached - the political will to realize real sovereign clouds and IT solutions in general does not exist yet. It is a matter of time - the more political intimidations, the sooner that boiling point will be reached. We should own our payment, web services, and security systems that function outside of the US. Do our (defense) systems have a backdoor - enabling someone to switch it off with the push of a button? Twenty, thirty years ago, that would have been a nuisance. Today, it would be catastrophic. Building a sovereign cloud is a process and it will have to happen in steps. In every step a layer of sovereignty is addressed. That of hardware and chips is perhaps in one of the last steps. 
We also know that the US views economic interests as national interests. They do not hesitate to leverage their information position to give their companies an advantage in commercial dealings. By building, utilizing open source and procuring locally, you also contribute to our European knowledge base. Many German, French, Spanish, and Italian governments have adopted this approach and are leading by example. The argument that we no longer have this expertise is a self-fulfilling prophecy. We have the talent and the tools. The only thing missing is the courage to change.</p>]]></content><author><name>Piotr Maćkowski</name></author><category term="Sovereignty" /><category term="Geopolitics" /><category term="OSS" /><category term="Cloud" /><summary type="html"><![CDATA[For years, Europeans have lived comfortably, storing and processing data on servers located in the EU, i.e. on servers physically in the EU, but legally controlled by foreign entities. We celebrated compliance audits and built data centers across the continent, believing that physical location equaled digital safety. But what good is data residency compliance if you cannot be certain you can access your data tomorrow?]]></summary></entry><entry><title type="html">Making YouTube usable again</title><link href="https://piotrmackowski.com/Making-YouTube-usable-again/" rel="alternate" type="text/html" title="Making YouTube usable again" /><published>2025-12-14T00:00:00+01:00</published><updated>2025-12-14T00:00:00+01:00</updated><id>https://piotrmackowski.com/Making%20YouTube%20usable%20again</id><content type="html" xml:base="https://piotrmackowski.com/Making-YouTube-usable-again/"><![CDATA[<p>YouTube has gone through a fair amount of enshittification. Let’s make it better in a few steps. Google is actually quite helpful in this regard - if you know what you’re looking for.</p>

<p><img src="/assets/images/nsh.jpg" alt="Not saving your history" /></p>

<p>In your <a href="https://myactivity.google.com/product/youtube/controls">YouTube activity controls</a>:</p>
<ul>
  <li>turn off the history and delete any saved history,</li>
  <li>turn off personalised ads,</li>
  <li>delete ‘YouTube survey answers’ and ‘YouTube Customize Your Feed Feedback’,</li>
</ul>

<p>At first you might worry: What if I forget I have already watched this video and I will waste time watching it again? Well, then it probably wasn’t important in the first place and you have forgotten about the activity due to the sheer amount of stuff you have watched. Nothing to be ashamed of. It’s like watching a favorite movie twice.
While personalised ads sound nice (if forced upon, let’s watch something ‘useful’), every click and search on the platform is used to target you with personalised ads to increase revenue. The purpose of ads is to make money off you, the product. The less personalised ads you watch, the lower the chance the advertiser will be successful in their act, i.e. the conversion rate drops. 
Last but not least, any customization to your feed places you at a disadvantage, because you are more likely to keep watching whatever the platform feeds you. If outraging content does the trick, then that is what will be suggested. Your worth is measured in the time you spent watching, which is also known as engagement.</p>

<p>The above exercise will result in a clean home page with no recommendations, no available shorts, and only videos of channels you have actually subscribed to. You will see shorts in your subscriptions pane, if those channels produce such content.</p>

<p><img src="/assets/images/ywa.jpg" alt="Cleaner YouTube" /></p>

<p>Also, while you’re at it, it might be worthwhile to delete any <a href="https://myactivity.google.com/product/youtube/interactions">interactions</a> you have associated with your account, but it’s slightly more work, as you must delete each category separately. An argument can be made for using the platform without an account, but you won’t have the clean user experience displayed above and your subscriptions feed. The alternative is a custom frontend like <a href="https://yewtu.be/">Invidious</a> and RSS feeds. YouTube used to have a built-in RSS button, but it was removed to encourage us to use the platform. Although the button disappeared, the feeds did not. <a href="https://chuck.is/yt-rss/">Here</a> is a short guide on how to get the RSS feed for any YouTube channel.</p>

<p>For an enhanced experience, I recommend installing Firefox with the following extensions:</p>
<ul>
  <li><a href="https://github.com/gorhill/uBlock#ublock-origin">uBlock Origin</a></li>
  <li><a href="https://privacybadger.org/">Privacy Badger</a></li>
  <li><a href="https://dearrow.ajay.app/">DeArrow - Better Titles and Thumbnails</a></li>
  <li><a href="https://sponsor.ajay.app/">SponsorBlock</a></li>
</ul>

<p>In Firefox privacy settings, available at about:preferences#privacy:</p>
<ul>
  <li>Enable strict tracking protection
    <ul>
      <li>Uncheck ‘Fix major site issues’</li>
    </ul>
  </li>
  <li>Check ‘Tell websites not to sell or share my data’</li>
  <li>Check ‘Block pop-ups and third-party redirects’</li>
  <li>Check ‘Warn you when websites try to install add-ons’</li>
  <li>Disable Mozilla telemetry, by unchecking:
    <ul>
      <li>‘Send technical and interaction data to Mozilla’</li>
      <li>‘Send daily usage ping to Mozilla’</li>
      <li>‘Automatically send crash reports’</li>
    </ul>
  </li>
</ul>

<p>To support content creators, consider donating directly.</p>

<p>On a closing note, YouTube is by no means an exception. Surveillance capitalism is a business model where companies collect data and monetize users by selling their future behavior. The user experience must be degraded to make the platform more addictive, thus ensuring the platform continues to grow. Therefore, we should all make an effort to educate ourselves and others to consciously interact with the product, rather than being the product.</p>]]></content><author><name>Piotr Maćkowski</name></author><category term="Privacy" /><category term="Google" /><summary type="html"><![CDATA[YouTube has gone through a fair amount of enshittification. Let’s make it better in a few steps. Google is actually quite helpful in this regard - if you know what you’re looking for. In your YouTube activity controls: turn off the history and delete any saved history, turn off personalised ads, delete ‘YouTube survey answers’ and ‘YouTube Customize Your Feed Feedback’, At first you might worry: What if I forget I have already watched this video and I will waste time watching it again? Well, then it probably wasn’t important in the first place and you have forgotten about the activity due to the sheer amount of stuff you have watched. Nothing to be ashamed of. It’s like watching a favorite movie twice. While personalised ads sound nice (if forced upon, let’s watch something ‘useful’), every click and search on the platform is used to target you with personalised ads to increase revenue. The purpose of ads is to make money off you, the product. The less personalised ads you watch, the lower the chance the advertiser will be successful in their act, i.e. the conversion rate drops. Last but not least, any customization to your feed places you at a disadvantage, because you are more likely to keep watching whatever the platform feeds you. If outraging content does the trick, then that is what will be suggested. Your worth is measured in the time you spent watching, which is also known as engagement. The above exercise will result in a clean home page with no recommendations, no available shorts, and only videos of channels you have actually subscribed to. You will see shorts in your subscriptions pane, if those channels produce such content. Also, while you’re at it, it might be worthwhile to delete any interactions you have associated with your account, but it’s slightly more work, as you must delete each category separately. An argument can be made for using the platform without an account, but you won’t have the clean user experience displayed above and your subscriptions feed. The alternative is a custom frontend like Invidious and RSS feeds. YouTube used to have a built-in RSS button, but it was removed to encourage us to use the platform. Although the button disappeared, the feeds did not. Here is a short guide on how to get the RSS feed for any YouTube channel. For an enhanced experience, I recommend installing Firefox with the following extensions: uBlock Origin Privacy Badger DeArrow - Better Titles and Thumbnails SponsorBlock In Firefox privacy settings, available at about:preferences#privacy: Enable strict tracking protection Uncheck ‘Fix major site issues’ Check ‘Tell websites not to sell or share my data’ Check ‘Block pop-ups and third-party redirects’ Check ‘Warn you when websites try to install add-ons’ Disable Mozilla telemetry, by unchecking: ‘Send technical and interaction data to Mozilla’ ‘Send daily usage ping to Mozilla’ ‘Automatically send crash reports’ To support content creators, consider donating directly. On a closing note, YouTube is by no means an exception. Surveillance capitalism is a business model where companies collect data and monetize users by selling their future behavior. The user experience must be degraded to make the platform more addictive, thus ensuring the platform continues to grow. Therefore, we should all make an effort to educate ourselves and others to consciously interact with the product, rather than being the product.]]></summary></entry><entry><title type="html">OSINT your future employer</title><link href="https://piotrmackowski.com/OSINT-your-future-employer/" rel="alternate" type="text/html" title="OSINT your future employer" /><published>2025-03-28T00:00:00+01:00</published><updated>2025-03-28T00:00:00+01:00</updated><id>https://piotrmackowski.com/OSINT%20your%20future%20employer</id><content type="html" xml:base="https://piotrmackowski.com/OSINT-your-future-employer/"><![CDATA[<p>Some employers do a very thorough background check on their prospective employees, so why shouldn’t you return the favour? Whatever you have chosen to be interviewed for, I believe basic research is expected of every candidate. Think in terms of how the company makes money and what influences its position in the market.</p>

<p>In security, deeper research is desired and an easy way to show you know your stuff. Also, unlike in other occupations, you should be able to pull off a bit of targeted open source intelligence on your interviewer without hiding it. Don’t refrain from explicitly mentioning your preparation. As long as you manage to smoothly incorporate your findings into the conversation, you will leave a long-lasting impression on the other person.</p>

<p>Your shopping list might include, but is not limited to:</p>
<ul>
  <li>the homepage,</li>
  <li>disclosed security breaches,</li>
  <li>reviews on Glassdoor,</li>
  <li>other job descriptions,</li>
  <li>Shodan,</li>
  <li>Google dorks,</li>
  <li>bug bounty platforms,</li>
  <li>the team you aspire to become part of and their activity:
    <ul>
      <li>LinkedIn &amp; Github profiles,</li>
      <li>conferences and meetups,</li>
      <li>blogs and podcasts.</li>
    </ul>
  </li>
</ul>

<p>Your objective is to learn more about the company, the team and to find out whether you want to invest time in the recruitment process at all. Assuming you have the luxury to say no, this research helps you to avoid certain red flags. Also, your time is precious. The reality is that you will need to go through this quite a few times depending on your interview to offer ratio. Grab yourself something to write on, pick a target and follow along.</p>

<p>Starting with the homepage and general news sites, get an idea what the business is about, what makes it profitable. Is it B2B, B2C or both? Does the industry mandate any compliance requirements? Look for (financial) reports. You don’t need to be an expert in accounting to understand whether there’s growth year on year or stagnation. If publicly traded, <a href="https://www.google.com/finance/">check how the stock price</a> is holding up over the years. If private, verify who has the majority. An about us section might offer some information about the board and executives. Do they have someone responsible for security? If there’s just a CIO, then security is most likely in scope of this person. Think about <a href="https://www.isc2.org/Insights/2024/07/CISO-Reporting-Lines-Why">the difference in company reporting structures</a> and how this affects who calls the shots and how the budget flows down.</p>

<p>Moving on to investments, take note of any (past) mergers and acquisitions. 
Let’s face it, M&amp;A’s are tough for everyone involved, wherever you’re in the food chain. Especially if IT is a supporting function rather than the core business, you can count on the business to accept the risk and to force IT to just make it happen. If entity A has a better security posture than entity B, most likely A won’t like to establish trust with B. We shall first raise the security posture of B, and only then incorporate them or migrate their services and shut them down. Both strategies take time. IT ends up with a fragmented environment, which is harder to manage. The budget stays the same though, the investment shall pay off after all.</p>

<p>In the interview, this knowledge allows you to ask strategic questions: “I noticed the recent acquisition of Company B. How is the team handling the migration of their legacy services? Are we isolating their environment or integrating it immediately?” This shows you understand the business risk, not just the technology.</p>

<p>To finish off the general information scraping, search for any disclosed security breaches. There are public repositories such as <a href="https://www.breaches.cloud/">breaches.cloud</a>, but your favorite search engine should do the trick just fine. Did the breach affect the bottom line anyhow? Additionally, reviews on sites like Glassdoor and GoWork (Poland specific) can give you a general idea of average employee satisfaction, but be mindful of the negativity bias. Often you will find insightful information you wouldn’t get to know otherwise before starting the actual job, unless you have access to an insider. <a href="https://www.youtube.com/watch?v=bUvVaXZRnTA">Antisyphon training</a> offers a practical approach to gaining such access if you’re up for it.</p>

<p>Prepare questions based on the information you have found. <em>While researching the position, I came across XYZ, how does that impact your responsibilities?</em> This shows you have done your homework and you get more information about what the team actually struggles with, which you can come back to later on in the conversation. Regardless of the type of financial trend identified earlier, you can mention you have checked the books and enquire how it affects the team. Perhaps there was a headcount reduction, or they had received more funding for trainings.</p>

<p>Now it’s time to move on to the tech stack. Your job description is the starting point. Then, go on a high level through other job descriptions (like DevOps, SRE’s, IAM, network, compliance, system engineering, developers and data) to get an idea of the ecosystem. Once you have exhausted those, tools like Shodan, Censys or ZoomEye can be helpful to have a look from a slightly different angle. Do they have HTTPS, HSTS and a CSP everywhere? Say you’re interviewing for a position at Tripadvisor, and the topic of system design comes up. Well, obviously a reliable service needs to have some kind of bot protection and CAPTCHA’s, so this is where DataDome comes in. The Envoy proxy handles the API gateway and load balancing at the edge. Fastly is the CDN of choice. Instead of starting the discussion from scratch, disclose what your understanding of their system is, and consider asking the interviewer to fill in the missing parts.</p>

<p><img src="/assets/images/Tripadvisor.JPG" alt="Tripadvisor - Shodan results" />
Recall the fragmented environment as a result of mergers and acquisitions discussed earlier. The below table might reflect those legacy systems the company failed to kill or actual honeypots.</p>

<table>
  <thead>
    <tr>
      <th>Top Products</th>
      <th>Count</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>nginx</td>
      <td>37</td>
    </tr>
    <tr>
      <td>SQL Server Browser Service</td>
      <td>19</td>
    </tr>
    <tr>
      <td>Lotus Domino httpd</td>
      <td>1</td>
    </tr>
    <tr>
      <td>Apache httpd</td>
      <td>1</td>
    </tr>
  </tbody>
</table>

<p>DNS records often provide an interesting angle at SaaS integrations. A personal favorite of mine to check those is <a href="https://web-check.xyz/">web-check.xyz</a>, as it queries a holistic overview with stuff like security.txt in one click. Depending on the maturity of the company you can expect some of those records to be forgotten and left for the eternity or actually planted to deceive you. Most of these records serve a purpose that we can use to our advantage. Imagine yourself on the interview discussing a hypothetical security awareness campaign. It would make sense to craft one somewhat aligned to what users actually tend to interact with on a daily basis, wouldn’t it? So instead of the usual M365 login page, you say you have checked their DNS records, and therefore, you propose two scenarios like <em>Dropbox - someone has shared a file</em> and <em>Docusign - HR documents about to expire</em> campaign.</p>

<p><img src="/assets/images/dnsrecords.jpg" alt="DNS records" /></p>

<p>Multi tenant SaaS solutions often follow a standard convention for their subdomains. Enumeration of those is straightforward and true positives are highly accurate:</p>
<ul>
  <li>company.pagerduty.com</li>
  <li>company.webex.com</li>
  <li>company.zendesk.com</li>
  <li>company.slack.com</li>
  <li>company.service-now.com</li>
  <li>company.service-now.com/login.do (SSO bypass)</li>
  <li>company.my.salesforce.com</li>
  <li>company.docusign.net</li>
</ul>

<p>Google dorks could go either way in my experience. I wouldn’t spend a lot of time here, but you can just get lucky. After all, “luck is what happens when preparation meets opportunity.”
Try the following to discover subdomains and specific URL’s:</p>
<ul>
  <li><code class="language-plaintext highlighter-rouge">site:target[.]com -www</code></li>
  <li><code class="language-plaintext highlighter-rouge">site:target[.]com (inurl:config OR inurl:dev OR inurl:test OR inurl:backup OR inurl:admin OR inurl:integration OR inurl:staging OR inurl:internal)</code></li>
</ul>

<p>If there’s a public bug bounty program, take note of the scope. The larger the scope, the more challenging it is to sustain the program. You can enquire whether there are plans to expand the scope. The hardened, core environment, which is subject to certain audits, is most likely in scope, whereas less critical parts are not.</p>

<p>Once you have a general idea of what is going on, it’s time to dive deeper into individuals, who make it all happen. By going through LinkedIn profiles you should be able to establish a mind map who works with who and which people specialize in what. Often the experience section can offer some insight into what projects or initiatives have been conducted. If someone is active on the platform, pay attention to the latest mentions, comments, (company) events and posts. GitHub is also worth a shot.</p>

<p>Finally, the most time consuming part: conferences, meetups, books, blogs and podcasts. This can be a lot to go through, so just focus on what or who interests you. If you have attended conferences in the past, there’s a good chance you still have access to the recordings. If you did not, perhaps you can pay to receive access, or buy a ticket for the next edition, which comes with the access to the recordings of the past edition(s). Check YouTube for openly available content. If the team is active in the community, just being aware of what is happening is already an advantage. On a side note, if you have been a speaker at an event and it was recorded, you can count on people to grab a meeting room to watch it together.</p>

<p>I hope I have equipped you with a few ideas you wouldn’t have considered otherwise. In general - outcomes may vary, so try and see what works for you. Do the recon, find the gaps, and bring them to the table.</p>]]></content><author><name>Piotr Maćkowski</name></author><category term="OSINT" /><category term="LinkedIn" /><category term="Google" /><summary type="html"><![CDATA[Some employers do a very thorough background check on their prospective employees, so why shouldn’t you return the favour? Whatever you have chosen to be interviewed for, I believe basic research is expected of every candidate. Think in terms of how the company makes money and what influences its position in the market.]]></summary></entry><entry><title type="html">How to 10x your Secure Score</title><link href="https://piotrmackowski.com/How-to-10x-you-Secure-Score/" rel="alternate" type="text/html" title="How to 10x your Secure Score" /><published>2024-10-30T00:00:00+01:00</published><updated>2024-10-30T00:00:00+01:00</updated><id>https://piotrmackowski.com/How%20to%2010x%20you%20Secure%20Score</id><content type="html" xml:base="https://piotrmackowski.com/How-to-10x-you-Secure-Score/"><![CDATA[<p>How can you leverage the <a href="https://learn.microsoft.com/en-us/defender-xdr/microsoft-secure-score">Microsoft Secure Score</a> to your advantage? The beauty of this tool lies in its ability to portray your security posture in a single number that is both understandable for a non-technical audience and relatable to the posture of other similarly sized companies. Securing leadership buy-in was never so easy before.</p>

<p><em>Your secure score is 52%, whereas organizations like yours score just 45%.</em></p>

<p>Whether it’s your job to set goals or to achieve them, the recommendations offer out of the box specific, measurable and relevant objectives. Upon closing them it’s straightforward to communicate the value and the impact you have had on the security of your tenant.</p>

<p>The exact set of recommendations depends on your tenant, i.e. what products you have licensed. A full-blown Enterprise Mobility + Security E3/E5 setup should result in a somewhat similar distribution of recommendations across Microsoft’s products like below.</p>

<table>
  <thead>
    <tr>
      <th>Product</th>
      <th>Weight</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Defender for Endpoint</td>
      <td>60%</td>
    </tr>
    <tr>
      <td>Defender for Identity</td>
      <td>12%</td>
    </tr>
    <tr>
      <td>Defender for Office</td>
      <td>11%</td>
    </tr>
    <tr>
      <td>Exchange Online</td>
      <td>2%</td>
    </tr>
    <tr>
      <td>Intune</td>
      <td>3%</td>
    </tr>
    <tr>
      <td>Microsoft Entra ID</td>
      <td>7%</td>
    </tr>
    <tr>
      <td>Other Apps</td>
      <td>5%</td>
    </tr>
  </tbody>
</table>

<p>You’ll immediately notice that MDE significantly impacts the overall score, so it makes sense to put the focus on hardening your endpoints. However, it’s essential to first consider the needs and perspectives of your stakeholders. Unless you are a solo admin, the products listed above are likely managed by various teams, each with a different appetite for security and reliability standards, as well as varying levels of interest in hardening their respective products. Therefore, your best bet might be to knock on everyone’s door to gauge who is ready to collaborate promptly and who may place your request toward the end of their backlog. Act accordingly.</p>

<p>Nevertheless, Attack Surface Reduction rules will eventually end up on your plate. Some of them you won’t be able to enforce at all, some require auditing and analysis. Some rules can be implemented in block mode without risking sleepless nights. <a href="https://blog.nathanmcnulty.com/defender-for-endpoint-implementing-asr-rules/">Nathan McNulty</a> and <a href="https://jeffreyappel.nl/microsoft-defender-for-endpoint-series-attack-surface-reduction-and-additional-protection-part4b/">Jeffrey Appel</a> have each published excellent hands-on material that should get you started.</p>

<p>If you choose to not action a recommendation, it’s beneficial to formally accept the risk in the portal, so that your peers have a clear picture of what is in progress, completed or accepted as is. Some recommendations are specific to highly regulated environments, and it is wise to just accept the risk in less regulated environments. For instance, while at first it may seem a good idea to not allow anonymous participants to join meetings in Teams, you will be unpleasantly surprised when you realise you have delayed several hiring processes because the candidates could not attend their virtual interview.</p>

<h3 id="why-a-100-score-doesnt-mean-100-secure">Why a 100% Score doesn’t mean 100% Secure</h3>

<p>The downside of building your leadership buy-in on a metric like Secure Score is that certain aspects are outside of your control or not at all reflected in that number. The system can suddenly turn against you if the % drops, to name just a few examples;</p>
<ul>
  <li>Microsoft adds new recommendations that you are not compliant with,</li>
  <li>your company procures new products, which results in additional recommendations and a shift in the weights,</li>
  <li>your department onboards a bunch of endpoints, but the same hardening you have driven so diligently so far is not a part of the MVP.</li>
</ul>

<p>The why behind looking secure and being secure is very well explained in <a href="https://www.youtube.com/watch?v=CYYT581O67Q">a recent talk by Kat Traxler at the fwd;cloudsec conference</a>, which connects the dots between security and Daniel Kahneman’s Thinking, Fast and Slow. We tend to overemphasize metrics that are easily measured and frequently reported. What you see is all there is - your fast, lazy System 1 brain doesn’t look for information it doesn’t have. Pursuing a perfect posture is the natural thing to do, because it’s the easiest thing to do and simplest to measure. Chasing a perfect posture feels efficient and rewards us with immediate satisfaction, but efficiency is not the same as effectiveness. The opportunity cost here is that we have no capacity left to tackle risk from other angles, such as asset management, detection, response or governance. Slow and deliberate System 2 thinking is needed to assess what activities will help your organization the most to reduce the risk.</p>

<p>For example, Teams allows by default communication with external domains, yet there is no guidance (recommendation) on managing or restricting this setting. This feature permits users to connect with individuals outside the organization, who can reach them simply by knowing their email addresses. While this promotes cross-organizational collaboration, it also exposes your users to social engineering attacks. 
External users could exploit this functionality to verify active email addresses, initiate conversations on Teams, impersonate trusted contacts, or send malicious links and attachments with the intent to compromise devices or accounts. Additionally, this configuration enables external monitoring of user availability status and retrieval of Out of Office messages if configured. To mitigate these risks, you must restrict Teams communication to specific, trusted external domains - if external communication through Teams is required at all.</p>

<h3 id="the-way-forward">The way forward</h3>
<p>I recommend you position the Secure Score as one of the health indicators, but do not let it become the definition of your security program. Use it to drive the initial conversations and clear the low-hanging fruit, but recognize and be open about its limitations.</p>]]></content><author><name>Piotr Maćkowski</name></author><category term="Defender XDR" /><category term="Microsoft" /><category term="XSPM" /><summary type="html"><![CDATA[How can you leverage the Microsoft Secure Score to your advantage? The beauty of this tool lies in its ability to portray your security posture in a single number that is both understandable for a non-technical audience and relatable to the posture of other similarly sized companies. Securing leadership buy-in was never so easy before.]]></summary></entry><entry><title type="html">Beyond certificates</title><link href="https://piotrmackowski.com/Beyond-certificates/" rel="alternate" type="text/html" title="Beyond certificates" /><published>2024-09-11T00:00:00+02:00</published><updated>2024-09-11T00:00:00+02:00</updated><id>https://piotrmackowski.com/Beyond%20certificates</id><content type="html" xml:base="https://piotrmackowski.com/Beyond-certificates/"><![CDATA[<p>Certificates are great to show one is willing to go the extra mile. They usually come with a structured learning path, and satisfaction when you receive that precious badge in your mailbox. It is easy to fall into the trap of grinding certificates one after the other, without applying the knowledge you have gained, keeping structured notes and practicing spaced repetition. Do yourself a favor, and invest your time into other areas such as networking (the in-person type), projects and volunteering.
Organizations and vendors usually have some way of building and engaging their community for obvious reasons. Think in terms of conferences, online events, user group meetups, working groups, community projects, Slack and Discord channels.</p>

<h3 id="csp-communities">CSP communities</h3>
<p>Microsoft <a href="https://www.aka.ms/JoinCCP">Customer Connection Programs</a> come in a few different flavors depending on the products involved. Joining any CCP gives you access to community calls, private previews, and focus groups with Microsoft’s product teams. If you work at a place that has Copilot written all over it, I think it does make sense to have access to the roadmap of individual products. That way you can filter past the corporate sales talk and to a certain degree of transparency provided by the NDA, see for yourself which products are doomed and which ones Microsoft still invests in. These two are not mutually exclusive (like Windows 11), but you get the idea. You don’t want to be in the middle of an OKR, when you read an unwanted sales email from a Microsoft partner and you realize the very product you have adopted is declared EOS, e.g. <a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-change-announcement-microsoft-entra-permissions-management-end-of-sale/4399382">CIEM</a>.</p>

<p>As a member you can submit feedback about the products you work with, and you’ll be rewarded with points for your engagement. There’s gamification to keep doing so. The most active members are rewarded with badges, invites to join a podcast or a 1:1 with an engineer to discuss a topic of choice. 
Even though they are referred to as <em>customer</em> connection programs, you can also apply if you work for a Partner of Microsoft (many MSPs are members of the partner network).</p>

<p>For AWS folks, there’s the <a href="https://aws.amazon.com/developer/community/community-builders/">AWS Community Builders</a> program. Applications are evaluated once per year, so this is something to plan ahead.</p>

<h3 id="cloud-security-alliance">Cloud Security Alliance</h3>
<p><a href="https://cloudsecurityalliance.org/research/working-groups">CSA working groups</a> are accessible and will welcome people even with limited experience. Some groups are more established in their ways of working than others, but in general you can contribute straight away by reviewing papers written by others and eventually get involved in new projects.</p>

<h3 id="local">Local</h3>
<p>Nothing can beat a local meet up, where you have the chance to meet other like-minded individuals and exchange ideas. Depending on the area you live in there will be different options, if there’s none - consider starting a local chapter with friends and/or colleagues. If you happen to be employed, your company should be happy to host an event once in a while, as it gives them brand exposure and results in a ton of positive PR material.</p>

<p>I happen to live in Warsaw at the moment, and there is a lot happening. If you’re elsewhere, look for the local equivalents of these.</p>
<ul>
  <li><a href="https://isc2chapter-poland.com/">ISC2 Chapter Poland</a></li>
  <li><a href="https://dc4822.org/">DC4822 - Official Warsaw DEFCON Group</a></li>
  <li><a href="https://local.issa.org.pl/">ISSA Polska</a></li>
  <li><a href="https://owasp.org/www-chapter-poland/">OWASP</a></li>
  <li><a href="https://crossweb.pl/en/events/warszawa/it/">Crossweb - overview of all events</a></li>
  <li><a href="https://www.meetup.com/pl-PL/find/?suggested=true&amp;source=EVENTS&amp;keywords=security">Meetup</a></li>
</ul>

<p>Certificates get you the interview, but talking to people is often where the real value lies.</p>]]></content><author><name>Piotr Maćkowski</name></author><category term="Self development" /><category term="Career" /><category term="Volunteering" /><summary type="html"><![CDATA[Certificates are great to show one is willing to go the extra mile. They usually come with a structured learning path, and satisfaction when you receive that precious badge in your mailbox. It is easy to fall into the trap of grinding certificates one after the other, without applying the knowledge you have gained, keeping structured notes and practicing spaced repetition. Do yourself a favor, and invest your time into other areas such as networking (the in-person type), projects and volunteering. Organizations and vendors usually have some way of building and engaging their community for obvious reasons. Think in terms of conferences, online events, user group meetups, working groups, community projects, Slack and Discord channels.]]></summary></entry></feed>