Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

251–260 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#251
post #215

Earlier quoted context omitted.

You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Lin…

> Are you saying Linux is intrinsically better? Can we say that the market has spoken? https://en.wikipedia.org/wiki/Usage_share_of_operating_syste... I look forward to the day that windows is mostly a UI over WSL and things like the regsitry become a distant memory.

The market is an illusion. Until recently I had no means to buy Linux, I was forced to buy Windows (and it is illegal here, but all you get for going to a trial is not even the price of a licence). Even today the options are very few.

The idea of a market works if it costs ~0 to enter a market, consumers have an infinite access to knowledge and infinite time to make a decision BUT make it in 1s when at the store, and also enough money so as to not be a problem. Basically, consumers have all the power and vendors have none.

Nothing is really a market, and operating systems definitely shows it.

Re: Everything authenticated by Microsoft is tainted

#252
post #178
post #167

Earlier quoted context omitted.

> own ways to do anything but be a slave to Microsoft I guarantee 99/100 humans on this forum either currently host with AWS/GCP/Azure or have worked at a shop that does. And I bet an outsized portion of those AWS/GCP shops also host on Azure for Azure AD. There is no one that is ready for a de-Microsofted world. Even Linux distros have been increasing their support for integrating into the MS ecosystem and forsaking…

My entire adult life and career has been MS free. It’s not that rare.

I wanted to believe the same, until I thought about the Tax Office and, basically, the entirety of my government, who happen to not be USA but is definitely a Microsoft place.

Re: Everything authenticated by Microsoft is tainted

#253
post #127

Earlier quoted context omitted.

Have you checked if you have a Microsoft CA installed to your system?

More seriously, on my Debian stable system: $ dpkg -l ca-certificates Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-===============-============-============-================================= ii ca-certificates 20230311 all Common CA certif…

And so, to back to your question:

> Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone...

Are these certificates affected? Or perhaps the CA/Browser Forum aren't aware of the scope.

Re: Everything authenticated by Microsoft is tainted

#254
post #139

Earlier quoted context omitted.

"Security researchers agree" is a very broad statement. I don't believe there is a consensus at all. Fragmentation creates different problems than centralization, but it isn't a magical bullet either. Depending on your resources, you are far, far better off trusting even Microsoft than trying to come up with your own security implementation.

You are correct. There are those who warn, and those who ignore. There is no consensus. But, that's with every industry, every field, every platform. Some warn, others ignore. Wanna bet who's right?

I like how you open with "you are correct" then go on to completely ignore the GPs comments.

I've been doing this stuff for longer than a lot of people on here have been alive and the biggest risk is always your weakest link. The weakest link in most companies isn't the cloud, it's the engineers deploying to the cloud. That weak link exists regardless of whether those engineers deploy to a centralised place or on-prem.

Is there an additional risk having something centralised? Sure. But in the vast majority of use cases, that risk is going to be marginal (and for those types of businesses where it is an unacceptable risk, they are largely not using public clouds for exactly this reason).

And we are back to my point about these conversations being nuanced. A security team, if they do their job correctly, doesn't just make blanket statements like "centralised systems are insecure" -- instead they identify the risks and develop an IT strategy based around which risks a business is willing to accept and which are not.

Re: Everything authenticated by Microsoft is tainted

#255

Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…

> This was a bad breach, for sure, and we may not fully understand its scope at this point

> I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did.

When you consider the potential implications, and possible scenarios, from a security perspective you have to assume that they're not just "possible" but a reality.

If you find a zero day exploit, you don't just ignore patching it because "well nobody else probably has it".

Re: Everything authenticated by Microsoft is tainted

#256
post #187

Earlier quoted context omitted.

A lot later. The damage was done. Whoever had those keys could have had access to all MS accounts and services. And those people had already hacked an engineer's account. Because the chances of stumbling upon this key when only hacking one engineering account are very low, it's reasonable to assume many MS engineering accounts had already been hacked. Basically, your MS account is not safe.

> many MS engineering accounts had already been hacked This isnt being focused on enough here. MS is set up in such a way that there are individual members of staff, with individual devices, that just need to be compromised for all their infrastructure is compromised. This fact alone means that's its near certainly presently compromised. states have the resources to place an engineer at MS, let alone compromise one o…

Microsoft knows which accounts were targeted by the attacker. They say so in the first link: "Our telemetry and investigations indicate that post-compromise activity was limited to email access and exfiltration for targeted users." Therefore, no, it is hyperbole that this attack means any and all MS data is compromised.

The key that was compromised from one MS engineer was used in conjunction with a specific bug - crash dumps were including secret keys, accessible on a debug environment -, this is not how the system is intended to work at all and they implemented measures to fix it. So this is another hyperbole from the original post.

Re: Everything authenticated by Microsoft is tainted

#257
post #146

Earlier quoted context omitted.

OK. Maybe the "email provider" part is the problem. They were probably lax on spammers or they couldn't keep up with them. I have experience with hosting my own on dedicated servers. It's mostly been fine.

This is what I used to do (and what my father still does). Essentially if you don't have 20+ years of history you appear to be doomed on this. Adding DKIM / SPF even configured correctly didn't seem to do much good.

This has not been my experience but every circumstance is different.

Re: Everything authenticated by Microsoft is tainted

#259
post #221

Earlier quoted context omitted.

One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.

Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.

FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8

Re: Everything authenticated by Microsoft is tainted

#260
post #51

This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".

This. They don’t even use a HSM if I understood correctly and using one is not part of the mitigation plan. Not OK.

They sure sell HSM on Azure.
Post reply on HN