This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.
[flagged]
Everything authenticated by Microsoft is tainted
101–110 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#102This is actually wild.. I'm only reading about this properly now thanks to this article but how did this fly under the radar? The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??
The postmortem about this was here on the front page few weeks ago. No conspiracy needed, just normal big tech malpractice
Re: Everything authenticated by Microsoft is tainted
#103Earlier quoted context omitted.
[flagged]
Surprised I don't see M$FT. It's like slashdot in the early 2000s. Edit: -4 downd00ts! Haha must have triggered a few oldies who never let go of their hate.
Re: Everything authenticated by Microsoft is tainted
#104That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To Linux?
Certainly not, Microsoft-y admin only know Microsoft, they usually can't do much else, it's all they know. They certainly won't bite the hand the feeds them. That means the organizations are stuck, which is exactly what Microsoft wanted all those years ago with a monopoly, and got it.
Customers too stuck in their own ways to do anything but be a slave to Microsoft and their constant insecurity deserve what they get sadly.
Re: Everything authenticated by Microsoft is tainted
#105When I worked at Microsoft, I found a case internally where it appeared that a service was accepting expired certificates as a form of authentication for admin-level calls. I was fairly new, so I brought it to someone who had been at Microsoft for the better part of a decade. We didn't own the service in question, and he told me that, since it wasn't our service, I should just focus on continuing our work, and that i…
Re: Everything authenticated by Microsoft is tainted
#106Earlier quoted context omitted.
On-prem is very expensive compared to cloud.
For upfront costs, it can be. But when your running its pretty smooth sailing. Or is this the discussion of having a team of SysOps vs a team of Cloud Engineers?
Re: Everything authenticated by Microsoft is tainted
#107Earlier quoted context omitted.
This. They don’t even use a HSM if I understood correctly and using one is not part of the mitigation plan. Not OK.
HSM’s are super inconvenient obviously, and as Mr. Robot showed not perfect. So why bother? /s
Re: Everything authenticated by Microsoft is tainted
#108Earlier quoted context omitted.
> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.
I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.
Re: Everything authenticated by Microsoft is tainted
#109Re: Everything authenticated by Microsoft is tainted
#110Earlier quoted context omitted.
Regulation can absolutely improve the state of privacy over the status quo. Defeatism like this does nobody any favors. As far as companies are concerned, personal information should be considered hazardous material, and avoided at all costs.
For day to day stuff sure. But thinking it will actually protect you if you have an actual valuable secret is willful naïveté. That isn’t defeatism, that’s a realistic appraisal of the situation. If what you described was actually possible, we wouldn’t all be still able to browse all the top secret files leaked from Wikileaks for instance.