Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

81–90 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#81
post #22

Earlier quoted context omitted.

[flagged]

Surprised I don't see M$FT. It's like slashdot in the early 2000s. Edit: -4 downd00ts! Haha must have triggered a few oldies who never let go of their hate.

Why do you think people hated Microsoft? Let's see if you know actually know anything about their deep and wide business sociopathy.

One of the big reasons that monopolies are really bad is that they are also inevitably incompetent. The fact those two things go hand in hand makes the inherent corruption of monopoly / cartels doubly damaging.

....almost all markets are cartels at a minimum these days

Re: Everything authenticated by Microsoft is tainted

#82
post #2

I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.

drown in champagne or drown in filthy sea water? for some, this sounds like a nonsensical choice. for others, a defining moment of leadership.

https://nationalpost.com/news/canada/charles-joughin-titanic...

>How a baker survived the Titanic sinking by getting really drunk

Bottoms up!

Re: Everything authenticated by Microsoft is tainted

#83
post #63

This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".

Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone...

Have you checked if you have a Microsoft CA installed to your system?

Re: Everything authenticated by Microsoft is tainted

#84
post #8
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

On-prem is very expensive compared to cloud.

On the contrary on-prem is vastly cheaper except for the smallest of loads.

https://techcrunch.com/2019/06/21/three-years-after-moving-o...

Re: Everything authenticated by Microsoft is tainted

#85
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

> „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact.

Disagree. You don't need 10 years in IT to understand the meaning of: "M$ allowed customers to use their house-keys to open everyone's office safe, lied about it for 2 years, and still doesn't have a plan for fixing it".

McNeally was simply wrong, but despair is easier than fixing things, so a lot of people went with despair. The popularity of cloud and SaaS is the result. But this isn't a foretold destiny; just don't "trust" people you don't actually trust.

Re: Everything authenticated by Microsoft is tainted

#86

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

Also worth of mentioning, the USS Yorktown incident which happened in that period.

https://www.wired.com/1998/07/sunk-by-windows-nt/

Re: Everything authenticated by Microsoft is tainted

#87
post #34

This is actually wild.. I'm only reading about this properly now thanks to this article but how did this fly under the radar? The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??

The postmortem about this was here on the front page few weeks ago. No conspiracy needed, just normal big tech malpractice

Re: Everything authenticated by Microsoft is tainted

#88
post #63

Earlier quoted context omitted.

Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone...

Have you checked if you have a Microsoft CA installed to your system?

I simply assume Microsoft have already compromised my systems already. :)

Re: Everything authenticated by Microsoft is tainted

#89
post #49

If the lesson the author is ultimately trying to convey is "You can't trust cloud infrastructure providers to protect your data, especially Microsoft." My answer is, "Okay. What can a company do when there is no choice?" The number of enterprise-grade applications that are cloud-only offerings is only increasing. Regardless of whether or not my company actually wants to to own the risk of storing its data in a third…

> Okay. What can a company do when there is no choice?

The company can recognize that "there is no choice" is not a valid option. There are many choices if the company actually cared to invest into choices. That requires learning and actually vetting your vendors though. That's hard work. Good luck getting people to do hard work.

Re: Everything authenticated by Microsoft is tainted

#90
post #61

Earlier quoted context omitted.

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

They replaced Windows NT with Classic Mac OS?

Isn't that like moving from Windows NT to windows 95 for hosting your web server?
Post reply on HN