Earlier quoted context omitted.
Apparently they might also be backdoored by the NSA: https://news.ycombinator.com/item?id=37571014
Still probably better than having the private key part of a random core dump from a random developer. :s That’s just embarrassing.
Everything authenticated by Microsoft is tainted
121–130 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#122This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.
Found following from the links from the post: 2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry [1], Source[2], German source) Also the following: https://infosec.exchange/@briankrebs/110820474957163710 Quite damning if true. [1]:…
This is not to downplay how bad Microsoft's security lapses were, and how bad their announcements were. The most horrifying part to me, besides the need for "premium" logs to detect a breach which I'd been complaining about before this, was how PR seemed to blame the Exchange Online team for misusing the authentication libraries, but later they updated the libraries and said the token validation issue was "corrected using the updated libraries". That feels like internal blame shifting out in public.
[1] https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...
Re: Everything authenticated by Microsoft is tainted
#123Earlier quoted context omitted.
And just recently Sharepoint was found to accept alg: null JWT tokens (ie. complete authentication bypass)
Do you have a link to a cve or vuln report? I’d like to read more
Re: Everything authenticated by Microsoft is tainted
#124Re: Everything authenticated by Microsoft is tainted
#125And now the search feature doesn’t work anymore.
If it wasn’t for the game support being important for work I’d happily leave and avoid every aspect of their ecosystem. What other reasons do people have for sticking with Microsoft apart from software compatibility?
Re: Everything authenticated by Microsoft is tainted
#126Re: Everything authenticated by Microsoft is tainted
#127Earlier quoted context omitted.
Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone...
Have you checked if you have a Microsoft CA installed to your system?
$ dpkg -l ca-certificates
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name Version Architecture Description
+++-===============-============-============-=================================
ii ca-certificates 20230311 all Common CA certificates
$ trust list | grep Microsoft
label: Microsoft ECC Root Certificate Authority 2017
label: Microsoft RSA Root Certificate Authority 2017
On RHEL 9: $ rpm -q ca-certificates
ca-certificates-2023.2.60_v7.0.306-90.1.el9_2.noarch
$ trust list | grep Microsoft
label: Microsoft ECC Product Root Certificate Authority 2018
label: Microsoft ECC Root Certificate Authority 2017
label: Microsoft ECC TS Root Certificate Authority 2018
label: Microsoft Identity Verification Root Certificate Authority 2020
label: Microsoft RSA Root Certificate Authority 2017
label: Microsoft Root Authority
label: Microsoft Root Certificate Authority
label: Microsoft Root Certificate Authority 2010
label: Microsoft Root Certificate Authority 2011
label: Symantec Enterprise Mobile Root for Microsoft
Interesting that RHEL has many more certificates, when both packages take whatever's bundled into NSS.According to 'rpm -q --changelog ca-certificates' RHEL take their certs from "CKBI 2.60_v7.0.306 from NSS 3.91" and according to /usr/share/doc/ca-certificates/changelog.Debian.gz, Debian take theirs from "Mozilla certificate authority bundle" 2.60.
Re: Everything authenticated by Microsoft is tainted
#128He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
Migrating will be relatively cheap. No wonder they’re hobbling the tools (/tinfoil), they see the threat.
Re: Everything authenticated by Microsoft is tainted
#129This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…
Microsoft is luring in non-tech companies with Active Directory and Office 365 and then catches them with promises about good integration into all services. Once the companies are in the Azure dashboard, why not try those fancy services they offer? It's all smoke and mirrors but it works.
It does work and it is very compelling, at least on the tin. The problem is convincing powers that be that it doesn't do what it says is borderline impossible. The most they've built is equal parts astounding and terrifying.
In a sort of funny twist I feel like this is an area Google could really excel in if they got their shit together. Signing up for Workspace and GCP and everything else makes you feel like they don't want you to use their products.
TFA seems strangely relevant as there seems to be some cultural values reflected in both Microsoft's security posture and reputation, and the ability to bundle and market disparate and downright broken (at least in some cases) products effectively.
Re: Everything authenticated by Microsoft is tainted
#130Earlier quoted context omitted.
> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.
I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.