Earlier quoted context omitted.
More seriously, on my Debian stable system: $ dpkg -l ca-certificates Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-===============-============-============-================================= ii ca-certificates 20230311 all Common CA certif…
And so, to back to your question: > Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone... Are these certificates affected? Or perhaps the CA/Browser Forum aren't aware of the scope.
Everything authenticated by Microsoft is tainted
271–280 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#272He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
Test it out, if curious - Pretty straight-forward. And a heck of a lot more economical.
Re: Everything authenticated by Microsoft is tainted
#273Earlier quoted context omitted.
> This was a bad breach, for sure, and we may not fully understand its scope at this point > I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did. When you consider the potential implications, and possible scenarios, from a security perspective you have to assume that they're not just "possible" but a reality. If you find a zero day exploit, you don't just ignore pat…
Of course you patch it, but you don’t assume that every system affected by this 0-day got exploited. You try to check if some were and it’s obvious that people at Microsoft are doing exactly that. Not saying that MS’s response was great, but I agree with GP that the whole thing is hyberbolic.
Uhh, what? Of course you do. Why give the benefit of the doubt to hackers who hacked you with malicious intentions? That's the type of security nonsense that I'd expect from... Well, Microsoft lol
Re: Everything authenticated by Microsoft is tainted
#274Earlier quoted context omitted.
This would sound like ChatGPT if I didn't know better... All of your arguments are "made up" arguments, they contradict themselves or each other or assume some very unlikely situations, especially on behalf of what the post you replied to wanted to say, where it's clear it's not what it wanted to say. Let's dive in! > So are you suggesting that the most practicable alternative is to be a slave Clearly, the post you r…
You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Lin…
Similarly, I'm not against Microsoft products being used in hospitals. I'm for transparency of standards, rules used by hospitals to acquire and maintain software, public interfaces, reporting...
If such rules are created and Microsoft is playing by the rules -- then I have no problem with it, but having Microsoft decide what the rules are is a disaster.
Re: Everything authenticated by Microsoft is tainted
#275Earlier quoted context omitted.
Is it? Every large company has a well compensated CTO whose job it is to think through these sorts of hypotheticals. But “nobody gets fired for choosing Microsoft”, and so the monopoly continues…
"A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional and orthodox way along with his fellows, so that no one can really blame him"
Re: Everything authenticated by Microsoft is tainted
#276Earlier quoted context omitted.
You are correct. There are those who warn, and those who ignore. There is no consensus. But, that's with every industry, every field, every platform. Some warn, others ignore. Wanna bet who's right?
I like how you open with "you are correct" then go on to completely ignore the GPs comments. I've been doing this stuff for longer than a lot of people on here have been alive and the biggest risk is always your weakest link. The weakest link in most companies isn't the cloud, it's the engineers deploying to the cloud. That weak link exists regardless of whether those engineers deploy to a centralised place or on-pre…
Some warn, others ignore. Is true. It's true for every industry, every walk of life, in every country, on the entire planet.
Experts, though, when have they agreed on anything, in any field?
One must ascertain for themselves which authoritative sources can be relied upon. The experts that warn of centralization are authoritative and masters in their fields.
Centralization in any other area of life tends to be bad for citizens, so I ask you this: Why would centralization lead to MORE security, or MORE benefit to the users and citizens of the world?
I'll wait...
Re: Everything authenticated by Microsoft is tainted
#277He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
If it is the case that it is going to be extremely risky to run of MS supplied infrastructure (including Windows) we should see insurance premiums sky-rocket for companies and organisations using those platforms. Eventually, it will become cheaper to migrate off the MS platforms. This is mixed with an ever increasing legislative push and higher fines for leaking PII.
e.g.: https://www.cnbc.com/2022/10/11/companies-are-finding-it-har...
Re: Everything authenticated by Microsoft is tainted
#278Earlier quoted context omitted.
Doubt it. Data governance and access control is just getting to be a bigger deal with each passing year, and nobody wants to (pay enough to) self-manage that. Or to take personal responsibility for it. Maybe “on prem” but largely managed by someone else, which is already a thing.
It's ironic that data governance and access control are getting to be a bigger deal every year exactly because everyone migrated off premises to the cloud. People lost control over their data when they migrated it to the cloud and now they try to take control back by imposing more and more policies.
[edit] to editorialize, I also think ~everyone is going to get this very wrong. I think doing this stuff such that you don’t grind productivity to a halt but also don’t have mile-wide vulnerabilities is goddamn near an Apollo Program level of difficult, and basically nobody is treating it that way (and a lot of them would probably sooner abandon their grand mass-data-total-control plans if they had to treat it that way—which is exactly what I think most of them should do, but execs just love the idea of perfect legibility of data and processes end to end on their phone or whatever, even if it’s in-fact just a money-wasting and risk-generating fantasy for most companies)
Re: Everything authenticated by Microsoft is tainted
#279Earlier quoted context omitted.
You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Lin…
The thing is: Windows and Office is insecure by default. Admins react by sprinkling anti-virus on top of it, but that doesn't help any. It still enables users to open random mail attachments in Office or similar. And Office doesn't have any sandboxing or other mitigation in place, again it's insecure by default. If you enable users to do stuff like this, you have noone to blame if you get owned. Are the usual Linux d…
Re: Everything authenticated by Microsoft is tainted
#280Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…