People fled from mainframes, now they are flocking to cloud...
Everything authenticated by Microsoft is tainted
71–80 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#72This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…
> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.
Re: Everything authenticated by Microsoft is tainted
#73Earlier quoted context omitted.
[flagged]
You should be. HN buried Mastodon as a viable social media platform a year ago.
Re: Everything authenticated by Microsoft is tainted
#74Earlier quoted context omitted.
On-prem is very expensive compared to cloud.
And not guaranteed to solve problems like this. Because at the end of the day, the maintenance of a cloud infrastructure is irreducible complexity so you replace having a breach because a centralized controlling authority made a mistake with having a breach because your own hired staff made a mistake and you got infiltrated by either a lucky drive by or a persistent attacker against your organization.
Re: Everything authenticated by Microsoft is tainted
#75Re: Everything authenticated by Microsoft is tainted
#76This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".
This. They don’t even use a HSM if I understood correctly and using one is not part of the mitigation plan. Not OK.
Re: Everything authenticated by Microsoft is tainted
#77Earlier quoted context omitted.
The worst part of the story to me is —- those were not even the right keys, those were something issued to a client and scoped, but scoping check was broken. It’s unbelievably bad all around
Close, but not quite. The keys were for consumer Microsoft accounts, but accepted for organization accounts as well.
Re: Everything authenticated by Microsoft is tainted
#78Earlier quoted context omitted.
> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.
I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.
Re: Everything authenticated by Microsoft is tainted
#79We all ought to be using Qubes OS! We, as the Hacker News community, ought to be more concerned about making it easier to use reasonably secure systems. How do I buy a computer that runs Qubes? https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/
As someone who runs Qubes on one of my laptops (the travel one) I can assure you that your long battery life days are over.
Re: Everything authenticated by Microsoft is tainted
#80I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.
Bloated security theater being profitable also doesnt help. One example is smartphones as TAN generators for online banking replacing TAN lists. While you can now charge customers per SMS, the second factor got quite a bit more easy to attack.