Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

101–110 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#101
post #22

This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.

[flagged]

if their keys to the kingdom leaking out and them not realising for 2 years aren't cause to say "Microsoft sux" then what would be?

Re: Everything authenticated by Microsoft is tainted

#102
post #87
post #34

This is actually wild.. I'm only reading about this properly now thanks to this article but how did this fly under the radar? The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??

The postmortem about this was here on the front page few weeks ago. No conspiracy needed, just normal big tech malpractice

Do you have a link? There's been a lot of stories about Microsoft, Azure and security...

Re: Everything authenticated by Microsoft is tainted

#103
post #22

Earlier quoted context omitted.

[flagged]

Surprised I don't see M$FT. It's like slashdot in the early 2000s. Edit: -4 downd00ts! Haha must have triggered a few oldies who never let go of their hate.

Don't forget that it was then Microsoft CEO Steve Ballmer who in 2001 compared Linux to cancer. If there is childish vitriol somewhere, it did start neither on HN nor on /.

Re: Everything authenticated by Microsoft is tainted

#104
He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?"

That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To Linux?

Certainly not, Microsoft-y admin only know Microsoft, they usually can't do much else, it's all they know. They certainly won't bite the hand the feeds them. That means the organizations are stuck, which is exactly what Microsoft wanted all those years ago with a monopoly, and got it.

Customers too stuck in their own ways to do anything but be a slave to Microsoft and their constant insecurity deserve what they get sadly.

Re: Everything authenticated by Microsoft is tainted

#105

When I worked at Microsoft, I found a case internally where it appeared that a service was accepting expired certificates as a form of authentication for admin-level calls. I was fairly new, so I brought it to someone who had been at Microsoft for the better part of a decade. We didn't own the service in question, and he told me that, since it wasn't our service, I should just focus on continuing our work, and that i…

Facebook had the same. First it was “nothing at facebook is somebody else’s problem”, but eventually it became “everything at Meta is somebody else’s problem”

Re: Everything authenticated by Microsoft is tainted

#106
post #8

Earlier quoted context omitted.

On-prem is very expensive compared to cloud.

For upfront costs, it can be. But when your running its pretty smooth sailing. Or is this the discussion of having a team of SysOps vs a team of Cloud Engineers?

Most software vendors switched to subscription model, so that’s not obvious anymore. Yeah and as you mention, good luck getting experts for all of your software and hardware components unless you are a big tech company.

Re: Everything authenticated by Microsoft is tainted

#107
post #76
post #51

Earlier quoted context omitted.

This. They don’t even use a HSM if I understood correctly and using one is not part of the mitigation plan. Not OK.

HSM’s are super inconvenient obviously, and as Mr. Robot showed not perfect. So why bother? /s

Apparently they might also be backdoored by the NSA: https://news.ycombinator.com/item?id=37571014

Re: Everything authenticated by Microsoft is tainted

#108

Earlier quoted context omitted.

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.

I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.

85%? I can't imagine even dedicated spam hosting companies in China having that kind of deliverability issues. That is seriously bizarre.

Re: Everything authenticated by Microsoft is tainted

#110
post #98
post #97

Earlier quoted context omitted.

Regulation can absolutely improve the state of privacy over the status quo. Defeatism like this does nobody any favors. As far as companies are concerned, personal information should be considered hazardous material, and avoided at all costs.

For day to day stuff sure. But thinking it will actually protect you if you have an actual valuable secret is willful naïveté. That isn’t defeatism, that’s a realistic appraisal of the situation. If what you described was actually possible, we wouldn’t all be still able to browse all the top secret files leaked from Wikileaks for instance.

While it's true that the best way to keep a secret is to keep it off the internet, regulation could absolutely improve the prospects of keeping secrets by requiring encryption in every context, imposing heavy penalties on companies that fail to properly secure sensitive data (much heavier than what we currently see, up to the corporate death penalty), and enshrining in law the people's right to strong encryption.
Post reply on HN