Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

131–140 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#132
post #108

Earlier quoted context omitted.

I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.

85%? I can't imagine even dedicated spam hosting companies in China having that kind of deliverability issues. That is seriously bizarre.

Sometimes you get a bad roll of the dice when you choose a lesser known email provider and you start with worse than average reputation. Can never go wrong with Gsuite, O365, etc.

Re: Everything authenticated by Microsoft is tainted

#133
post #55
post #8

Earlier quoted context omitted.

On-prem is very expensive compared to cloud.

For on-prem or cloud, you need some engineers (either SRE or SysEng) to handle your hosting infrastructure. So, not much difference in cost there. Then, there is all of that compute. Currently, an AMD EPYC 7551 system can be put together for about $2.2K USD. That’s 64 threads, 256GB of RAM, redundant 2TB NVMe in RAID1, plus chassis, power and such. The equivalent amount of compute being available 24/7 is going to be…

I also held this view for a long time but what you are talking about is basically Amazon EC2. There are, what, 200-250 AWS services, however, and that's where things begin to become more interesting. Can you replace any of them with in house solutions? Certainly. But the costs of doing so might not be favorable.

You could operate an on premise bakery but most companies just order donuts.

Re: Everything authenticated by Microsoft is tainted

#134
post #113

Earlier quoted context omitted.

On the contrary on-prem is vastly cheaper except for the smallest of loads. https://techcrunch.com/2019/06/21/three-years-after-moving-o...

Not everyone is DropBox. IIRC GitLab also wanted to switch but after long planning they found out it would be worse.

True, but even a single server is a lot cheaper on Linode, and cheaper still on OVH, even the best quality colo and dedicated server providers, than on any cloud. On-prem is going to be cheaper than that. And internet connectivity ... is more expensive than it was in 1990, and generally pretty much free in colo or dedi services.

Re: Everything authenticated by Microsoft is tainted

#135

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

It's not about securing user's data, it's about not being blamed for it.

It doesn't matter that China/Whichever state actor is snooping on all your user's data. Either no-one finds out and you're good. Or the blast radius is _so_ wide, that all blame falls on Microsoft

Re: Everything authenticated by Microsoft is tainted

#136

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To Linux? The short answer is...yes. Of course it isn't easy. Of course it would take time. But it's certainly not impossible. It's certainly been done. I'm not defending MS but the idea that they're some sort of siren and companies can't help themeselves...well, please get me a list of those companies so we shor…

Unfortunately even much of the open source world generates and distributes their official builds from Microsoft infrastructure. And even the distros themselves will get the source to do their own builds from the copies hosted on Microsoft infrastructure. So it's not a cure all if you suspect you can't trust GitHub.

Re: Everything authenticated by Microsoft is tainted

#138
post #2

I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.

Arguably much of this is caused by governments getting into the zeroday market / blackhat position removing the incentives to fix stuff. IT security got degraded so far that it starts effecting the economy. There was a reason initial cryptocontrol had exceptions for businesses. Bloated security theater being profitable also doesnt help. One example is smartphones as TAN generators for online banking replacing TAN lis…

> Arguably much of this is caused by governments getting into the zeroday market / blackhat position removing the incentives to fix stuff.

I don't see the argument here. CISA posts issues they find, are they intended to be comprehensive?

Re: Everything authenticated by Microsoft is tainted

#139
post #30

Earlier quoted context omitted.

How is that a good analogy when the cloud computing sector has been growing year on year? There's literally no evidence to support that analogy. It's not even remotely accurate. I'm not saying cloud computing is the solution to every problem, and nor should it be, but calling it a sinking ship is simply absurd. Frankly, I grow so tired of people thinking everything is a boolean choice. The real problem with the cloud…

Security researchers agree with OP and disagree vehemently with your assessment. Cloud is centralizing. Centralizing, instead of distributing, is bad. Centralization broadens and expands the attack surface and creates a honey pot for attackers. This isn’t hyperbole nor is it alarmist. This is reality playing out before us in real time.

"Security researchers agree" is a very broad statement. I don't believe there is a consensus at all.

Fragmentation creates different problems than centralization, but it isn't a magical bullet either. Depending on your resources, you are far, far better off trusting even Microsoft than trying to come up with your own security implementation.

Re: Everything authenticated by Microsoft is tainted

#140
post #49

If the lesson the author is ultimately trying to convey is "You can't trust cloud infrastructure providers to protect your data, especially Microsoft." My answer is, "Okay. What can a company do when there is no choice?" The number of enterprise-grade applications that are cloud-only offerings is only increasing. Regardless of whether or not my company actually wants to to own the risk of storing its data in a third…

> Okay. What can a company do when there is no choice? The company can recognize that "there is no choice" is not a valid option. There are many choices if the company actually cared to invest into choices. That requires learning and actually vetting your vendors though. That's hard work. Good luck getting people to do hard work.

I've been through multiple vendor vetting processes at my company, and there has always been a line drawn at whether or not the company's data is stored with the vendor in the cloud. My company is very cloud averse due to the nature of the business, and the kind of data they store. The vendor products that make that cut are usually not the best, and if they have a cloud offering, it's almost always superior to their on-premise offering. Every time I go through this process, it shifts even further in the direction of more + better cloud offerings, and fewer on-premise offerings.
Post reply on HN