Earlier quoted context omitted.
Russian state media taking a victory lap, I see
Please leave your Redditor mentality at the door. Nothing good is gained by this kind of commenting.
Gotcha.
161–170 of 389 posts
Earlier quoted context omitted.
Russian state media taking a victory lap, I see
Please leave your Redditor mentality at the door. Nothing good is gained by this kind of commenting.
Gotcha.
Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simple firewall appliance. The absolute minimum set of configuration options, the simplest possible hardware architecture; something you could actually trust with your life. Right now I have zero confidence that any of the commercially available security appliances are actually secure against nation-states.
Source: https://www.nytimes.com/2020/12/13/us/politics/russian-hacke...
Everytime I hear about Office 365, it's always with respect to some vulnerability or downtime.
For me it’s usually complaining about what the fuck shit they have done to outlook. It’s like a train in Mumbai at rush hour these days.
We're moving to 365 and I'd like to know what f*ckery to expect. =(
Earlier quoted context omitted.
For me it’s usually complaining about what the fuck shit they have done to outlook. It’s like a train in Mumbai at rush hour these days.
Could you expand on that? We're moving to 365 and I'd like to know what f*ckery to expect. =(
Rest of office is pretty good. Do not worry about this. It works well.
Fortunately no classified information was compromised. All of the Treasury emails just said "brrrrrrr".
Maybe trusting Microsoft with the keys to your kingdom is a bad idea.
All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…
Earlier quoted context omitted.
>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
I'm just glad I'm not the only one who sees this as a problem.
Earlier quoted context omitted.
Yes, I’m quite certain they can/do, as it is a requirement for FedRAMP. However, the US government has their own IDS/IDP that they use for the .gov domain, namely EINSTEIN (and its variants).
Don't confuse the .gov DNS/email domain and network monitoring tools like Einstein. The brave new world of govt cloud computing use makes this not as straight forward as it might have been 10 years ago.
Then again, I have seen crazier things and sometimes government takes quite a while to catch up with technology implementations.