Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

231–240 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#231

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

Moving off Windows or Azure or whatever probably isn't adequate.

All architectures based on certificate authorities are fundamentally fragile in the same way. People look at me like my head is spinning when I suggest just adding ephemeral self-signed CA root certs to deployment pipelines (or, god forbid, use SSH keys, or even symmetric keys).

However, those approaches have a much, much smaller attack surface than HTTPS or standard X.509 SSH authentication, so I'll keep recommending it.

I think the reason for the pushback is that, in this space, attack surface is roughly proportional to monetization potential.

Re: Everything authenticated by Microsoft is tainted

#232
post #221

Earlier quoted context omitted.

One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.

Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.

"MSN Limited Edition Gold CD" is actually a thing.

Re: Everything authenticated by Microsoft is tainted

#233
post #215

Earlier quoted context omitted.

This would sound like ChatGPT if I didn't know better... All of your arguments are "made up" arguments, they contradict themselves or each other or assume some very unlikely situations, especially on behalf of what the post you replied to wanted to say, where it's clear it's not what it wanted to say. Let's dive in! > So are you suggesting that the most practicable alternative is to be a slave Clearly, the post you r…

You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Lin…

The thing is: Windows and Office is insecure by default. Admins react by sprinkling anti-virus on top of it, but that doesn't help any.

It still enables users to open random mail attachments in Office or similar. And Office doesn't have any sandboxing or other mitigation in place, again it's insecure by default. If you enable users to do stuff like this, you have noone to blame if you get owned.

Are the usual Linux distro's better? Hell no! They have the same flawed security architecture as Windows, only without any motivated attackers (yet).

But there are actually secure alternatives: QubesOS and ChromeOS.

QubesOS is probably not that suitable to end-users, they can do too much wrong to twart it's security (using the "financial" qube to browse p0rn... etc.).

ChromeOS is a reasonably secure OS: It's root filesystem is read-only with tamper-proof authentication, user's home directory is encrypted. Chrome runs with the usual privilege separation in multiple processes each in it's own tight sandbox. There is no way to autostart anything.

Even in the nuclear case of a 0-day RCE + chained sandbox breakout + privilege escalation to root, the threat can not persist itself... you just reboot the device and are save again.

And Google has lot's of experience in security, they one of the few who build their own browser, the most hostile environment. They are clearly thinking about security front and center and not as an afterthought (like Microsoft).

Re: Everything authenticated by Microsoft is tainted

#234

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

Another reason I am in love with LLMs. You don’t need to know the software like the back of your hand - a new environment is like a new programming language, as long as you’re able to ask the right questions new environments will be far more accessible. Experienced admins should know the requirements, and not be limited to the tools. Migrating will be relatively cheap. No wonder they’re hobbling the tools (/tinfoil),…

My experience with LLMs is that they distill just the group think from the internet, and remove all rational thought.

I doubt they'll be much help doing anything that is better than whatever standard practice was 6-12 months ago.

If anything, I'd expect them to cement in incumbents and bad practices, since fewer people will be reading documentation and thinking critically about how to do better.

Re: Everything authenticated by Microsoft is tainted

#235
post #146

Earlier quoted context omitted.

Sometimes you get a bad roll of the dice when you choose a lesser known email provider and you start with worse than average reputation. Can never go wrong with Gsuite, O365, etc.

OK. Maybe the "email provider" part is the problem. They were probably lax on spammers or they couldn't keep up with them. I have experience with hosting my own on dedicated servers. It's mostly been fine.

This is what I used to do (and what my father still does). Essentially if you don't have 20+ years of history you appear to be doomed on this. Adding DKIM / SPF even configured correctly didn't seem to do much good.

Re: Everything authenticated by Microsoft is tainted

#236
post #97
post #91

Earlier quoted context omitted.

None of which will change those three points practically. For any bit of information, they may not apply, but if you assume they’re true you’ll: 1) not record information that is truly damaging in a damaging way (which is really good practice in general if you’ve got something to lose!) 2) have practical operational practices which do not rely on these being false - which is a really good idea if that actually matter…

Regulation can absolutely improve the state of privacy over the status quo. Defeatism like this does nobody any favors. As far as companies are concerned, personal information should be considered hazardous material, and avoided at all costs.

Government regulation is what created and propped up Solar Winds.

I have to believe it's possible, but I have never seen any reasonable proposal for government regulation of infosec. Even disclosure requirements become bullshit and only harm everyone faster than they can get published.

Re: Everything authenticated by Microsoft is tainted

#237

When I worked at Microsoft, I found a case internally where it appeared that a service was accepting expired certificates as a form of authentication for admin-level calls. I was fairly new, so I brought it to someone who had been at Microsoft for the better part of a decade. We didn't own the service in question, and he told me that, since it wasn't our service, I should just focus on continuing our work, and that i…

Why didn’t you go to ReportItNow like our training has been telling people to do for years?

Re: Everything authenticated by Microsoft is tainted

#238
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

This is abismal advise (and potentially self-serving advise, if you work in the industry) to give. As ever, there are nuances; "only a Sith speaks in absolutes" and all that.

#1. You have no privacy ONLINE. Providers have perverse incentives to sell you out down the river. Therefore, you DEFEND yourself by keeping a shallow online presence. If you are a casual user, you keep as little information online, specially in social media, as possible. If you need an online presence, you ASSESS the risks and pay time and money to MITIGATE those risks. If you don't see a Return-Of-Investment on those mitigation efforts, chances are you have been CONNED into thinking you need an online presence, but you probably DONT.

#2. There is no ABSOLUTE security. All possible defense measure CAN be circumvented, not not necessarily WILL be circumvented. You ASSESS as many risks as you can imagine, and MITIGATE only those where you expect a positive ROI. The ones you don't mitigate, you ASSUME. The ones you cannot afford to assume, you DO NOT TAKE by refusing to use the system.

#2.a Corollary to #2. If you take ZERO risk management, you still have a BASELINE level of security based on the risk-reward analysis by the criminogenic/sociopath portion of the population; they will not attempt an invasion if they do not expect to get away with it, or to gain something out of it. The more cynical people in the know claim there's no security, the more this baseline approaches zero and the more vulnerable the general population is.

#2.b Even if you are not part of the general population, the lower the BASELINE, the more time and money you PERSONALLY have to invest in risk management to achieve a bearable level of safety. Cynicism is costing US time and money, pal; don't pee/shit on the village's wheel just because it looks edgy!!!

#3. All your CURRENT digital information is already public or will become public AT SOME POINT. You can do better and pick the technologies that will push that point FURTHER into the FUTURE. And for not yet digitalized information, you may make conscious decisions whether the convenience is worth the risk.

Re: Everything authenticated by Microsoft is tainted

#239

Earlier quoted context omitted.

What's wrong with openldap? I mean, apart from being a pita, i thought it was the widely used central auth directory (behind all sorts of sso frontends).

I maintain a small openldap directory for our company and I think it's great. The main problems revolve around being somewhat old-fashioned and not intuitive for modern tech workers. I'm the only one in my org that really knows anything about it. Management software for openldap definitely has room for improvement, and documentation could be improved as well. It works great though! Super fast and flexible.

Yes indeed! When i said it's a pita, i mostly meant that LDAP is a pita (needlessly complex spec with complicated query language and the whole schema extension zoo). openldap is pretty fine as far as it can be.

Personally i'm using lldap, which is a neat no-footgun ldap daemon for small/personal deployments.

Re: Everything authenticated by Microsoft is tainted

#240
post #215

Earlier quoted context omitted.

You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Lin…

> Are you saying Linux is intrinsically better? Can we say that the market has spoken? https://en.wikipedia.org/wiki/Usage_share_of_operating_syste... I look forward to the day that windows is mostly a UI over WSL and things like the regsitry become a distant memory.

> Can we say that the market has spoken?

Microsoft aggressively abused its monopoly position in order to make sure that Linux would never win in the desktop market, and then inertia took over, so no we can't say that the market has said anything useful

Post reply on HN