Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.
These problems are specific to Microsoft though; outside of service outages and customer misconfiguration, AWS and GCP don't have a history of such incidents.
Everything authenticated by Microsoft is tainted
31–40 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#32This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.
Which has these among a long list (retaining the reverse order from link above). NB I have just copied and pasted for convenience; neither removed text which refers to links nor added the actual links. You can click through yourself if you want to follow the links.
8023-08: Again Microsoft, again Azure: "unauthorized access to cross-tenant applications and sensitive data (including but not limited to authentication secrets)". If you aren't tech-savvy: this is very bad. (Source)
A reoccuring pattern emerges more and more: Microsoft didn't fix the issue in months and as of 2023-08-03 it is still an open vulnerability in Azure, risking the data of all Azure customers. related:
Microsoft comes under blistering criticism for “grossly irresponsible” security | Ars Technica
BrianKrebs: "The CEO of Tenable just ripped Microsoft a new on…" - Infosec Exchange
2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry, Source, German source)
With the default logs, customers could not even detect intruders as you would need to pay extra to get access to those log files.
Microsoft did not communicate which services were affected and which not. Any Microsoft cloud service was potentially compromised.
Most probably, the usual "any compromised system needs to be thrown away and re-created from scratch will not be applied here. As a consequence, you can't trust any data from Microsoft services any more.
Security experts like Mike Kuketz think that most probably we need to consider all Microsoft systems that are using their cloud authentication including all Windows hosts are compromised.
According to this German source, Microsoft is still refusing to tell what happened and which systems are affected to what extend.
2023-08-18: German comment: Many similar comments like that underline that Microsoft disqualifies as a trustworthy partner.
2023-09-06: first public explanation by MS: Microsoft: Results of Major Technical Investigations for Storm-0558 Key Acquisition Press reactions: heise (German), fefe (German)
Re: Everything authenticated by Microsoft is tainted
#33I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.
This is clearly an overreaction. Cloud will be fine.
Re: Everything authenticated by Microsoft is tainted
#34The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??
Re: Everything authenticated by Microsoft is tainted
#35This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.
2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry [1], Source[2], German source)
Also the following:
https://infosec.exchange/@briankrebs/110820474957163710
Quite damning if true.
[1]: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... [2]: https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...
Re: Everything authenticated by Microsoft is tainted
#36Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.
Re: Everything authenticated by Microsoft is tainted
#37Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.
There is a best of both worlds in there and I think we've gotten where we are now because of cloud providers marketing themselves suitable for everyone.
Re: Everything authenticated by Microsoft is tainted
#38Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.
Re: Everything authenticated by Microsoft is tainted
#39Earlier quoted context omitted.
These problems are specific to Microsoft though; outside of service outages and customer misconfiguration, AWS and GCP don't have a history of such incidents.
Was the Capital One breach not a result of gross internal malpractice on the part of Amazon? That allowed an Amazon employee to gain priviledged access to CC data in Capital One's environment.
Re: Everything authenticated by Microsoft is tainted
#40This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…
Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.