Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

181–190 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#181
post #34

This is actually wild.. I'm only reading about this properly now thanks to this article but how did this fly under the radar? The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??

I don't understand either how it got to keep such a low profile. Not long before this came out, there was an "incident" where everyone could alter specific Bing search results (and probably other services too), and as a consequence gain access to all data the browser shares with bing, and that includes the access keys to all the MS accounts of the user that happens to use Bing for that specific search. Impact unknown, because they didn't divulge that. Why? Your guess is as good as mine.

Re: Everything authenticated by Microsoft is tainted

#182
I think this is a pretty big leap to conclusions. Some guy on Mastdon doesn’t know what Microsoft’s security team knows about the breach.

It’s irresponsible to make broad claims like this, that everything in Microsoft’s cloud has to be replaced to mitigate the breach. That doesn’t pass the sniff test.

I get that Microsoft has a vested interest in mitigating the PR aspect of it, but I doubt they’ve just done nothing to correct the issue.

Re: Everything authenticated by Microsoft is tainted

#183

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> be a slave to Microsoft

Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business, I think you are completely fucking yourself over with this sort of attitude.

How much business convenience are you willing to squander over these principles? And, are you truly upholding your principles on a consistent basis or is this a reductive "at least it's not Microsoft" line of thinking? Microsoft is a big place. Some parts good some parts bad. You may be leaving a lot of upside on the table by never considering them as an option.

We are a "Microsoft shop", but we still use other vendors when it makes sense. I don't trip over myself trying to get 100% off AWS over some ridiculous tribalism. Their domain registration and S3 object stores work really well for us so we continue to use them, even when it creates a bit of integration overhead (SCIM identity sync w/ AAD, etc).

Re: Everything authenticated by Microsoft is tainted

#184
post #178
post #167

Earlier quoted context omitted.

> own ways to do anything but be a slave to Microsoft I guarantee 99/100 humans on this forum either currently host with AWS/GCP/Azure or have worked at a shop that does. And I bet an outsized portion of those AWS/GCP shops also host on Azure for Azure AD. There is no one that is ready for a de-Microsofted world. Even Linux distros have been increasing their support for integrating into the MS ecosystem and forsaking…

My entire adult life and career has been MS free. It’s not that rare.

It's not that rare for developers and sys admins. It's pretty rare outside of that, particularly if you're on a corporate-managed system. Wander down to HR or finance or legal and see how many *nix systems you see.

Re: Everything authenticated by Microsoft is tainted

#185

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.

I joined Accenture in 2003 after over three years of onslaught of Windows e-mail Virus after Virus. They were actively transitioning away from Lotus Notes to Exchange/Outlook and migrated everyone a few months after I joined. Within weeks they were hit with Sobig, causing 100,000 employees to spend hours each dealing with it.

Several million dollars gone from one virus. But they forged ahead, entreating further with Microsoft.

Victims absolutely shouldn’t be blamed, however, you don’t buy a Pinto if you are concerned about being trapped in a fiery wreck, you don’t go to Skid Row after dark if you’re concerned about violent crime, and you don’t buy Microsoft if you’re concerned about security. These are all things we’ve known for decades.

Re: Everything authenticated by Microsoft is tainted

#186

Maybe this explains why Defender (Microsoft's AV) became so overly aggressive during previous few months. They had a problem and acted in a semi-panic mode forcing Defender to mark nearly everything as a "virus" when its Cloud Protection mode was turned on.

Uh, are you certain of that? When security alarms start going off, “darn, they broke the detector!” isn’t the only explanation.

I'm certain as I'm in the field. Another plausible explanation is a wider rollout of a ML-based tech which is not very discrete in its detections.

Re: Everything authenticated by Microsoft is tainted

#187
post #148

The writeup by Microsoft is far more illustrative than the frankly confusing post and blog from the main article: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... Also, unlike what (I think) is being claimed here, Microsoft did fix the issue after learning about it: https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...

A lot later. The damage was done. Whoever had those keys could have had access to all MS accounts and services.

And those people had already hacked an engineer's account. Because the chances of stumbling upon this key when only hacking one engineering account are very low, it's reasonable to assume many MS engineering accounts had already been hacked.

Basically, your MS account is not safe.

Re: Everything authenticated by Microsoft is tainted

#188

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.

Microsoft is slowly chipping away on-prem Exchange and AD, forcing people into their Azure/O365 offerings little by little. They advertise their Cloud offerings as being more secure.

Re: Everything authenticated by Microsoft is tainted

#190
post #139

Earlier quoted context omitted.

Security researchers agree with OP and disagree vehemently with your assessment. Cloud is centralizing. Centralizing, instead of distributing, is bad. Centralization broadens and expands the attack surface and creates a honey pot for attackers. This isn’t hyperbole nor is it alarmist. This is reality playing out before us in real time.

"Security researchers agree" is a very broad statement. I don't believe there is a consensus at all. Fragmentation creates different problems than centralization, but it isn't a magical bullet either. Depending on your resources, you are far, far better off trusting even Microsoft than trying to come up with your own security implementation.

You are correct. There are those who warn, and those who ignore.

There is no consensus.

But, that's with every industry, every field, every platform.

Some warn, others ignore.

Wanna bet who's right?

Post reply on HN