U.S. and key allies accuse China of Microsoft Exchange cyberattacks
1–10 of 267 posts
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#2Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#3Will someone accuse Microsoft of publishing vulnerable software?
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#4Will someone accuse Microsoft of publishing vulnerable software?
The issue is not that a random guy on the internet hacks the software, but a _state_ actor.
I feel bad for the admins who are stuck with these systems.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#5In Stuxnet for example, the alleged perpetrators hinted that they were behind it.
Will the same countries and allies now condemn known, disclosed and proven cyberattacks sourced from other countries (with known state involvement and complicity) on activists and journalists that lead to imprisonment and death?
And Microsoft has a very long history of vulnerabilities and hiding it. And then they will refuse to patch known vulnerabilities in lower versioned software trying to force large customers to do unwanted version upgrades and to adopt the more expensive SaaS offerings.
They are now trying to force all customers off of the already paid for and cheaper on-prem Microsoft Exchange which is still the dominant software in the directory services market and trying to get all corporates onto Azure AD.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#6Will someone accuse Microsoft of publishing vulnerable software?
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#7Earlier quoted context omitted.
The issue is not that a random guy on the internet hacks the software, but a _state_ actor.
The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft. I feel bad for the admins who are stuck with these systems.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#8Will someone accuse Microsoft of publishing vulnerable software?
If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#9Will someone accuse Microsoft of publishing vulnerable software?
If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors
(Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the driving force behind buying security measures is not the (unlikely) possibility of being a victim of a break-in, but the (more likely) possibility of not getting insurance to cover it.)
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#10Will someone accuse Microsoft of publishing vulnerable software?