Live data from Hacker News

“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

arstechnica.com

51–60 of 92 posts

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#51

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

The question is if this wouldn't have been reported what are the chances that this would have been exploited. Or what are the chances that Microsoft got saved from a hack in the wild from this knowing this vulnerability. If we assume that the codebase has one vulnerability for 10k lines, we would still get 10s of thousands of vulnerabilities. Any one of those could cost billion dollar to Microsoft, but patching one of those doesn't make the chance of getting hacked much different.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#52
post #48

Earlier quoted context omitted.

The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice: 1. Disclose to Microsoft for $40k 2. Disclose to an intelligence agency for several times that 3. Disclose to criminals for several times that, in turn The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a si…

If companies have to outcompete criminals and intelligence agencies in the open market there will be no bug bounties, we'll just go back to the old way of doing things. The reality is that if an organization is using a managed database and doesn't have service-provider vulnerabilities as part of their threat model, they are naive and arguably negligent.

Mid-range engineer at big tech makes $350k / year. I think having a vulnerability like this go to Microsoft instead of criminals is easily worth a few engineer-years. A $1M payout is just not unreasonable or even difficult for a $2.5T corporation.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#53
post #2

I always wonder if these types of vulnerabilities affect the most secret DoD contracts, or if those accounts are somehow sharded onto sufficiently separate systems/networks?

Nope. Look here (https://docs.microsoft.com/en-us/azure/azure-government/comp...) and search for Cosmos and you'll see this service is only approved for DoD Impact Level II systems. That is the lowest impact level the DoD offers and includes only systems exposed to the public, like the websites for recruiting and career descriptions. Any system handling controlled unclassified information or PII would not have been allowed to use this service.

And when you're talking about "most secret" contracts, those are all classified systems, which are on totally separate networks in totally separate private data centers located on military installations. Unless you've figured out how to break strong symmetric encryption using hardware-generated, hardware-loaded, pre-shared keys controlled in military arms rooms, that means you need physical access. It doesn't necessarily mean you need to break into a military installation. You can always try to break into a contractor SCIF instead, but that still isn't all that easy. My wife once saw some AT&T contractors digging too close to the wrong fiber line at her facility when she was working for the Navy at a contractor site and unmarked black SUVs were there to take those guys away to God knows where within two minutes.

That said, I don't doubt people try. When I was at Raytheon working at a secure facility, a Chinese company bought the property across the street, built a hotel at exactly the same height with windows facing us, and it was conspicuously almost always empty. I don't think demand for hotel rooms was financing that place.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#54

Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?

This is more akin to leaving the door unlocked than to having a break in.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#55
post #48

Earlier quoted context omitted.

If companies have to outcompete criminals and intelligence agencies in the open market there will be no bug bounties, we'll just go back to the old way of doing things. The reality is that if an organization is using a managed database and doesn't have service-provider vulnerabilities as part of their threat model, they are naive and arguably negligent.

Mid-range engineer at big tech makes $350k / year. I think having a vulnerability like this go to Microsoft instead of criminals is easily worth a few engineer-years. A $1M payout is just not unreasonable or even difficult for a $2.5T corporation.

My point isn't that $40K is enough or $1M is too much, it's that pinning public payouts to the grey/black market is unsustainable. This bug could easily be worth $10M in the right hands, so why stop at 7 figures?

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#56
post #27

Earlier quoted context omitted.

> By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records? Comparing cloud storage and paper records is worse than comparing apples to oranges; it's comparing apples to celery. Sure they're both edible but they are vastly different organisms. And yes, there can be legal consequences for a company if someone breaks into their office and steals paper r…

An analogy of an analogy. Could somebody go one level deeper?

Comparing the original statement to the subsequent analogy is a bit like comparing an apple and an NFT of an apple...

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#57

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

One thing: Given the rise of MS stock in the recent past and the pandemic, I have seen many long-time MS folks decide to retire, especially in the last 10–12 months.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#58
post #34

Earlier quoted context omitted.

Because it is unethical and in most countries illegal :) But you are right. They should pay them more.

I wouldn’t use it maliciously, but I would honestly think twice about disclosing it. I think that’s especially true for anyone that doesn’t have a way to gain from the publicity.

This seems like a strange calculation... you think the scrutiny from being identified as talented enough to find this is bad enough to not be worth $40k + the reputation bump for your CV?

That seems overly paranoid.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#59
post #24

Earlier quoted context omitted.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice: 1. Disclose to Microsoft for $40k 2. Disclose to an intelligence agency for several times that 3. Disclose to criminals for several times that, in turn The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a si…

Options 2 and 3 pose a moral and physical risk. Money isn't the only factor.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#60

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

One thing is for sure, putting its astronomical revenue growth on the side, which presumably involves some fuzzy math... Azure is definitely the worst of the big three cloud providers
Post reply on HN