Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

71–80 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#72

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.

I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.

Re: Everything authenticated by Microsoft is tainted

#73
post #53
post #22

Earlier quoted context omitted.

[flagged]

You should be. HN buried Mastodon as a viable social media platform a year ago.

Mastodon is often really slow. The krebs link loaded after like two minutes with an error, then a soft refresh finally loaded it. That happens regularly with Mastodon links for me

Re: Everything authenticated by Microsoft is tainted

#74
post #8

Earlier quoted context omitted.

On-prem is very expensive compared to cloud.

And not guaranteed to solve problems like this. Because at the end of the day, the maintenance of a cloud infrastructure is irreducible complexity so you replace having a breach because a centralized controlling authority made a mistake with having a breach because your own hired staff made a mistake and you got infiltrated by either a lucky drive by or a persistent attacker against your organization.

It's not exactly a replacement. Your own hired staff can still mess things up in the cloud and leave a door open. The cloud doesn't magically apply all the best practices on its own. See all the people caught with open access to S3.

Re: Everything authenticated by Microsoft is tainted

#76
post #51

This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".

This. They don’t even use a HSM if I understood correctly and using one is not part of the mitigation plan. Not OK.

HSM’s are super inconvenient obviously, and as Mr. Robot showed not perfect. So why bother? /s

Re: Everything authenticated by Microsoft is tainted

#77
post #56

Earlier quoted context omitted.

The worst part of the story to me is —- those were not even the right keys, those were something issued to a client and scoped, but scoping check was broken. It’s unbelievably bad all around

Close, but not quite. The keys were for consumer Microsoft accounts, but accepted for organization accounts as well.

[deleted]

Re: Everything authenticated by Microsoft is tainted

#78

Earlier quoted context omitted.

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.

I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.

GSuite tends to work ok for email. There might be others.

Re: Everything authenticated by Microsoft is tainted

#79
post #21

We all ought to be using Qubes OS! We, as the Hacker News community, ought to be more concerned about making it easier to use reasonably secure systems. How do I buy a computer that runs Qubes? https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/

As someone who runs Qubes on one of my laptops (the travel one) I can assure you that your long battery life days are over.

Yes, the shortened battery life is quite noticeable.

Re: Everything authenticated by Microsoft is tainted

#80
post #2

I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.

Arguably much of this is caused by governments getting into the zeroday market / blackhat position removing the incentives to fix stuff. IT security got degraded so far that it starts effecting the economy. There was a reason initial cryptocontrol had exceptions for businesses.

Bloated security theater being profitable also doesnt help. One example is smartphones as TAN generators for online banking replacing TAN lists. While you can now charge customers per SMS, the second factor got quite a bit more easy to attack.

Post reply on HN