Earlier quoted context omitted.
Doubt it. Data governance and access control is just getting to be a bigger deal with each passing year, and nobody wants to (pay enough to) self-manage that. Or to take personal responsibility for it. Maybe “on prem” but largely managed by someone else, which is already a thing.
It's ironic that data governance and access control are getting to be a bigger deal every year exactly because everyone migrated off premises to the cloud. People lost control over their data when they migrated it to the cloud and now they try to take control back by imposing more and more policies.
Everything authenticated by Microsoft is tainted
281–290 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#282Earlier quoted context omitted.
The worst part is that very poor diversification / groupthink is exactly what creates financial bubbles and financial crises. We seem to be reaching that uncomfortable too-big-to-fail scale in computing / cyber security.
> We seem to be reaching We clearly reached it at the 90's. We have been waiting for the other shoe to drop since then.
Re: Everything authenticated by Microsoft is tainted
#283Earlier quoted context omitted.
I like how you open with "you are correct" then go on to completely ignore the GPs comments. I've been doing this stuff for longer than a lot of people on here have been alive and the biggest risk is always your weakest link. The weakest link in most companies isn't the cloud, it's the engineers deploying to the cloud. That weak link exists regardless of whether those engineers deploy to a centralised place or on-pre…
Well, the supposition GP made was that Security Experts AGREE ON ANYTHING. Which is a patently false supposition. Some warn, others ignore. Is true. It's true for every industry, every walk of life, in every country, on the entire planet. Experts, though, when have they agreed on anything, in any field? One must ascertain for themselves which authoritative sources can be relied upon. The experts that warn of centrali…
That’s not what they said
> Centralization in any other area of life tends to be bad for citizens, so I ask you this: Why would centralization lead to MORE security, or MORE benefit to the users and citizens of the world?
I had already addressed the point about centralisation and risk. This additional question you’re raising is, at best, a straw man argument.
If you go back and read, and I mean properly read, pause and think about the comments being made, you’d realise that we aren’t saying risk doesn’t exist. We are saying the reality of that risk depends on numerous factors specific to each business, project, and even team. Thus you cannot distil “the cloud” down to a single truism such as what you keep trying to do.
Re: Everything authenticated by Microsoft is tainted
#284From Microsoft’s blog post on the incident (Mitigation and Hardening section): - On June 26, OWA stopped accepting tokens issued from GetAccessTokensForResource for renewal, which mitigated the token renewal being abused. - On June 27, Microsoft blocked the usage of tokens signed with the acquired MSA key in OWA preventing further threat actor enterprise mail activity. - On June 29, Microsoft completed replacement of…
If you have immutable, permanent audit logs, you can go through all actions authenticated with something directly or indirectly signed by the leaked key. However, building such an audit log in a way that someone with maximum permissions still can't tamper with it is not easy — and not cheap. (And, worst case, the audit log may not have the necessary detail; e.g. just listing an authenticated identity, but not the way authentication was established — thus not allowing easy identification of possibly compromised access.)
As such, the hole in the strategy is that it doesn't account for other persistent backdoors that may have been added while access using this leaked key was possible. It only prevents further exploitation of the issue. But depending on the sophistication level of the attackers — which seems extremely high considering how the key was apparently stolen — it's nigh impossible to figure out how many secondary avenues of access they have established.
Re: Everything authenticated by Microsoft is tainted
#285Earlier quoted context omitted.
> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.
Microsoft is slowly chipping away on-prem Exchange and AD, forcing people into their Azure/O365 offerings little by little. They advertise their Cloud offerings as being more secure.
Re: Everything authenticated by Microsoft is tainted
#286He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
> be a slave to Microsoft Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business , I think you are completely fucking yourself over with this sort of attitude. How much business convenience are you willing to squander over thes…
Maybe, but you're also avoiding a whole lot of downside. I don't think it's unreasonable to avoid Microsoft products, either as a business or as a person.
Whether or not it makes business sense to depends on your business, of course, but there are plenty of successful businesses who avoid Microsoft.
Re: Everything authenticated by Microsoft is tainted
#287He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
Re: Everything authenticated by Microsoft is tainted
#288This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".
Re: Everything authenticated by Microsoft is tainted
#289Re: Everything authenticated by Microsoft is tainted
#290Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…
> This was a bad breach, for sure, and we may not fully understand its scope at this point > I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did. When you consider the potential implications, and possible scenarios, from a security perspective you have to assume that they're not just "possible" but a reality. If you find a zero day exploit, you don't just ignore pat…
No you don't. You definitely don't want to assume otherwise and you spend the time derisking and investigating, but if you have zero evidence to support the situation you don't just consider it the case anyways.