Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

121–130 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#121
post #111

Earlier quoted context omitted.

Apparently they might also be backdoored by the NSA: https://news.ycombinator.com/item?id=37571014

Still probably better than having the private key part of a random core dump from a random developer. :s That’s just embarrassing.

No doubt. My expectations to MS engineering are really low so I'm unfortunately not shocked.

Re: Everything authenticated by Microsoft is tainted

#122

This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.

Found following from the links from the post: 2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry [1], Source[2], German source) Also the following: https://infosec.exchange/@briankrebs/110820474957163710 Quite damning if true. [1]:…

The issue was specific to services that used Microsoft's .NET libraries for Azure AD authentication without doing additional checks for auth token validity [1], which was not "all of Microsoft". There's no public list of what components are used where AFAIK, we just know that MS says forged auth tokens were successfully used on Exchange Online email. It is sensationalizing to say the entire Azure cloud was hacked.

This is not to downplay how bad Microsoft's security lapses were, and how bad their announcements were. The most horrifying part to me, besides the need for "premium" logs to detect a breach which I'd been complaining about before this, was how PR seemed to blame the Exchange Online team for misusing the authentication libraries, but later they updated the libraries and said the token validation issue was "corrected using the updated libraries". That feels like internal blame shifting out in public.

[1] https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...

Re: Everything authenticated by Microsoft is tainted

#123

Earlier quoted context omitted.

And just recently Sharepoint was found to accept alg: null JWT tokens (ie. complete authentication bypass)

Do you have a link to a cve or vuln report? I’d like to read more

https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-cha...

Re: Everything authenticated by Microsoft is tainted

#125
Unrelated, but this afternoon Microsoft decided I couldn’t use my laptop for 10 minutes for mandatory updates, which was a serious problem.

And now the search feature doesn’t work anymore.

If it wasn’t for the game support being important for work I’d happily leave and avoid every aspect of their ecosystem. What other reasons do people have for sticking with Microsoft apart from software compatibility?

Re: Everything authenticated by Microsoft is tainted

#126
post #8
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

On-prem is very expensive compared to cloud.

It really depends and it's not that clear when a single vcpu costs $30 and then you have the hidden egress fees.

Re: Everything authenticated by Microsoft is tainted

#127
post #63

Earlier quoted context omitted.

Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone...

Have you checked if you have a Microsoft CA installed to your system?

More seriously, on my Debian stable system:

    $ dpkg -l ca-certificates
    Desired=Unknown/Install/Remove/Purge/Hold
    | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
    |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
    ||/ Name            Version      Architecture Description
    +++-===============-============-============-=================================
    ii  ca-certificates 20230311     all          Common CA certificates
    
    $ trust list | grep Microsoft
        label: Microsoft ECC Root Certificate Authority 2017
        label: Microsoft RSA Root Certificate Authority 2017
On RHEL 9:

    $ rpm -q ca-certificates
    ca-certificates-2023.2.60_v7.0.306-90.1.el9_2.noarch
    
    $ trust list | grep Microsoft
        label: Microsoft ECC Product Root Certificate Authority 2018
        label: Microsoft ECC Root Certificate Authority 2017
        label: Microsoft ECC TS Root Certificate Authority 2018
        label: Microsoft Identity Verification Root Certificate Authority 2020
        label: Microsoft RSA Root Certificate Authority 2017
        label: Microsoft Root Authority
        label: Microsoft Root Certificate Authority
        label: Microsoft Root Certificate Authority 2010
        label: Microsoft Root Certificate Authority 2011
        label: Symantec Enterprise Mobile Root for Microsoft
Interesting that RHEL has many more certificates, when both packages take whatever's bundled into NSS.

According to 'rpm -q --changelog ca-certificates' RHEL take their certs from "CKBI 2.60_v7.0.306 from NSS 3.91" and according to /usr/share/doc/ca-certificates/changelog.Debian.gz, Debian take theirs from "Mozilla certificate authority bundle" 2.60.

Re: Everything authenticated by Microsoft is tainted

#128

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

Another reason I am in love with LLMs. You don’t need to know the software like the back of your hand - a new environment is like a new programming language, as long as you’re able to ask the right questions new environments will be far more accessible. Experienced admins should know the requirements, and not be limited to the tools.

Migrating will be relatively cheap. No wonder they’re hobbling the tools (/tinfoil), they see the threat.

Re: Everything authenticated by Microsoft is tainted

#129
post #42

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

Microsoft is luring in non-tech companies with Active Directory and Office 365 and then catches them with promises about good integration into all services. Once the companies are in the Azure dashboard, why not try those fancy services they offer? It's all smoke and mirrors but it works.

I'm honestly surprised they haven't been trying to bundle GitHub more (or vice versa).

It does work and it is very compelling, at least on the tin. The problem is convincing powers that be that it doesn't do what it says is borderline impossible. The most they've built is equal parts astounding and terrifying.

In a sort of funny twist I feel like this is an area Google could really excel in if they got their shit together. Signing up for Workspace and GCP and everything else makes you feel like they don't want you to use their products.

TFA seems strangely relevant as there seems to be some cultural values reflected in both Microsoft's security posture and reputation, and the ability to bundle and market disparate and downright broken (at least in some cases) products effectively.

Re: Everything authenticated by Microsoft is tainted

#130

Earlier quoted context omitted.

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.

I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.

Fastmail is very good and has been running for 24 years, with good deliverability. Migadu I hear is good. There's quite a few email providers that aren't Microsoft or Google that have their shit together.
Post reply on HN