Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

241–250 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#241
post #150

Earlier quoted context omitted.

> "Okay. What can a company do when there is no choice?" The number of enterprise-grade applications that are cloud-only offerings is only increasing. I'd be curious to know what kind of problems could be only solved through a cloud-only solution. It's a honest question; I'm not old enough to remember actually using mainframes but in my days companies had their own IT staff, gear and storage. I understand that hiring…

Software security is a good example. Lets say you work for a large company, you have 50K repos in your git instance, and you have 10K developers on staff churning out all of that software from the mundane to the mission critical. You want to provide a means for your developers to be good citizens to get out in front of security vulnerabilities. Building an in house solution to do this is extremely costly in every way…

Hum... We are still dealing with the last cloud-based security scanner that injected malware into every large IT related company, and still discovering what companies are completely hacked because of it but are hiding this.

So, color me unimpressed.

Re: Everything authenticated by Microsoft is tainted

#242
post #61

Earlier quoted context omitted.

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

They replaced Windows NT with Classic Mac OS?

Harder to execute a useful payload in a cooperative multitasking environment.

Re: Everything authenticated by Microsoft is tainted

#243

Earlier quoted context omitted.

Don't forget that it was then Microsoft CEO Steve Ballmer who in 2001 compared Linux to cancer. If there is childish vitriol somewhere, it did start neither on HN nor on /.

Oh I know, all companies change over time and both Billy and Balmer have zero impact on the day to day operations at Microsoft. The Microsoft today isn't the Microsoft of the 2000s. Now I wish the same thing could be said about Google which is quickly becoming the Microsoft of the 2000s.

You keep saying that they're different, but to my old eyes you're just buying their marketing.

They still have horrible security. They are still product dumping. They're still ignoring user preferences and forcing their agenda (eg: Edge) They're worse than ever about user privacy.

I could go on. I don't like Google either, but your corporate loyalty is silly. Both can be and are terrible.

Re: Everything authenticated by Microsoft is tainted

#244

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> be a slave to Microsoft Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business , I think you are completely fucking yourself over with this sort of attitude. How much business convenience are you willing to squander over thes…

> How much business convenience are you willing to squander over these principles

I haven't seen such a clear statement of this idea in a very long time[1].

The "principles" you are trading for convenience include control of your network.

[1] Last time was a talk by Bruce Schneier, a long time back. He famously declared if you give people a choice between security and dancing pigs, they'll take the pigs every time.

Re: Everything authenticated by Microsoft is tainted

#245
Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But...

> They were able to implant #backdoors, self-made keys, ... all over the place.

I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did.

> If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get rid of the intruders. Everything authenticated by Microsoft is tainted. Even #Windows auth.

Microsoft's response also seems to clearly state that they have rotated the keys, moved them to a more secure storage, etc. They don't say they've removed the attackers, I guess, but they certainly don't indicate that the attack is ongoing. Certainly they don't indicate that all auth is forever broken.

I feel like the conclusions being drawn are extreme.

https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...

Re: Everything authenticated by Microsoft is tainted

#246

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> be a slave to Microsoft Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business , I think you are completely fucking yourself over with this sort of attitude. How much business convenience are you willing to squander over thes…

Ha.

What do principles have to do with ANY of this? Microsoft promised a level of security and didn't deliver, and is now covering up, BADLY.

The only logical solution is to start looking elsewhere, even if you can't switch right now.

YOUR cope appears absolutely delusional.

Re: Everything authenticated by Microsoft is tainted

#247
post #178

Earlier quoted context omitted.

My entire adult life and career has been MS free. It’s not that rare.

MS is still probably somewhere in the supply chain of software you use. They have contributed to the Linux Kernel, they own GitHub and NPM, they make an extremely popular editor, among other things. It’s a different set of risks than depending on them directly, but they’re still there.

Contributing to something and owning it are wildly different levels of control. The rest of it is reasonable, but Linux doesn't belong in your list.

Re: Everything authenticated by Microsoft is tainted

#248
post #22

Earlier quoted context omitted.

[flagged]

Surprised I don't see M$FT. It's like slashdot in the early 2000s. Edit: -4 downd00ts! Haha must have triggered a few oldies who never let go of their hate.

Top comment has "windoze" mentioned. It is pretty much slashdot from 2000s

Re: Everything authenticated by Microsoft is tainted

#249
post #139

Earlier quoted context omitted.

"Security researchers agree" is a very broad statement. I don't believe there is a consensus at all. Fragmentation creates different problems than centralization, but it isn't a magical bullet either. Depending on your resources, you are far, far better off trusting even Microsoft than trying to come up with your own security implementation.

You are correct. There are those who warn, and those who ignore. There is no consensus. But, that's with every industry, every field, every platform. Some warn, others ignore. Wanna bet who's right?

The broken clock is. - Coles law

Re: Everything authenticated by Microsoft is tainted

#250
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

Doubt it. Data governance and access control is just getting to be a bigger deal with each passing year, and nobody wants to (pay enough to) self-manage that. Or to take personal responsibility for it.

Maybe “on prem” but largely managed by someone else, which is already a thing.

Post reply on HN