Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

11–20 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#11
We all ought to be using Qubes OS! We, as the Hacker News community, ought to be more concerned about making it easier to use reasonably secure systems. How do I buy a computer that runs Qubes?

https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/

Re: Everything authenticated by Microsoft is tainted

#12
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

These problems are specific to Microsoft though; outside of service outages and customer misconfiguration, AWS and GCP don't have a history of such incidents.

Re: Everything authenticated by Microsoft is tainted

#15
post #2

I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.

This is clearly an overreaction. Cloud will be fine.

Re: Everything authenticated by Microsoft is tainted

#16
Microsoft should have done a clean room implementation of their cloud and used that to pivot their customers into more manageable technology for both parties.

That they've chosen to integrate it with all their legacy stack (which is one of the most complicated ones in existence) is understandable and what 99% of companies would have done but... it's a horrible experience using it. Maybe people with only Microsoft experience don't feel the pain anymore.

Re: Everything authenticated by Microsoft is tainted

#17

We all ought to be using Qubes OS! We, as the Hacker News community, ought to be more concerned about making it easier to use reasonably secure systems. How do I buy a computer that runs Qubes? https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/

why?

Re: Everything authenticated by Microsoft is tainted

#18
post #8
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

On-prem is very expensive compared to cloud.

It's actually often cheaper[1], assuming you need a relatively fixed amount of compute and have the capital for upfront costs. Cloud gives you a lot of flexibility, but at a premium, and trades CAPEX for OPEX which is very appealing if you're a startup and don't know if you'll be around in a year.

[1] https://www.researchgate.net/figure/Yearly-cost-difference-o...

Re: Everything authenticated by Microsoft is tainted

#19
post #8
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

On-prem is very expensive compared to cloud.

For upfront costs, it can be. But when your running its pretty smooth sailing.

Or is this the discussion of having a team of SysOps vs a team of Cloud Engineers?

Re: Everything authenticated by Microsoft is tainted

#20
This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".
Post reply on HN