Not buying off on more than the fact the report was made.
Skepticism is the order of the day.
101–110 of 389 posts
Not buying off on more than the fact the report was made.
Skepticism is the order of the day.
Earlier quoted context omitted.
>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).
https://www.bnnbloomberg.ca/gavin-newsom-declares-california...
The "have been hacked by" scale seems to have two settings: 0. Forgot to secure access with password. 100. Nation state.
"Ah yes we are from IT and found suspicious behavior, we need to reset your password, can you provide it immediately? No? Okay well we will be contacting your manager immediately for insubordination. You may want to gather your belongings.
Ok, any capital letters?"
Earlier quoted context omitted.
I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…
I think it's a mistake to limit the scope of consideration to countries that are antagonist to America. I doubt it was them, but at least in theory, might not Canada have an interest in having advanced knowledge of things the US Treasury might decide? Certainly the US economy impacts Canada as well, as it does nearly any other country to one degree or another.
As much as Canadians like to shit on America, one thing they gave going for them south of the border is that "Fuck yeah America" attitude that leads people to pursue excellence.
We don't have that in our public sector. We just have passive aggression, mediocrity and memes about being polite.
Earlier quoted context omitted.
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.
Earlier quoted context omitted.
I don’t know a lot about how states conduct cyber espionage against one another, but it does feel a bit off to be told that this was the work of a nation state with zero proof as to why.
Some of it is based on analysis of the actors motives - if you have 0-day works on fully patched Office 365, that took months/years to work, and throw it at a US government agency, you're clearly not in it for the money, _and_ you have no qualms about blowing your exploit.
Earlier quoted context omitted.
>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…
Earlier quoted context omitted.
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.