Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

221–230 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#221
post #194

From Microsoft’s blog post on the incident (Mitigation and Hardening section): - On June 26, OWA stopped accepting tokens issued from GetAccessTokensForResource for renewal, which mitigated the token renewal being abused. - On June 27, Microsoft blocked the usage of tokens signed with the acquired MSA key in OWA preventing further threat actor enterprise mail activity. - On June 29, Microsoft completed replacement of…

One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.

Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.

Re: Everything authenticated by Microsoft is tainted

#222
post #216

Earlier quoted context omitted.

Evidently it was not the correct medicine.

More like one batch was deficient and was recalled as soon as the issue was discovered.

MS discovered this years ago. And they have refused any recall.

This is also not the first time they cover up some serious problem and refuse to fix it. In fact, that's a daily activity for them. This one is just a larger problem than usual because they are broken too, not only their clients (even though, that makes it only slightly larger).

Re: Everything authenticated by Microsoft is tainted

#223
post #215

Earlier quoted context omitted.

This would sound like ChatGPT if I didn't know better... All of your arguments are "made up" arguments, they contradict themselves or each other or assume some very unlikely situations, especially on behalf of what the post you replied to wanted to say, where it's clear it's not what it wanted to say. Let's dive in! > So are you suggesting that the most practicable alternative is to be a slave Clearly, the post you r…

You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Lin…

Yes. In every possible way, yes.

Re: Everything authenticated by Microsoft is tainted

#224
post #159

Earlier quoted context omitted.

"A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional and orthodox way along with his fellows, so that no one can really blame him"

The worst part is that very poor diversification / groupthink is exactly what creates financial bubbles and financial crises. We seem to be reaching that uncomfortable too-big-to-fail scale in computing / cyber security.

> We seem to be reaching

We clearly reached it at the 90's. We have been waiting for the other shoe to drop since then.

Re: Everything authenticated by Microsoft is tainted

#225
post #182

I think this is a pretty big leap to conclusions. Some guy on Mastdon doesn’t know what Microsoft’s security team knows about the breach. It’s irresponsible to make broad claims like this, that everything in Microsoft’s cloud has to be replaced to mitigate the breach. That doesn’t pass the sniff test. I get that Microsoft has a vested interest in mitigating the PR aspect of it, but I doubt they’ve just done nothing t…

Everyone on HN should know that this is not just one guy on Mastodon.

https://arstechnica.com/security/2023/08/microsoft-cloud-sec...

Re: Everything authenticated by Microsoft is tainted

#226

Earlier quoted context omitted.

> be a slave to Microsoft Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business , I think you are completely fucking yourself over with this sort of attitude. How much business convenience are you willing to squander over thes…

This would sound like ChatGPT if I didn't know better... All of your arguments are "made up" arguments, they contradict themselves or each other or assume some very unlikely situations, especially on behalf of what the post you replied to wanted to say, where it's clear it's not what it wanted to say. Let's dive in! > So are you suggesting that the most practicable alternative is to be a slave Clearly, the post you r…

You run your own mail?

Re: Everything authenticated by Microsoft is tainted

#227

Earlier quoted context omitted.

SolarWinds is the name of company that was compromised, and as far as I can tell was never owned by MS.

Right, but the question is whether SolarWinds was owned due to an MS vuln. A quick scan of a summary of the SolarWinds story suggests that's not the case, but it's possible that the article I read glossed over too much.

> the question is whether SolarWinds was owned due to an MS vuln

No, but the other way around happened. It may be even this hack on the article, it's not very clear.

The Solar Winds thing is probably much larger than what we have been allowed to know. I do expect more of it to come out, for decades because the victims just have no way to know they have a problem.

Re: Everything authenticated by Microsoft is tainted

#228
post #194

From Microsoft’s blog post on the incident (Mitigation and Hardening section): - On June 26, OWA stopped accepting tokens issued from GetAccessTokensForResource for renewal, which mitigated the token renewal being abused. - On June 27, Microsoft blocked the usage of tokens signed with the acquired MSA key in OWA preventing further threat actor enterprise mail activity. - On June 29, Microsoft completed replacement of…

These points seem to dispute the "the keys are compromised and still in use" and the "everything is tainted" title.

Re: Everything authenticated by Microsoft is tainted

#229
post #215

Earlier quoted context omitted.

This would sound like ChatGPT if I didn't know better... All of your arguments are "made up" arguments, they contradict themselves or each other or assume some very unlikely situations, especially on behalf of what the post you replied to wanted to say, where it's clear it's not what it wanted to say. Let's dive in! > So are you suggesting that the most practicable alternative is to be a slave Clearly, the post you r…

You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Lin…

> Are you saying Linux is intrinsically better?

Can we say that the market has spoken?

https://en.wikipedia.org/wiki/Usage_share_of_operating_syste...

I look forward to the day that windows is mostly a UI over WSL and things like the regsitry become a distant memory.

Re: Everything authenticated by Microsoft is tainted

#230
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

It's already started. I design systems in a european country and there are already municipal and state agencies requesting us to make more on-prem stuff. I also heard of various projects to create more European cloud services.
Post reply on HN