“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
31–40 of 92 posts
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#32I don't know how these security boundaries are usually implemented, but I would expect this bug to be way less plausible. Isn't this an architectural smell?
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#33What kind of private key is it, and can it be called _private_ key if it exists remotely?
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#34$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.
But you are right. They should pay them more.
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#35$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.
The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#36$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.
The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.
PR campaign or not, you don't spit on those kinds of rewards. And it's a bad look on MS to award 40k on one of the worst vulnerabilities to ever hit a cloud provider...
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#37Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#38Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#39$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.
The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.
1. Disclose to Microsoft for $40k
2. Disclose to an intelligence agency for several times that
3. Disclose to criminals for several times that, in turn
The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a significant number of vulnerabilities will be exploited rather than reported.
$40k doesn't even come close to covering engineer time here. This should be a $1M payout.
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#40I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…