Live data from Hacker News

“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

arstechnica.com

41–50 of 92 posts

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#41
post #34

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

Because it is unethical and in most countries illegal :) But you are right. They should pay them more.

I wouldn’t use it maliciously, but I would honestly think twice about disclosing it. I think that’s especially true for anyone that doesn’t have a way to gain from the publicity.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#42
post #24

Earlier quoted context omitted.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

That sounds like paying artists with "exposure".

There is kind of a 2-sided argument here:

1. Small time cheap skate business owners sometimes try to cheat professional artists by "paying with exposure", when they have no meaningful audience or influence and therefore no meaningful exposure to give.

2. Sources that do genuinely have very large audiences and influence can infact give an artist so much exposure that it's worth far more than any reasonable direct payment

This situation seems a lot more like 2 than 1. The company is in the business of helping companies secure their cloud environments, and these articles going around the tech press are being read by hundreds of thousands of people who are generally more interested in cloud security than a random person. They could spend many times the amounts discussed here on advertising and still not get their name in front of that many of the right people in a good context.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#43

Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?

There already are consequences. Auditors will check the physical security of your office buildings if you're dealing with anything sensitive. If a breach happens later on and it turns out you cut corners on that physical security (or even somehow unwittingly compromised it) then you're not going to have a good time.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#44
post #42

Earlier quoted context omitted.

That sounds like paying artists with "exposure".

There is kind of a 2-sided argument here: 1. Small time cheap skate business owners sometimes try to cheat professional artists by "paying with exposure", when they have no meaningful audience or influence and therefore no meaningful exposure to give. 2. Sources that do genuinely have very large audiences and influence can infact give an artist so much exposure that it's worth far more than any reasonable direct paym…

Big or small company, I doubt they can pay the employees' salary with "exposure". They might have pratically infinite VC money for now, but that's an orthogonal discussion, just as "exposure" and being fairly compensated are.

edit: and what about it had been a smaller company or individual researcher who wouldn't be able to gain as much from this publicity? Are you saying that Microsoft would have awarded them $ 500k? Because that's not the message sent with this reward. And frankly, even this discussion is kind of off-the-point because I doubt that's what they took into account when defining the money quantity.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#45

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

At the time of XP, Microsoft had a fierce monopoly in the world and was absolutely dominating.

I wouldn’t be surprised if they started embracing the “ship fast” mentality with the cloud a bit more over the past years, in order to corner the market more quickly (which they did).

Additionally, I can also imagine that the release processes for cloud are fundamentally different than something like an OS. With the cloud, there’s a much larger mentality of releasing often, and it may be difficult to translate rigorous security audits to this workflow.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#46
post #24

Earlier quoted context omitted.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice: 1. Disclose to Microsoft for $40k 2. Disclose to an intelligence agency for several times that 3. Disclose to criminals for several times that, in turn The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a si…

[deleted]

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#47

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

Maybe they have already sold the exploit months ago to everybody that would buy it?

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#48
post #24

Earlier quoted context omitted.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice: 1. Disclose to Microsoft for $40k 2. Disclose to an intelligence agency for several times that 3. Disclose to criminals for several times that, in turn The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a si…

If companies have to outcompete criminals and intelligence agencies in the open market there will be no bug bounties, we'll just go back to the old way of doing things.

The reality is that if an organization is using a managed database and doesn't have service-provider vulnerabilities as part of their threat model, they are naive and arguably negligent.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#49
post #40

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

I'm wondering about this, too. There are so many things being redone from scratch that I'm scratching my head about the why. Maybe Microsoft lost so many engineers from the 90s that they don't have the people anymore that understand the old code.

The problem here is due to a lack of basic security practices. There is nothing related to old code, it is brand new code and infrastructure that was deployed without audit.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#50

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

I think this is more of an industry problem than a Microsoft problem. This was a feature added onto an existing service. The old waterfall method of security approvals might have caught this, but for most orgs that has gone the way of the dodo (and probably for the better).

Cosmos DB probably went through security review during the design phase and then again regularly as the code was written and improved. The Jupyter notebook functionality was also likely reviewed by security teams during the design, testing, and implementation phases. But once you're through those approvals most security review is going to be done via automated tooling with only occasional re-reviews and penetration testing at scheduled intervals. Automated testing is great at detecting vulnerabilities that have been discovered in the past, but really not good at detecting new classes of vulnerabilities, hard-to-detect authorization vulnerabilities, or how code integrates with other services.

Once the initial approval and code reviews had been done developers would still be committing code to the service and each line of code is probably not receiving a manual code review. Vulnerabilities like this are hard to detect even with a manual review as the testing team may not have great knowledge of all interconnected services, especially if it's an outside vendor.

Post reply on HN