Live data from Hacker News

“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

arstechnica.com

11–20 of 92 posts

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#12

It's bothersome that they keep saying 'primary key' in regards to what seems to be an 'access key' relating to a database. Disappointing to see that it's arstechnica.

It's the term that MS uses, agree unfortunate name but you can't blame Ars.

https://docs.microsoft.com/en-us/azure/cosmos-db/secure-acce...

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#14
post #6

I think the worst vulnerability I can imagine is the USG having unfettered access to the entire db contents without a warrant, which is already the case with everything in Azure. This bug only seems to widen that vulnerability slightly, to those groups plus those with knowledge of this bug. Nothing in major US cloud providers can reasonably be expected to remain private, so I think this breathless headline is a littl…

> Nothing in major US cloud providers can reasonably be expected to remain private

I'd expand that to "Nothing in third-party cloud providers can reasonably be expected to remain private". If you don't have ultimate oversight of how the host of your data is managed, anything could be going on there, regardless what nationality of company is managing it or what promises their salespeople make.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#17
post #6

I think the worst vulnerability I can imagine is the USG having unfettered access to the entire db contents without a warrant, which is already the case with everything in Azure. This bug only seems to widen that vulnerability slightly, to those groups plus those with knowledge of this bug. Nothing in major US cloud providers can reasonably be expected to remain private, so I think this breathless headline is a littl…

>the worst vulnerability I can imagine is the USG having unfettered access You cannot imagine any other party it would be worse to be vulnerable to?

No.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#18
post #6

I think the worst vulnerability I can imagine is the USG having unfettered access to the entire db contents without a warrant, which is already the case with everything in Azure. This bug only seems to widen that vulnerability slightly, to those groups plus those with knowledge of this bug. Nothing in major US cloud providers can reasonably be expected to remain private, so I think this breathless headline is a littl…

> Nothing in major US cloud providers can reasonably be expected to remain private I'd expand that to "Nothing in third-party cloud providers can reasonably be expected to remain private". If you don't have ultimate oversight of how the host of your data is managed, anything could be going on there, regardless what nationality of company is managing it or what promises their salespeople make.

Further amended: nothing connected to the internet can reasonably be expected to remain private.

Unless you have some secret kung-fu that makes your on-prem infrastructure hack-proof.

The issue with the cloud is scale.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#19
Whenever stuff like this happens I see people saying there should be legal consequences for leaking data.

By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#20

Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?

https://www.law.cornell.edu/wex/negligence
Post reply on HN