Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

61–70 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#61

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

They replaced Windows NT with Classic Mac OS?

Re: Everything authenticated by Microsoft is tainted

#62
post #30
post #2

I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.

How is that a good analogy when the cloud computing sector has been growing year on year? There's literally no evidence to support that analogy. It's not even remotely accurate. I'm not saying cloud computing is the solution to every problem, and nor should it be, but calling it a sinking ship is simply absurd. Frankly, I grow so tired of people thinking everything is a boolean choice. The real problem with the cloud…

Security researchers agree with OP and disagree vehemently with your assessment.

Cloud is centralizing. Centralizing, instead of distributing, is bad.

Centralization broadens and expands the attack surface and creates a honey pot for attackers.

This isn’t hyperbole nor is it alarmist. This is reality playing out before us in real time.

Re: Everything authenticated by Microsoft is tainted

#63

This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".

Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone...

Re: Everything authenticated by Microsoft is tainted

#64

When I worked at Microsoft, I found a case internally where it appeared that a service was accepting expired certificates as a form of authentication for admin-level calls. I was fairly new, so I brought it to someone who had been at Microsoft for the better part of a decade. We didn't own the service in question, and he told me that, since it wasn't our service, I should just focus on continuing our work, and that i…

Fascinating insight. This is not dissimilar from other megacorporations that become too bureaucratized over their lifetimes. When growing quickly, bureaucracy helps to organize people and hold a team accountable for their own mistakes. As time moves on, these different teams begin to act as independent entities who no longer successfully communicate or collaborate and the entire business becomes both fragile and ossified, hence that “not my problem” attitude.

Re: Everything authenticated by Microsoft is tainted

#65
post #61

Earlier quoted context omitted.

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

They replaced Windows NT with Classic Mac OS?

Yes.

https://news.slashdot.org/story/99/09/10/1034202/army-dumps-...

Re: Everything authenticated by Microsoft is tainted

#66
post #56

This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".

The worst part of the story to me is —- those were not even the right keys, those were something issued to a client and scoped, but scoping check was broken. It’s unbelievably bad all around

Close, but not quite. The keys were for consumer Microsoft accounts, but accepted for organization accounts as well.

Re: Everything authenticated by Microsoft is tainted

#67

This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".

You can still create "app registration secrets" that last for up to two years. Until recently, you could create essentially unlimited-duration secrets.

Re: Everything authenticated by Microsoft is tainted

#68

Microsoft should have done a clean room implementation of their cloud and used that to pivot their customers into more manageable technology for both parties. That they've chosen to integrate it with all their legacy stack (which is one of the most complicated ones in existence) is understandable and what 99% of companies would have done but... it's a horrible experience using it. Maybe people with only Microsoft exp…

Your viewpoint isn’t without merit. I think it’s just a cost/benefit analysis issue though. Each platform has its own warts. For Microsoft, they built much of their business on backward compatibility, so breaking with that would be tough. As concerns the cloud, MS does partner with Canonical quite a bit, so it isn’t as if they are dogmatic in their tech stack. This issue seems more of a company one and not a technical one.

Re: Everything authenticated by Microsoft is tainted

#69
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

Those 3 points are only teaching despair. The more useful thing to teach is who we can blame, and how to reclaim actual privacy and security… even if it means using the dreaded regulation hammer.
Post reply on HN