Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

31–40 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#31
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

These problems are specific to Microsoft though; outside of service outages and customer misconfiguration, AWS and GCP don't have a history of such incidents.

Was the Capital One breach not a result of gross internal malpractice on the part of Amazon? That allowed an Amazon employee to gain priviledged access to CC data in Capital One's environment.

Re: Everything authenticated by Microsoft is tainted

#32

This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.

Probably a better link would have been the one linked to in the post*:

https://karl-voit.at/cloud/

Which has these among a long list (retaining the reverse order from link above). NB I have just copied and pasted for convenience; neither removed text which refers to links nor added the actual links. You can click through yourself if you want to follow the links.

8023-08: Again Microsoft, again Azure: "unauthorized access to cross-tenant applications and sensitive data (including but not limited to authentication secrets)". If you aren't tech-savvy: this is very bad. (Source)

A reoccuring pattern emerges more and more: Microsoft didn't fix the issue in months and as of 2023-08-03 it is still an open vulnerability in Azure, risking the data of all Azure customers. related:

Microsoft comes under blistering criticism for “grossly irresponsible” security | Ars Technica

BrianKrebs: "The CEO of Tenable just ripped Microsoft a new on…" - Infosec Exchange

2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry, Source, German source)

With the default logs, customers could not even detect intruders as you would need to pay extra to get access to those log files.

Microsoft did not communicate which services were affected and which not. Any Microsoft cloud service was potentially compromised.

Most probably, the usual "any compromised system needs to be thrown away and re-created from scratch will not be applied here. As a consequence, you can't trust any data from Microsoft services any more.

Security experts like Mike Kuketz think that most probably we need to consider all Microsoft systems that are using their cloud authentication including all Windows hosts are compromised.

According to this German source, Microsoft is still refusing to tell what happened and which systems are affected to what extend.

2023-08-18: German comment: Many similar comments like that underline that Microsoft disqualifies as a trustworthy partner.

2023-09-06: first public explanation by MS: Microsoft: Results of Major Technical Investigations for Storm-0558 Key Acquisition Press reactions: heise (German), fefe (German)

Re: Everything authenticated by Microsoft is tainted

#33
post #15
post #2

I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.

This is clearly an overreaction. Cloud will be fine.

He defeats Sephiroth at the end of the game. Maybe he'll defeat Microsoft too.

Re: Everything authenticated by Microsoft is tainted

#34
This is actually wild.. I'm only reading about this properly now thanks to this article but how did this fly under the radar?

The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??

Re: Everything authenticated by Microsoft is tainted

#35

This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.

Found following from the links from the post:

2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry [1], Source[2], German source)

Also the following:

https://infosec.exchange/@briankrebs/110820474957163710

Quite damning if true.

[1]: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... [2]: https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...

Re: Everything authenticated by Microsoft is tainted

#37
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

I half hope so.. for the larger companies who can afford and will maintain their infrastructure security i absolutely agree. At the same time i do see the benefits of a managed system for the smaller not so rich companies or businesses!

There is a best of both worlds in there and I think we've gotten where we are now because of cloud providers marketing themselves suitable for everyone.

Re: Everything authenticated by Microsoft is tainted

#38
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

What I think one of most potential future, low code or no-code will be last resort of hosting stuff somewhere affordably. Given how WordPress introduced 1 century subscription. With the complexity of systems there is no such thing as simple server hosting.

Re: Everything authenticated by Microsoft is tainted

#39

Earlier quoted context omitted.

These problems are specific to Microsoft though; outside of service outages and customer misconfiguration, AWS and GCP don't have a history of such incidents.

Was the Capital One breach not a result of gross internal malpractice on the part of Amazon? That allowed an Amazon employee to gain priviledged access to CC data in Capital One's environment.

No, it wasn't.

Re: Everything authenticated by Microsoft is tainted

#40

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure.

Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.

Post reply on HN