I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…
>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
WaPo is reporting that this and the FireEye breach were via Solarwinds:
> All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity.
That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.
How is it not Microsoft's fault if they don't provide the user with any information to decide whether the MFA request is legit?
There's literally no upside to hiding this information.
It seems like a fair game to me. You can always protect yourself by investing in cyber-security if you don't want to be spied on. It's not like war where innocent people die and a there's a lot of human suffering. It's just a tech race where the nations doing a good job get a deserved advantage without doing direct damage to the population.
There are hacks that can cause extensive destruction. But it isn't good to talk about them lest we give people ideas.
The United States has admitted to perpetrating coups to get a us-friendly dictator in otherwise democratic societies: https://www.youtube.com/watch?v=_2khAmMTAjI
Curious how this is connected at all to my question? I know "America Bad" is trendy now, but I don't see the connection.
Please, this isn't Reddit. The US just happens to be part of the list of bad guys together with Russia, North Korea, Israel, PRC, etc. The difference is that on sites with a lot of US users pointing the finger at the US is more often than not seen as someone being Edgy or whatever while pointing it at Russia is cool/patriotic/stating the facts/etc.
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
WaPo is reporting that this and the FireEye breach were via Solarwinds: > All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity. https://www.washingtonpost.com/national-security/russian-gov...
>SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information