Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

91–100 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#91
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

Those 3 points are only teaching despair. The more useful thing to teach is who we can blame, and how to reclaim actual privacy and security… even if it means using the dreaded regulation hammer.

None of which will change those three points practically.

For any bit of information, they may not apply, but if you assume they’re true you’ll:

1) not record information that is truly damaging in a damaging way (which is really good practice in general if you’ve got something to lose!)

2) have practical operational practices which do not rely on these being false - which is a really good idea if that actually matters (you have actual enemies somewhere).

3) you’ll focus on safety and building value in areas which are not mere information at rest, which is a good modern practice.

Osama Bin Laden already knew all this, which is why it took so long to find him. A decade or so. I guarantee you the CIA has been learning this with all their leaks. The FBI learned this this after COINTELPRO.

What is not written down can’t show up as a grainy photocopy in the New York Times, or a viral video from Wikileaks, or whatever.

What you’re talking about is a hammer to use to punish someone after a leak. But by then it’s far too late for anything actually valuable.

Necessary and important for ‘day to day’ stuff like bank account balances I guess, as long as you assume that they’ll be violated with little practical recourse if you have anything actually valuable in it.

Streisand effect, etc.

Re: Everything authenticated by Microsoft is tainted

#93
post #73
post #53

Earlier quoted context omitted.

You should be. HN buried Mastodon as a viable social media platform a year ago.

Mastodon is often really slow. The krebs link loaded after like two minutes with an error, then a soft refresh finally loaded it. That happens regularly with Mastodon links for me

there isn't a single Mastodon server. It's a web application (like Wordpress which frequently gets hugged to death when linked here).

Re: Everything authenticated by Microsoft is tainted

#94
post #32

This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.

Probably a better link would have been the one linked to in the post*: https://karl-voit.at/cloud/ Which has these among a long list (retaining the reverse order from link above). NB I have just copied and pasted for convenience; neither removed text which refers to links nor added the actual links. You can click through yourself if you want to follow the links. 8 023-08: Again Microsoft, again Azure: "unauthorized a…

The timeline now includes this significant event:

> 2023-09-29: My Mastodon message about the latest news was posted on Hacker News and its discussion reached number one worldwide.

The circle is complete.

Re: Everything authenticated by Microsoft is tainted

#95

Microsoft should have done a clean room implementation of their cloud and used that to pivot their customers into more manageable technology for both parties. That they've chosen to integrate it with all their legacy stack (which is one of the most complicated ones in existence) is understandable and what 99% of companies would have done but... it's a horrible experience using it. Maybe people with only Microsoft exp…

Having backwards compatibility is their defining feature and selling point, so no way ant of that will happen

Re: Everything authenticated by Microsoft is tainted

#96

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Blame CTOs and system admins who are either married to the stack because it's the most familiar OR they were forced onto it by a CTO because, "no one ever got fired for picking a Gartner upper right quadrant option."

Well, I can't talk for all of them, but at least 2 I worked for have migrated or are finalizing their migration from Azure.

Re: Everything authenticated by Microsoft is tainted

#97
post #91

Earlier quoted context omitted.

Those 3 points are only teaching despair. The more useful thing to teach is who we can blame, and how to reclaim actual privacy and security… even if it means using the dreaded regulation hammer.

None of which will change those three points practically. For any bit of information, they may not apply, but if you assume they’re true you’ll: 1) not record information that is truly damaging in a damaging way (which is really good practice in general if you’ve got something to lose!) 2) have practical operational practices which do not rely on these being false - which is a really good idea if that actually matter…

Regulation can absolutely improve the state of privacy over the status quo. Defeatism like this does nobody any favors.

As far as companies are concerned, personal information should be considered hazardous material, and avoided at all costs.

Re: Everything authenticated by Microsoft is tainted

#98
post #97
post #91

Earlier quoted context omitted.

None of which will change those three points practically. For any bit of information, they may not apply, but if you assume they’re true you’ll: 1) not record information that is truly damaging in a damaging way (which is really good practice in general if you’ve got something to lose!) 2) have practical operational practices which do not rely on these being false - which is a really good idea if that actually matter…

Regulation can absolutely improve the state of privacy over the status quo. Defeatism like this does nobody any favors. As far as companies are concerned, personal information should be considered hazardous material, and avoided at all costs.

For day to day stuff sure.

But thinking it will actually protect you if you have an actual valuable secret is willful naïveté.

That isn’t defeatism, that’s a realistic appraisal of the situation.

If what you described was actually possible, we wouldn’t all be still able to browse all the top secret files leaked from Wikileaks for instance.

Re: Everything authenticated by Microsoft is tainted

#99
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

WTF? I would only expect this view from an organization pushing for total transparency (like advertisement industry or national security) or from somebody brainwashed by them. There is no need for such despair yet.

All of the points are not true I think:

1. People can still have guaranteed privacy (e.g. going into the woods with no devices). As with many laws an incentive to ensure privacy of others could be punishment in case of failure.

2. There is no absolute security, but there is security against certain threat models.

3. Why would data I keep on a device that is not connected to any network ever get public?

Post reply on HN