https://www.wired.com/story/microsoft-morse-team/ Skip to main content Open Navigation Menu To revist this article, visit My Profile, then View saved stories. Close Alert WIRED The Microsoft Team Racing to Catch Bugs Before They Happen * Backchannel * Business * Culture * Gear * Ideas * Science * Security More To revist this article, visit My Profile, then View saved stories. Close Alert Sign In Search * Backchannel * Business * Culture * Gear * Ideas * Science * Security * Podcasts * Video * Artificial Intelligence * Climate * Games * Newsletters * Magazine * Events * Wired Insider * Coupons Lily Hay Newman Security Aug 3, 2022 12:43 PM The Microsoft Team Racing to Catch Bugs Before They Happen What's it like to be responsible for a billion people's digital security? Just ask the company's Morse researchers. * * * * To revist this article, visit My Profile, then View saved stories . Microsoft Logo Photograph: 360b/Alamy * * * * To revist this article, visit My Profile, then View saved stories . As a rush of cybercriminals, state-backed hackers, and scammers continue to flood the zone with digital attacks and aggressive campaigns worldwide, it's no surprise that the maker of the ubiquitous Windows operating system is focused on security defense. Microsoft's Patch Tuesday update releases frequently contain fixes for critical vulnerabilities, including those that are actively being exploited by attackers out in the world. The company already has the requisite groups to hunt for weaknesses in its code (the "red team") and develop mitigations (the "blue team"). But recently, that format evolved again to promote more collaboration and interdisciplinary work in the hopes of catching even more mistakes and flaws before things start to spiral. Known as Microsoft Offensive Research & Security Engineering, or Morse, the department combines the red team, blue team, and so-called green team, which focuses on finding flaws or taking weaknesses the red team has found and fixing them more systemically through changes to how things are done within an organization. "People are convinced that you cannot move forward without investing in security," says David Weston, Microsoft's vice president of enterprise and operating system security who's been at the company for 10 years. "I've been in security for a very long time. For most of my career, we were thought of as annoying. Now, if anything, leaders are coming to me and saying, 'Dave, am I OK? Have we done everything we can?' That's been a significant change." Morse has been working to promote safe coding practices across Microsoft so fewer bugs end up in the company's software in the first place. OneFuzz, an open source Azure testing framework, allows Microsoft developers to be constantly, automatically pelting their code with all sorts of unusual use cases to ferret out flaws that wouldn't be noticeable if the software was only being used exactly as intended. The combined team has also been at the forefront of promoting the use of safer programming languages (like Rust) across the company. And they've advocated embedding security analysis tools directly into the real software compiler used in the company's production workflow. That change has been impactful, Weston says, because it means developers aren't doing hypothetical analysis in a simulated environment where some bugs might be overlooked at a step removed from real production. The Morse team says the shift toward proactive security has led to real progress. In a recent example, Morse members were vetting historic software--an important part of the group's job, since so much of the Windows codebase was developed before these expanded security reviews. While examining how Microsoft had implemented Transport Layer Security 1.3, the foundational cryptographic protocol used across networks like the internet for secure communication, Morse discovered a remotely exploitable bug that could have allowed attackers to access targets' devices. As Mitch Adair, Microsoft's principal security lead for Cloud Security, put it: "It would have been as bad as it gets. TLS is used to secure basically every single service product that Microsoft uses." Most Popular * ISS science Russia's War in Ukraine Reveals More Problems in Space Ramin Skibba * Young child working on computers and phone at desk at night gear Kids Are Back in Classrooms and Laptops Are Still Spying on Them Pia Ceres * colorful still life with pill bottle, powders and other shapes backchannel The High-Stakes Race to Engineer New Psychedelic Drugs John Semley * a white device for brain science The Age of Brain-Computer Interfaces Is on the Horizon Grace Browne * The stakes are indescribably high when your job is to catch mistakes before someone else does in a product that's used by more than a billion people around the world. Anything you let slip by could play a role in the next global cybersecurity crisis. But Weston says the Morse team self-selects for people who view that reality as a driving motivation, rather than a paralyzing specter. "This is a game of inches; you can be amazing 99.9 percent of the time and introduce the wrong code at the wrong time and it can have dire consequences," Weston says. "If you work on the top of a tall building all day, you don't even notice it. But one day you might look down and go, 'whoa, I'm pretty high up here, that's scary.' But there are only a couple of places where you can do things at a billion scale, so the nice thing is we rarely have someone coming in who doesn't find that exciting rather than scary." Perhaps most importantly, Weston says the tradeoff for living with Microsoft's scale and the accompanying responsibility is that anything is possible at the company in a way that is only true at a small handful of the biggest tech giants. "In some companies it's like, well, we build a web application, we're sort of constrained on the tools we have or the expertise in the company," he says. "At Microsoft, we have everything from silicon to compilers to the operating system. You don't really have good excuses for why you can't do something." For the Morse team, though, this means there's no room to squander that rarified position. More Great WIRED Stories * The latest on tech, science, and more: Get our newsletters! * Humans have always been wrong about humans * I shredded a 70-mile dirt ride on a folding bike * After Roe, men might finally get better birth control * How to get into voice acting for video games * China is racing to electrify its future * [?] Explore AI like never before with our new database * [?] Want the best tools to get healthy? Check out our Gear team's picks for the best fitness trackers, running gear (including shoes and socks), and best headphones [Lily] Lily Hay Newman is a senior writer at WIRED focused on information security, digital privacy, and hacking. She previously worked as a technology reporter at Slate magazine and was the staff writer for Future Tense, a publication and project of Slate, the New America Foundation, and Arizona State University. Additionally... Read more Senior Writer * More from WIRED Many wooden arrows moving in pattern on red background The DHS Bought a 'Shocking Amount' of Phone-Tracking Data The ACLU released a trove of documents showing how Homeland Security contracted with surveillance companies to scour location information. Ashley Belanger, Ars Technica person reflected in mirror tiles A New Attack Can Unmask Anonymous Users on Any Major Browser Researchers have found a way to use the web's basic functions to identify who visits a site--without the user detecting the hack. Lily Hay Newman Person wearing earbuds and staring at bright phone screen in dark room Apple's Lockdown Mode Aims to Counter Spyware Threats Starting with iOS 16, people who are at risk of being targeted with spyware will have some much-needed help. Lily Hay Newman Automated license plate reader cameras mounted on traffic pole above street The Danger of License Plate Readers in Post-Roe America Known as ALPRs, this surveillance tech is pervasive across the US--and could soon be used by police and anti-abortion groups alike. Thor Benson Human eye shown on pixelated screen with hand cursor obscuring pupil Congress Might Pass an Actually Good Privacy Bill A bill with bipartisan support might finally give the US a strong federal data protection law. Gilad Edelman Woman looking at phone in bed in dark room The Most Popular Period-Tracking Apps, Ranked by Data Privacy Under increased scrutiny, certain period-tracking apps are seeing a surge of new users. Which are as safe as they claim to be? Kristen Poli A police officer wearing protective gear is seen walking in a street in Shanghai, China Chinese Police Exposed 1B People's Data in Unprecedented Leak Plus: A duplicitous bug bounty scheme, the iPhone's new "lockdown mode," and more of the week's top security news. Lily Hay Newman Close-up of computer processing chips New 'Retbleed' Attack Can Swipe Key Data From Intel and AMD CPUs The exploit can leak password information and other sensitive material, but the chipmakers are rolling out mitigations. Dan Goodin, Ars Technica WIRED WIRED is where tomorrow is realized. It is the essential source of information and ideas that make sense of a world in constant transformation. The WIRED conversation illuminates how technology is changing every aspect of our lives--from culture to business, science to design. The breakthroughs and innovations that we uncover lead to new ways of thinking, new connections, and new industries. * * * * * * More From WIRED * Subscribe * Newsletters * FAQ * Wired Staff * Press Center * Coupons * Editorial Standards Contact * Advertise * Contact Us * Customer Care * Jobs * RSS * Site Map * Accessibility Help * Conde Nast Store * Conde Nast Spotlight * Do Not Sell My Personal Info (c) 2022 Conde Nast. All rights reserved. Use of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Your California Privacy Rights. Wired may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices