Live data from Hacker News

Microsoft lost its keys, and the government got hacked

techcrunch.com

91–100 of 151 posts

Re: Microsoft lost its keys, and the government got hacked

#91
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

After spending 5 years of corporate work having to wrestle with Azure (in a ci/cd capacity) I would never recommend Microsoft's cloud offerings to anyone. Problem is that there is no other provider I would rather recommend. They are all bad in one way or another.

As a counterpoint:

I've worked with both Azure cloud and Azure DevOps (or whatever the feck they call it now) for a long time (maybe 10 years?), a lot in a corporate setting, but also for my startup.

Apart from the same price issues that exist across all the big 3 cloud providers, I actually really like Azure.

Re: Microsoft lost its keys, and the government got hacked

#92

> Microsoft still doesn’t know — or want to share — how China-backed hackers stole a key that allowed them to stealthily break into dozens of email inboxes, including those belonging to several federal government agencies.

Speculation: insider threat

Re: Microsoft lost its keys, and the government got hacked

#93

Any Windows product/system is a liability. I'm not sure how to put this lightly. It was designed to create a monopoly first before any other goal. And it's not that the alternatives are perfect, but Windows is as secure as swiss cheese.

> Any Windows product/system is a liability.

A self-evident realization: every single product/system is a liability.

Re: Microsoft lost its keys, and the government got hacked

#94
post #31

This headline does a good job of pointing out why we shouldn't allow backdoors in encryption.

no one said it was a backdoor, though. you have to have a key to encrypt stuff, and it was that key which got leaked, somehow . a backdoor is a way around the use of a key to see secret messages, or an alternate key which allows you to view messages without compromising the key which encrypts messages in normal operation. could have been a backdoor, sure, could have been something else. could have been carelessness.…

They didn't say it was an intentional backdoor. But if it were, the result would be the same.

It's hard to secure encryption keys. If you had a backdoor based on a key that you had to keep secret, leaks like these can happen. If Microsoft (or anyone) can't keep their encryption keys secure, they'd be equally unable to keep a backdoor key secure for the same reason.

Re: Microsoft lost its keys, and the government got hacked

#95
post #31

This headline does a good job of pointing out why we shouldn't allow backdoors in encryption.

no one said it was a backdoor, though. you have to have a key to encrypt stuff, and it was that key which got leaked, somehow . a backdoor is a way around the use of a key to see secret messages, or an alternate key which allows you to view messages without compromising the key which encrypts messages in normal operation. could have been a backdoor, sure, could have been something else. could have been carelessness.…

But an encryption back door is either a second key that someone else holds or it is some piece of information the public should not know about.

Either way, when the details about the back door leak, the system ceases to retain the properties of secure encryption.

Re: Microsoft lost its keys, and the government got hacked

#96
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

After spending 5 years of corporate work having to wrestle with Azure (in a ci/cd capacity) I would never recommend Microsoft's cloud offerings to anyone. Problem is that there is no other provider I would rather recommend. They are all bad in one way or another.

AWS is pretty decent in my experience, and when managed with Terraform (which is all but a requirement if you don't want to go completely b0nkers) it's a breeze to manage.

Re: Microsoft lost its keys, and the government got hacked

#97
post #12

Earlier quoted context omitted.

And yet, fascinatingly, very very little discussion. 60-ish comments was the most on any of those posts.

Mentioning China negatively is the kiss of death.

I feel I can't discuss some foreign nations anymore in a critical way since I fear giving mentally unstable war mongers ideas.

Re: Microsoft lost its keys, and the government got hacked

#98

Any Windows product/system is a liability. I'm not sure how to put this lightly. It was designed to create a monopoly first before any other goal. And it's not that the alternatives are perfect, but Windows is as secure as swiss cheese.

I know this is a bit of a thread jack, but this same attitude now playing out on Xbox in the console space. The recent FTC attempt to block the Activision merger surfaced emails saying that they were just going to outspend Sony to further consolidate and buy a higher position in the market, because they can.

There's nothing in any of Microsoft's revealed communications over the years where they ever seem to aspire to make better products. I mean, sure, obviously, there are pockets inside the company, but that has never seemed to be the purview of the board or the executives. If there's a thought leader in there somewhere who had passion to make great products like Jobs, I can't think of who it would be.

I almost feel bad for Microsoft, and I say this as a Microsoft-hater and Linux zealot who ran it on the desktop for 19 years before switching to Mac. It's the legacy backward-compatibility that makes Windows so attractive to a lot of organizations which makes it so vulnerable. OTOH, corporate IT divisions love it because Microsoft lets them do all sorts of stupid things to it, like prevent me from changing the desktop background, so it's kind of a deserved punishment.

Re: Microsoft lost its keys, and the government got hacked

#99
post #92

> Microsoft still doesn’t know — or want to share — how China-backed hackers stole a key that allowed them to stealthily break into dozens of email inboxes, including those belonging to several federal government agencies.

Speculation: insider threat

That would be my amateur guess as well which scares me in a couple of ways.

Re: Microsoft lost its keys, and the government got hacked

#100
post #71

Earlier quoted context omitted.

I like the Azure bash cli... That's about the only thing I like from Azure.

I moved from Azure to AWS. App Insights, DevOps pipelines, and WebApp slots look like future tech when compared to codepipelines and x-ray. DevOps in particular feels so close to being a really great tool. Not having to jump between 8 different UIs to deploy something is magical. If only they'd polish the rough bits and invest a bit more into it.

We use DevOps for pipelines, but AWS for our prod cloud environment.
Post reply on HN