Live data from Hacker News

Microsoft lost its keys, and the government got hacked

techcrunch.com

71–80 of 151 posts

Re: Microsoft lost its keys, and the government got hacked

#71

Earlier quoted context omitted.

After spending 5 years of corporate work having to wrestle with Azure (in a ci/cd capacity) I would never recommend Microsoft's cloud offerings to anyone. Problem is that there is no other provider I would rather recommend. They are all bad in one way or another.

I like the Azure bash cli... That's about the only thing I like from Azure.

I moved from Azure to AWS.

App Insights, DevOps pipelines, and WebApp slots look like future tech when compared to codepipelines and x-ray.

DevOps in particular feels so close to being a really great tool. Not having to jump between 8 different UIs to deploy something is magical. If only they'd polish the rough bits and invest a bit more into it.

Re: Microsoft lost its keys, and the government got hacked

#72
post #66

I work for NASA. Our budget is like $25B. We’re definitely inefficient and wasteful, but we still do a lot of new things. Just not nearly as much as we could. Microsoft’s operating budget was like $123B last year. There are bugs in office products that have been there for years What exactly are they doing with all that money?

[flagged]

Ah, no, but point taken. I can't think of an example myself because I don't know how Nasa functions.

Besides that, I think the valid critique (without the subtext) is, it's probably not a good comparison to measure a very large companies failings to a much smaller companies failings because their size is a definitively weighted factor in the outcome.

The caveat that I would add, is Nasa is publicly funded and it's probably ok to ask the question in the public interest. For private companies like Microsoft, just stop buying their products.

Re: Microsoft lost its keys, and the government got hacked

#73
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

> It saddens me to say, I don't know what the answer is.

I think the answer is a company willing to put in the work to force GPU manufacturers to provide high quality hardware drivers for a commercial Linux Distro. I mean all out partnership with the various vendors. Then sell prebuilts, maybe someone like System76 has come close, or has the capacity to do so. The Linux issues for me always seem to be hardware specific. Then its just making sure whatever the default DE is, has enough necessary polish.

Re: Microsoft lost its keys, and the government got hacked

#74

One of the reasons why we moved away from using Microsoft products for our identity management to Okta. Not that they are bad products per se, but as many organizations use Microsoft products they are prime targets for too many hackers and it’s hard going to bed thinking that your identity info might be hacked someday and/or not knowing if it will be. The surface area that Azure/Microsoft have is just too large for i…

Okta has been hacked a couple times now...

To toot my own companies horn[0] we designed our authentication protocol OpenPubkey[1] to have two signers on tokens:

1. The IDP signer (like microsoft or google) 2. The Cosigner (like bastionzero.com)

...so that even if microsoft's signing key is stolen, the attacker also needs to compromise the cosigner's signing key as well. It's like multisig for authentication tokens.

I don't know if OpenPubkey would have helped in this particular case as the details are still coming out[2], but I think the future of authentication schemes must require that authentication tokens must be signed by multiple signers at different organizations; Authentication systems with single point of compromise signing keys is too fragile. Or put another way authentication via multiple independent roots of trust is just too powerful of a security tool not to use.

[0]: BastionZero, https://bastionzero.com

[1]: OpenPubkey: Augmenting OpenID Connect with User held Signing Keys, https://eprint.iacr.org/2023/296

[2]: It appears the key stolen was an MSA key, not an Azure AD signing key. The MSA architecture might not fit into the OpenPubkey model (or it might I don't know enough about MSA signing keys work to say). Had it been an Azure AD signing key then OpenPubkey would mitigate the theft of an Azure AD Signing key. https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...

Re: Microsoft lost its keys, and the government got hacked

#75
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

After spending 5 years of corporate work having to wrestle with Azure (in a ci/cd capacity) I would never recommend Microsoft's cloud offerings to anyone. Problem is that there is no other provider I would rather recommend. They are all bad in one way or another.

The big red issue with MS is they elaborately make it very difficult to integrate outside their ecosystem and they love holding customers hostage to ridiculous restrictions, but also Azure is very difficult to centrally manage things for all subscriptions. Others are as well but not as much. I actually like the azure UI and CLI as well as many if their offerings, but it's so difficult to piece together a bigger picture or make small changes without doing a ton of work and more MS products being involved.

Also,unrelated: Azure AD is now "Entra ID" (????) now lol.

Re: Microsoft lost its keys, and the government got hacked

#76
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

> It saddens me to say, I don't know what the answer is. I think the answer is a company willing to put in the work to force GPU manufacturers to provide high quality hardware drivers for a commercial Linux Distro. I mean all out partnership with the various vendors. Then sell prebuilts, maybe someone like System76 has come close, or has the capacity to do so. The Linux issues for me always seem to be hardware specif…

people making massive income from the system exactly the way it is, do not care about doing this

Re: Microsoft lost its keys, and the government got hacked

#77
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

I’d go with Gmail…

Their pricing has become bonkers over the last few years. Most people in traditional businesses need o365 for word/excel/powerpoint, and you effectively get email for free, so for many companies its a no brainer.

Re: Microsoft lost its keys, and the government got hacked

#78
American companies are generally forbidden by EEOC rules from having reasonable security precautions unless some product is associated with a government contract and can require full blown security clearances. As a result you can safely assume that any given department with a juicy portfolio is fully compromised by foreign intelligence.

Re: Microsoft lost its keys, and the government got hacked

#80
post #67

Earlier quoted context omitted.

This really surprised me when I learned of this story on the weekend. Very little discussion, very little reception in IT news. Someone hacked Azure AD [1] and accessed the data of 25+ orgs and the reaction is *crickets*? [1] I'm not exactly sure which Azure component was hacked and the MS communication seems intentionally unclear and obtuse on this. It sounds like the private keys of Azure-internal auth servers were…

Microsoft has published a more technical analysis[1] which was submitted in two of those HN stories mentioned above (which received no interest). Microsoft have two identity services being MSA and AAD. MSA is used for consumer Microsoft accounts for use with products like Xbox. AAD is Azure AD that businesses use. When a client wants to authenticate to a Microsoft service, it asks MSA to sign a token for services acc…

As an update, the attackers were discovered by the customer due to mailbox access event logs showing an unexpected mail client to access mailbox items.[1][2] The attacker should have spoofed a realistic mail client.

[1] https://www.cisa.gov/news-events/cybersecurity-advisories/aa...

[2] https://learn.microsoft.com/en-us/office365/servicedescripti...

Post reply on HN