Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

41–50 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#41
post #8

Earlier quoted context omitted.

On-prem is very expensive compared to cloud.

Careful with blanket statements like these. Run a system with high sustained compute and data egress; even when accounting for engineer time (and people often neglect to account for time spent administering cloud infra), the cloud markup is huge. While it works for some companies, cloud is not universally cheaper.

This is the sentiment i share, which i think it's important to hammer down the point that it's the fault the cloud providers marketing themselves to be suitable for everyone. Because if they don't get as much money as possible then they don't see a purpose.

Re: Everything authenticated by Microsoft is tainted

#42

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

Microsoft is luring in non-tech companies with Active Directory and Office 365 and then catches them with promises about good integration into all services. Once the companies are in the Azure dashboard, why not try those fancy services they offer?

It's all smoke and mirrors but it works.

Re: Everything authenticated by Microsoft is tainted

#43

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure.

Blame CTOs and system admins who are either married to the stack because it's the most familiar OR they were forced onto it by a CTO because, "no one ever got fired for picking a Gartner upper right quadrant option."

Re: Everything authenticated by Microsoft is tainted

#44
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

But the cloud is much safer. It's not like someone is going to hack the whole Microsoft cloud. Oh, hang on ...

Funny as this was one of the winning arguments when we went to the cloud, couldn’t possible be safer to host your own, right ? RiGhT?

Re: Everything authenticated by Microsoft is tainted

#45
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

It's quite ironic that the recent centralization and cloudarisation of the Internet (& electronic devices).

When everything was local and private, the attacker could only access a specific device or network, even if the security was often very weak. Now a single attack on a centralized entity has such a big payoff, that it makes if viable to allocate much bigger resources by attackers.

Re: Everything authenticated by Microsoft is tainted

#46
post #22

This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.

[flagged]

Surprised I don't see M$FT. It's like slashdot in the early 2000s.

Edit: -4 downd00ts! Haha must have triggered a few oldies who never let go of their hate.

Re: Everything authenticated by Microsoft is tainted

#47
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

I think a new approach to privacy is likely around the corner. Why have one conversation with somebody when you can have as many as you want all at once?

There were already addons like that that created garbage traffic a while ago. Just wasnt practical without language networks.

Re: Everything authenticated by Microsoft is tainted

#48

This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.

Besides, in some services not even MS has control over the data, see KV or MHSM.

In the very same link he posts: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... "Post-compromise activity

Our telemetry and investigations indicate that post-compromise activity was limited to email access and exfiltration for targeted users."

So it's not "all Microsoft".

It's the usual exaggerated headline, but this time it draws attention on a person's post on Mastodon.

This platform is really no different from Twitter.

Re: Everything authenticated by Microsoft is tainted

#49
If the lesson the author is ultimately trying to convey is "You can't trust cloud infrastructure providers to protect your data, especially Microsoft." My answer is, "Okay. What can a company do when there is no choice?" The number of enterprise-grade applications that are cloud-only offerings is only increasing. Regardless of whether or not my company actually wants to to own the risk of storing its data in a third party, the day is coming where they have to choose to accept the risk that comes with storing data in the cloud, or re-inventing someone else's wheel at great development and operational cost.

Re: Everything authenticated by Microsoft is tainted

#50

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security.

I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux.

Microsoft may be popular, but they have big holes in their security. Always has been.

Post reply on HN