Live data from Hacker News

“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

arstechnica.com

61–70 of 92 posts

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#61
post #18

Earlier quoted context omitted.

> Nothing in major US cloud providers can reasonably be expected to remain private I'd expand that to "Nothing in third-party cloud providers can reasonably be expected to remain private". If you don't have ultimate oversight of how the host of your data is managed, anything could be going on there, regardless what nationality of company is managing it or what promises their salespeople make.

Further amended: nothing connected to the internet can reasonably be expected to remain private. Unless you have some secret kung-fu that makes your on-prem infrastructure hack-proof. The issue with the cloud is scale.

> The issue with the cloud is scale

I’d argue the issue with cloud is less about scale, more about how easy it is to get started. My mother could quite easily click through the account creation on a cloud provider and setup something insecure, but not a chance is she going to get a DC built with equipment racked or even a basic setup at a colo facility.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#62
post #50

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

I think this is more of an industry problem than a Microsoft problem. This was a feature added onto an existing service. The old waterfall method of security approvals might have caught this, but for most orgs that has gone the way of the dodo (and probably for the better). Cosmos DB probably went through security review during the design phase and then again regularly as the code was written and improved. The Jupyte…

this sounds reasonable but, in this case stealing a key and using it for a man-in-the-middle attack, is what happened

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#63
post #60

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

One thing is for sure, putting its astronomical revenue growth on the side, which presumably involves some fuzzy math... Azure is definitely the worst of the big three cloud providers

AZURE seems to be trying to play catch up -at least in feature parity - with AWS and to some extent GCP. IMO this sort of outcome is inevitable when moving at speed. While they do seem to have some sort of feature parity (on the tin type) and some good ideas, many of the services they have a pretty half baked once you scratch the surface, plus they're expensive.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#64
post #55

Earlier quoted context omitted.

Mid-range engineer at big tech makes $350k / year. I think having a vulnerability like this go to Microsoft instead of criminals is easily worth a few engineer-years. A $1M payout is just not unreasonable or even difficult for a $2.5T corporation.

My point isn't that $40K is enough or $1M is too much, it's that pinning public payouts to the grey/black market is unsustainable. This bug could easily be worth $10M in the right hands, so why stop at 7 figures?

You think Microsoft can't pay $10 million? Paying $40k means they don't give a shit about their customers.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#65
post #34

Earlier quoted context omitted.

Because it is unethical and in most countries illegal :) But you are right. They should pay them more.

I wouldn’t use it maliciously, but I would honestly think twice about disclosing it. I think that’s especially true for anyone that doesn’t have a way to gain from the publicity.

What would you use it for instead? 40k + recognition sounds way better than 0 and sitting on it.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#66
Microsoft isn't helped by the fact that there are also FB and Google in town, and they pay at least 20% more and have better engineers to work with as well, which makes work far less aggravating. So MS gets FB/Google rejects at this point, and there's a constant brain drain on top of that. But their internal culture has always been, "if we pay managers well enough things will work out". This breaks down when you actually have to do something hard (rather than rearrange buttons on Office app toolbars), as managers aren't the ones who do the actual work.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#67
post #55

Earlier quoted context omitted.

My point isn't that $40K is enough or $1M is too much, it's that pinning public payouts to the grey/black market is unsustainable. This bug could easily be worth $10M in the right hands, so why stop at 7 figures?

You think Microsoft can't pay $10 million? Paying $40k means they don't give a shit about their customers.

The reason you pay so little is to not encourage ppl to even start looking.

Knowledge required to find stuff like that is very scarse. And you have to know where to look for.

Chances to find something really big are so small that its not worth it to look for them finnancially.

Thats why ppl don’t do that often. They do it if they have long cooperation history with given company because they are treated as an employee.

TL;DR is that you don’t want to encourage ppl to start looking. All software has bugs, so its only a matter of time until someone finds something.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#68
post #40

I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…

I'm wondering about this, too. There are so many things being redone from scratch that I'm scratching my head about the why. Maybe Microsoft lost so many engineers from the 90s that they don't have the people anymore that understand the old code.

Understanding old code rarely gets one promotions.

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#69

$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.

well the black market is always going to pay more. that's kinda why criminals tend to go there...

Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure

#70
post #24

Earlier quoted context omitted.

The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.

The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice: 1. Disclose to Microsoft for $40k 2. Disclose to an intelligence agency for several times that 3. Disclose to criminals for several times that, in turn The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a si…

if you're only in it for the money i don't think white hat is your calling.
Post reply on HN