Earlier quoted context omitted.
I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.
I thought enough (5 or so?) downvotes resulted in an automatic [flagged][dead]? Did I misunderstand?
U.S. Treasury breached by hackers backed by foreign government – sources
311–320 of 389 posts
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#312Re: U.S. Treasury breached by hackers backed by foreign government – sources
#313Earlier quoted context omitted.
Sure. I meant vouch for it if the post warrants it , and not otherwise. If it deserves to be buried, leave it buried.
>Sure. I meant vouch for it if the post warrants it, and not otherwise. If it deserves to be buried, leave it buried. A fair point. And a correct one too. I took that as a given, but apparently folks are unable to read my mind. :) Thanks for clarifying. I should have been more explicit.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#314Earlier quoted context omitted.
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
If your IT department cared, they could disable the app notification MFA method in AAD and force you to either use passwordless or a TOTP code, both of which prevent you from blindly approving a sign-in you aren't involved in.
Notably, Microsoft's consumer MFA, the type used to protect Hotmail and XBox accounts shows more information in the exact same mobile app!
It's not that they don't have the capability, or don't know that it's important. Microsoft has explicitly chosen to never ever show additional information of any type for enterprise customers only.
They care about the security of their own things, not you stuff, in other words.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#315Re: U.S. Treasury breached by hackers backed by foreign government – sources
#316Earlier quoted context omitted.
This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…
That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.
It is is on by default however when using the same mobile app for Hotmail or XBox live accounts.
Microsoft thinks the data of Fortune 500 companies is less valuable than your Minecraft skins.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#317Earlier quoted context omitted.
To be fair you have the burden of proof by asserting "computers connected to the internet can not be secured."
It's an open problem in science to prove security of a network connected computer. It's well known.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#318Earlier quoted context omitted.
I think it's a mistake to limit the scope of consideration to countries that are antagonist to America. I doubt it was them, but at least in theory, might not Canada have an interest in having advanced knowledge of things the US Treasury might decide? Certainly the US economy impacts Canada as well, as it does nearly any other country to one degree or another.
Hahaha our military can't even figure out boots for the troops, you think we can hack the US Government? As much as Canadians like to shit on America, one thing they gave going for them south of the border is that "Fuck yeah America" attitude that leads people to pursue excellence. We don't have that in our public sector. We just have passive aggression, mediocrity and memes about being polite.
https://en.m.wikipedia.org/wiki/Communications_Security_Esta...
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#319Earlier quoted context omitted.
How is it not Microsoft's fault if they don't provide the user with any information to decide whether the MFA request is legit?
There's literally no upside to hiding this information.
That said, I'm sure there's a reasonable level somewhere in the middle. The current situation certainly doesn't sound like it, although I haven't used any form of Microsoft MFA, so I can't really say either way.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#320Earlier quoted context omitted.
Didn't Dan Kaminsky and others have tools to produce nearly arbitray collisions by the early 2000s?
Perhaps? I can't find any evidence easily that Dan did have such tool, but "by the early 2000s" it's not at all unthinkable certainly. If you have a link that'd be great. However the trouble is MD5 collision isn't like that hilarious "Send all zeroes" Microsoft bug from a few weeks back where you just try it a few times then it works because someone was very stupid - the MD5 collision is pretty hard, the Merkle–Damgå…
The MS article on the collision says the attack required knowledge of, among other things, the predictable serial numbers. They could have had as little as the usual inter-cert issuance time, or in the worst-case scenario with entirely predictable numbers could have had months or more.
Depending on the window the funds required would change dramatically.