Live data from Hacker News

“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

arstechnica.com

31–40 of 92 posts

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#32
It's even hard to imagine how this might have happened. Is the service a shared Jupyter server (or group thereof) that somehow has access to everything and it's within this service that the access/authorization is implemented? I wouldn't expect IAM to work this way in a cloud service

I don't know how these security boundaries are usually implemented, but I would expect this bug to be way less plausible. Isn't this an architectural smell?

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#33

What kind of private key is it, and can it be called _private_ key if it exists remotely?

It's private in the tenant. A SSL certificate encrypted web server also has the private key in the remote machine. Potentially hosting millions of other pages.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#34

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

Because it is unethical and in most countries illegal :)

But you are right. They should pay them more.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#35
post #24

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

That sounds like paying artists with "exposure".

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#36
post #24

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

Uh, yeah, maybe, I'm not sure how much this changes things to be honest. I fully agree with grandparent this is $1MM reward territory. (Edit: sibling put it really elegantly, this is pay-with-exposure justification)

PR campaign or not, you don't spit on those kinds of rewards. And it's a bad look on MS to award 40k on one of the worst vulnerabilities to ever hit a cloud provider...

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#37

Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?

You mean like in bailment? That's a thing.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#38

Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?

If we're into bad physical analogies, I feel a better comparison would be the company itself sending an indexed copy of the records of all their clients and relying on ethics alone to keep someone from reading others' data.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#39
post #24

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice:

1. Disclose to Microsoft for $40k

2. Disclose to an intelligence agency for several times that

3. Disclose to criminals for several times that, in turn

The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a significant number of vulnerabilities will be exploited rather than reported.

$40k doesn't even come close to covering engineer time here. This should be a $1M payout.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#40

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

I'm wondering about this, too. There are so many things being redone from scratch that I'm scratching my head about the why. Maybe Microsoft lost so many engineers from the 90s that they don't have the people anymore that understand the old code.
Post reply on HN