This is actually wild.. I'm only reading about this properly now thanks to this article but how did this fly under the radar? The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??
Everything authenticated by Microsoft is tainted
181–190 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#182It’s irresponsible to make broad claims like this, that everything in Microsoft’s cloud has to be replaced to mitigate the breach. That doesn’t pass the sniff test.
I get that Microsoft has a vested interest in mitigating the PR aspect of it, but I doubt they’ve just done nothing to correct the issue.
Re: Everything authenticated by Microsoft is tainted
#183He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business, I think you are completely fucking yourself over with this sort of attitude.
How much business convenience are you willing to squander over these principles? And, are you truly upholding your principles on a consistent basis or is this a reductive "at least it's not Microsoft" line of thinking? Microsoft is a big place. Some parts good some parts bad. You may be leaving a lot of upside on the table by never considering them as an option.
We are a "Microsoft shop", but we still use other vendors when it makes sense. I don't trip over myself trying to get 100% off AWS over some ridiculous tribalism. Their domain registration and S3 object stores work really well for us so we continue to use them, even when it creates a bit of integration overhead (SCIM identity sync w/ AAD, etc).
Re: Everything authenticated by Microsoft is tainted
#184Earlier quoted context omitted.
> own ways to do anything but be a slave to Microsoft I guarantee 99/100 humans on this forum either currently host with AWS/GCP/Azure or have worked at a shop that does. And I bet an outsized portion of those AWS/GCP shops also host on Azure for Azure AD. There is no one that is ready for a de-Microsofted world. Even Linux distros have been increasing their support for integrating into the MS ecosystem and forsaking…
My entire adult life and career has been MS free. It’s not that rare.
Re: Everything authenticated by Microsoft is tainted
#185He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.
Several million dollars gone from one virus. But they forged ahead, entreating further with Microsoft.
Victims absolutely shouldn’t be blamed, however, you don’t buy a Pinto if you are concerned about being trapped in a fiery wreck, you don’t go to Skid Row after dark if you’re concerned about violent crime, and you don’t buy Microsoft if you’re concerned about security. These are all things we’ve known for decades.
Re: Everything authenticated by Microsoft is tainted
#186Maybe this explains why Defender (Microsoft's AV) became so overly aggressive during previous few months. They had a problem and acted in a semi-panic mode forcing Defender to mark nearly everything as a "virus" when its Cloud Protection mode was turned on.
Uh, are you certain of that? When security alarms start going off, “darn, they broke the detector!” isn’t the only explanation.
Re: Everything authenticated by Microsoft is tainted
#187The writeup by Microsoft is far more illustrative than the frankly confusing post and blog from the main article: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... Also, unlike what (I think) is being claimed here, Microsoft did fix the issue after learning about it: https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...
And those people had already hacked an engineer's account. Because the chances of stumbling upon this key when only hacking one engineering account are very low, it's reasonable to assume many MS engineering accounts had already been hacked.
Basically, your MS account is not safe.
Re: Everything authenticated by Microsoft is tainted
#188He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.
Re: Everything authenticated by Microsoft is tainted
#189Re: Everything authenticated by Microsoft is tainted
#190Earlier quoted context omitted.
Security researchers agree with OP and disagree vehemently with your assessment. Cloud is centralizing. Centralizing, instead of distributing, is bad. Centralization broadens and expands the attack surface and creates a honey pot for attackers. This isn’t hyperbole nor is it alarmist. This is reality playing out before us in real time.
"Security researchers agree" is a very broad statement. I don't believe there is a consensus at all. Fragmentation creates different problems than centralization, but it isn't a magical bullet either. Depending on your resources, you are far, far better off trusting even Microsoft than trying to come up with your own security implementation.
There is no consensus.
But, that's with every industry, every field, every platform.
Some warn, others ignore.
Wanna bet who's right?