Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

151–160 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#151
post #138

Earlier quoted context omitted.

Arguably much of this is caused by governments getting into the zeroday market / blackhat position removing the incentives to fix stuff. IT security got degraded so far that it starts effecting the economy. There was a reason initial cryptocontrol had exceptions for businesses. Bloated security theater being profitable also doesnt help. One example is smartphones as TAN generators for online banking replacing TAN lis…

> Arguably much of this is caused by governments getting into the zeroday market / blackhat position removing the incentives to fix stuff. I don't see the argument here. CISA posts issues they find, are they intended to be comprehensive?

Unfortunately i dont see yours either. We have governments arguing against stronger encryption due to fears of going dark. Which means against having secure systems.

This is in addition to a lot of government agencies sitting on, and investing into the knowledge about vulnerabilities. Some of the more public ones getting fixed doesnt change the overall vulnerability of the system. There is a clear incentive mismatch. One cant pretend that those vulnerabilities are "safe" due to only spooks knowing of them. If you can find them, so can others. Especially if you are actively exploiting them.

I would argue that this shows both an unwillingness to accept improvements in security as well as actively degrading the current state. And this is before talking about governments actively adding vulnerabilities, which now even possible by law in some jurisdictions.

Re: Everything authenticated by Microsoft is tainted

#152
post #141
post #49

If the lesson the author is ultimately trying to convey is "You can't trust cloud infrastructure providers to protect your data, especially Microsoft." My answer is, "Okay. What can a company do when there is no choice?" The number of enterprise-grade applications that are cloud-only offerings is only increasing. Regardless of whether or not my company actually wants to to own the risk of storing its data in a third…

You can implement security measures on top of what is provided by Microsoft. If you have encryption at rest and you hold the keys locally, for example, even this high-level leak would not expose you. That said, good luck implementing and managing that in a large organization.

Large organizations are exactly what I'm thinking about.

Re: Everything authenticated by Microsoft is tainted

#153
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

> „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. Disagree. You don't need 10 years in IT to understand the meaning of: "M$ allowed customers to use their house-keys to open everyone's office safe, lied about it for 2 years, and still doesn't have a plan for fixing it". McNeally was simply wrong, but despair is easier than fixing things, so a lot of people went with despa…

Nah, no one outside tech cares.

Re: Everything authenticated by Microsoft is tainted

#154

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

This is exactly the same attitude people got to Web3. So many scam tokens and rugpulls, they’re like “what are you gonna do? it’s the wild west.” Worse than that, when Celsius, FTX and other centralized companies imploded due to unsustainable and negligent practices many people were led to conflate that with Web3 blockchain smart contracts ecosystem.

The ironic part is that Bitcoin and Ethereum, altcoins like Filecoin and the entire space of decentralized protocols (EVM, the coming-soon FVM, etc) was designed to eliminate centralized middlemen, including banking cartels, Amazon (which is being sued for monopolistic practices) and the soon-to-come CBDCs etc. In fact, all the responsible protocols (IPFS, UniSwap on Ethereum, Aave marketplace etc etc.) kept humming along regardless of bull and bear markets. It’s just distributed code!

But middlemen were able to convince the public that their centralized companies “ARE web3” and then overpromised yields and other crap.And now the public conflates that with all decentralized protocols that carry value — that’s why we can’t have nice things.

And a bunch of fly-by-night teams cloned contracts delivering no utility at all and some even put backdoors in them. Like PHP “give me the spaghetti codes” crowd and Javascript script kiddies and HTML personal sites with tags script kiddies… but with some money invested.

Cryptographers were right to protest the word “crypto” being associated with this.

Re: Everything authenticated by Microsoft is tainted

#155

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.

Someone complains of getting mugged, you say something about how they brought it on themselves... victim blaming.

But if that someone hunts down the mugger, dances a jig in front of him, starts mocking, "oh come on, I have a thousand bucks cash on me, point the gun at me already"... well, telling them that they're doing it to themselves isn't victim blaming. It's objective truth, the only truth that matters.

They're doing it right now. As we speak. We're having this conversation watching them while they try to throw themselves in front of the gun. It's time to stop worrying about whether or not we're insensitive when we describe what's happening in front of our eyes.

Re: Everything authenticated by Microsoft is tainted

#156

Earlier quoted context omitted.

> That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To Linux? The short answer is...yes. Of course it isn't easy. Of course it would take time. But it's certainly not impossible. It's certainly been done. I'm not defending MS but the idea that they're some sort of siren and companies can't help themeselves...well, please get me a list of those companies so we shor…

It's not the first time that a company got compromised due to microsoft software. This time it was their cloud offering, the previous N times it was AD, Exchange, Outlook, WSUS (for delayed updates), ... And even if they'd move to something else they'd reach for solutions that also get their tentacles into everything because those solutions are convenient during those time windows where they're not exploited.

Wasn’t SolarWinds Microsoft software being compromised too?

When the US govt got hacked they actually did something about it government-wide. Started new security standards. For themselves and their vendors like M$

Re: Everything authenticated by Microsoft is tainted

#157

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.

Is it? Every large company has a well compensated CTO whose job it is to think through these sorts of hypotheticals. But “nobody gets fired for choosing Microsoft”, and so the monopoly continues…

Re: Everything authenticated by Microsoft is tainted

#158
post #102
post #87

Earlier quoted context omitted.

The postmortem about this was here on the front page few weeks ago. No conspiracy needed, just normal big tech malpractice

Do you have a link? There's been a lot of stories about Microsoft, Azure and security...

This one probably: https://news.ycombinator.com/item?id=37408776

Re: Everything authenticated by Microsoft is tainted

#159
post #157

Earlier quoted context omitted.

> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.

Is it? Every large company has a well compensated CTO whose job it is to think through these sorts of hypotheticals. But “nobody gets fired for choosing Microsoft”, and so the monopoly continues…

"A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional and orthodox way along with his fellows, so that no one can really blame him"

Re: Everything authenticated by Microsoft is tainted

#160

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

Blatent case of Microsoft derangement syndrome.

Hard to take your comments seriously with such obvious disdain against the company and ridiculous victim blaming.

Post reply on HN