Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

261–270 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#261
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

Doubt it. Data governance and access control is just getting to be a bigger deal with each passing year, and nobody wants to (pay enough to) self-manage that. Or to take personal responsibility for it. Maybe “on prem” but largely managed by someone else, which is already a thing.

It's ironic that data governance and access control are getting to be a bigger deal every year exactly because everyone migrated off premises to the cloud. People lost control over their data when they migrated it to the cloud and now they try to take control back by imposing more and more policies.

Re: Everything authenticated by Microsoft is tainted

#262

Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…

> This was a bad breach, for sure, and we may not fully understand its scope at this point > I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did. When you consider the potential implications, and possible scenarios, from a security perspective you have to assume that they're not just "possible" but a reality. If you find a zero day exploit, you don't just ignore pat…

Of course you patch it, but you don’t assume that every system affected by this 0-day got exploited. You try to check if some were and it’s obvious that people at Microsoft are doing exactly that.

Not saying that MS’s response was great, but I agree with GP that the whole thing is hyberbolic.

Re: Everything authenticated by Microsoft is tainted

#263
post #251

Earlier quoted context omitted.

> Are you saying Linux is intrinsically better? Can we say that the market has spoken? https://en.wikipedia.org/wiki/Usage_share_of_operating_syste... I look forward to the day that windows is mostly a UI over WSL and things like the regsitry become a distant memory.

The market is an illusion. Until recently I had no means to buy Linux, I was forced to buy Windows (and it is illegal here, but all you get for going to a trial is not even the price of a licence). Even today the options are very few. The idea of a market works if it costs ~0 to enter a market, consumers have an infinite access to knowledge and infinite time to make a decision BUT make it in 1s when at the store, and…

>Until recently I had no means to buy Linux, I was forced to buy Windows

Huh, why not?

Re: Everything authenticated by Microsoft is tainted

#264

Earlier quoted context omitted.

Oh I know, all companies change over time and both Billy and Balmer have zero impact on the day to day operations at Microsoft. The Microsoft today isn't the Microsoft of the 2000s. Now I wish the same thing could be said about Google which is quickly becoming the Microsoft of the 2000s.

You keep saying that they're different, but to my old eyes you're just buying their marketing. They still have horrible security. They are still product dumping. They're still ignoring user preferences and forcing their agenda (eg: Edge) They're worse than ever about user privacy. I could go on. I don't like Google either, but your corporate loyalty is silly. Both can be and are terrible.

And in my eyes you're just a bitter old boomer stuck in his ways.

Security is no worse than what I see with osx. I don't use Linux because I have real work to do.

Edge is just chrome with a big blue E.

And every company product team ignores its users for monetary gain.

You really can't teach an old dog new tricks.

Re: Everything authenticated by Microsoft is tainted

#265

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> be a slave to Microsoft Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business , I think you are completely fucking yourself over with this sort of attitude. How much business convenience are you willing to squander over thes…

If only there were an alternative software development modality in which development is distributed, source available, and modification permitted to any party, with open review and analysis for vulnerabilities, and far less capacity for lock-in.

What you're arguing is essentially the Too Big to Fail proposition. The solution of which is to Not Let Things Get That Way.

https://en.wikipedia.org/wiki/Too_big_to_fail>

Re: Everything authenticated by Microsoft is tainted

#266
post #251

Earlier quoted context omitted.

> Are you saying Linux is intrinsically better? Can we say that the market has spoken? https://en.wikipedia.org/wiki/Usage_share_of_operating_syste... I look forward to the day that windows is mostly a UI over WSL and things like the regsitry become a distant memory.

The market is an illusion. Until recently I had no means to buy Linux, I was forced to buy Windows (and it is illegal here, but all you get for going to a trial is not even the price of a licence). Even today the options are very few. The idea of a market works if it costs ~0 to enter a market, consumers have an infinite access to knowledge and infinite time to make a decision BUT make it in 1s when at the store, and…

> The idea of a market works if it costs ~0 to enter a market, consumers have an infinite access to knowledge and infinite time to make a decision BUT make it in 1s when at the store, and also enough money so as to not be a problem. Basically, consumers have all the power and vendors have none.

I keep trying to communicate this whenever people are attempting to manifest an Invisible Hand to control bad behavior. More people need to be aware of this.

I like your succinct point. I wish there was something so short and understandable for an even fuller picture. Like including that for a marked to price things in a way that works for societies, consumers need to choose long term over short term gains and that the price needs to not make economic externalities of human rights or destroying the climate.

Re: Everything authenticated by Microsoft is tainted

#267

When I worked at Microsoft, I found a case internally where it appeared that a service was accepting expired certificates as a form of authentication for admin-level calls. I was fairly new, so I brought it to someone who had been at Microsoft for the better part of a decade. We didn't own the service in question, and he told me that, since it wasn't our service, I should just focus on continuing our work, and that i…

Training has been discouraging this behavior for years

Re: Everything authenticated by Microsoft is tainted

#268
post #251

Earlier quoted context omitted.

The market is an illusion. Until recently I had no means to buy Linux, I was forced to buy Windows (and it is illegal here, but all you get for going to a trial is not even the price of a licence). Even today the options are very few. The idea of a market works if it costs ~0 to enter a market, consumers have an infinite access to knowledge and infinite time to make a decision BUT make it in 1s when at the store, and…

>Until recently I had no means to buy Linux, I was forced to buy Windows Huh, why not?

Because no computer was sold with Linux in it. There wasn't even an offer, let alone a market.

Re: Everything authenticated by Microsoft is tainted

#269
post #216

Earlier quoted context omitted.

Evidently it was not the correct medicine.

More like one batch was deficient and was recalled as soon as the issue was discovered.

If I am reading the linked material correctly: more like a nefarious actor was able to get into the production facility and is still in there to this day. With the same false keycard that originally granted them access.

Re: Everything authenticated by Microsoft is tainted

#270
post #194

From Microsoft’s blog post on the incident (Mitigation and Hardening section): - On June 26, OWA stopped accepting tokens issued from GetAccessTokensForResource for renewal, which mitigated the token renewal being abused. - On June 27, Microsoft blocked the usage of tokens signed with the acquired MSA key in OWA preventing further threat actor enterprise mail activity. - On June 29, Microsoft completed replacement of…

One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.

Why is there no way of knowing? I would think Microsoft is able to do forensic snapshot comparisons for their datacenters -- at least, I would assume a trillion dollar company does.
Post reply on HN