Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

301–310 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#301
post #256

Earlier quoted context omitted.

> many MS engineering accounts had already been hacked This isnt being focused on enough here. MS is set up in such a way that there are individual members of staff, with individual devices, that just need to be compromised for all their infrastructure is compromised. This fact alone means that's its near certainly presently compromised. states have the resources to place an engineer at MS, let alone compromise one o…

Microsoft knows which accounts were targeted by the attacker. They say so in the first link: "Our telemetry and investigations indicate that post-compromise activity was limited to email access and exfiltration for targeted users." Therefore, no, it is hyperbole that this attack means any and all MS data is compromised. The key that was compromised from one MS engineer was used in conjunction with a specific bug - cr…

via the state department, they know which emails in outlook for the state dept were compromised by their access patterns.

That's the access patterns of a single application for a single user. They know absolutely nothing about what's happened to their infrastructure.

Re: Everything authenticated by Microsoft is tainted

#302
So here's a little brain teaser about what you have to do when dealing with potential nation-state actors. This scenario is for the folks who are calling "hyperbole" when the actor is clearly, potentially a nation-state. This scenario is based upon an event that actually occurred.

1. You have a $200 million piece of defense-critical equipment. 2. You know that there was a 5-minute period where a potential member of a foreign intelligence service was alone and unattended in the same room as this piece of equipment.

What do you do with the equipment? You can:

a) Put the equipment into service b) Disassemble the equipment on both a hardware and software level and try to detect if anything was altered c) Destroy the equipment

If you choose anything other than c) you have probably never been, nor should you ever be, in charge of securing critical assets that can be targeted by a nation-state. This incident seems to indicate that the leadership at Microsoft would choose a).

Also, bear in mind that these are the people that you just sent all your ChatGPT data to.

Re: Everything authenticated by Microsoft is tainted

#303

So here's a little brain teaser about what you have to do when dealing with potential nation-state actors. This scenario is for the folks who are calling "hyperbole" when the actor is clearly, potentially a nation-state. This scenario is based upon an event that actually occurred. 1. You have a $200 million piece of defense-critical equipment. 2. You know that there was a 5-minute period where a potential member of a…

Hi, person here who said that this is hyperbole. I said that because it states unfounded things in an extremely confusing way that implies that they are facts. No question, this was a very bad breach and I hope to learn more about it as the investigation continues.

Anyways, I've worked at companies that are absolutely targeted by nation states.

Re: Everything authenticated by Microsoft is tainted

#304
post #273

Earlier quoted context omitted.

> Of course you patch it, but you don’t assume that every system affected by this 0-day got exploited. Uhh, what? Of course you do. Why give the benefit of the doubt to hackers who hacked you with malicious intentions? That's the type of security nonsense that I'd expect from... Well, Microsoft lol

So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.

It's one thing if it's your laptop, but another if it's a system with billions of users.

Re: Everything authenticated by Microsoft is tainted

#305
post #273

Earlier quoted context omitted.

> Of course you patch it, but you don’t assume that every system affected by this 0-day got exploited. Uhh, what? Of course you do. Why give the benefit of the doubt to hackers who hacked you with malicious intentions? That's the type of security nonsense that I'd expect from... Well, Microsoft lol

So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.

A released 0day is an oxymoron..

Re: Everything authenticated by Microsoft is tainted

#306
post #273

Earlier quoted context omitted.

> Of course you patch it, but you don’t assume that every system affected by this 0-day got exploited. Uhh, what? Of course you do. Why give the benefit of the doubt to hackers who hacked you with malicious intentions? That's the type of security nonsense that I'd expect from... Well, Microsoft lol

So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.

Evertime a 0day thar granted privilege escalation was found on installed bins/libs, we ran a script that looked at setsuids on anything and everything and did a report on what was found. We managed to find a crypto miner once.

Obviously I won't run it on my personal computer, but i'm not renting my pc to anyone.

Re: Everything authenticated by Microsoft is tainted

#307
post #256

Earlier quoted context omitted.

Microsoft knows which accounts were targeted by the attacker. They say so in the first link: "Our telemetry and investigations indicate that post-compromise activity was limited to email access and exfiltration for targeted users." Therefore, no, it is hyperbole that this attack means any and all MS data is compromised. The key that was compromised from one MS engineer was used in conjunction with a specific bug - cr…

via the state department, they know which emails in outlook for the state dept were compromised by their access patterns. That's the access patterns of a single application for a single user. They know absolutely nothing about what's happened to their infrastructure.

If you would read the first link, you would see that what you're claiming is unsubstantiated. They could track it to a great level of detail because they identified the threat vector and patched it quickly.

Re: Everything authenticated by Microsoft is tainted

#308
post #194

From Microsoft’s blog post on the incident (Mitigation and Hardening section): - On June 26, OWA stopped accepting tokens issued from GetAccessTokensForResource for renewal, which mitigated the token renewal being abused. - On June 27, Microsoft blocked the usage of tokens signed with the acquired MSA key in OWA preventing further threat actor enterprise mail activity. - On June 29, Microsoft completed replacement of…

The problem is that you have no way to verify what may or may not have been done by malicious actors using compromised keys in the meantime. If you have immutable, permanent audit logs, you can go through all actions authenticated with something directly or indirectly signed by the leaked key. However, building such an audit log in a way that someone with maximum permissions still can't tamper with it is not easy — a…

Could this be said for just about _any_ intrusion? Once you’ve been compromised, is there any way to know that no back doors were installed? Is this situation different than others?

Re: Everything authenticated by Microsoft is tainted

#309
post #214

Earlier quoted context omitted.

Observation from german companies (smaller eg 250 employees, mid, big): Azure DevOps is used. Noone uses GitHub. I am sure it's widespread, but rather for small companies

Where I work (globally well-known brand) GitHub is chosen as the future platform, since apparently that is where MS invests more. DevOps is seen as legacy. Curious if others have different info.

From open source documentation commits and feature lag (new features for DevOps are old GitHub features and even now include GitHub branding) I think it is impossible to avoid the impression that GitHub is active development and DevOps is legacy.

The problem is that Microsoft still hasn't said that officially and directly out loud despite the writing on the wall. They continue to sell DevOps to new teams and point to its "active roadmap" (despite it being mostly unambitious and increasingly "copy X from GitHub"). So a lot of companies still have just enough doubt in the message that DevOps is legacy/dead that they keep inside it and don't migrate to GitHub, because Microsoft keeps giving them that doubt. I'm not sure if it is superstition on Microsoft's part to not kill DevOps (it is an ancient team with quite a legacy; it's maybe Microsoft's albatross), some sort of "magic" migration strategy they want to keep secret until complete, or just that Microsoft loves telling customers what they want to hear and enough companies want to hear "DevOps is alive and in good health" for a number of sunk cost or emotional support reasons.

Re: Everything authenticated by Microsoft is tainted

#310

So here's a little brain teaser about what you have to do when dealing with potential nation-state actors. This scenario is for the folks who are calling "hyperbole" when the actor is clearly, potentially a nation-state. This scenario is based upon an event that actually occurred. 1. You have a $200 million piece of defense-critical equipment. 2. You know that there was a 5-minute period where a potential member of a…

Hi, person here who said that this is hyperbole. I said that because it states unfounded things in an extremely confusing way that implies that they are facts. No question, this was a very bad breach and I hope to learn more about it as the investigation continues. Anyways, I've worked at companies that are absolutely targeted by nation states.

We are not talking about a vulnerability in Azure's system here, we are talking about a vulnerability that was exploited. The worst has happened, somebody got in and grabbed that key.

The idea that an attacker went to this length to get the key and then did nothing with it is absurd.

Post reply on HN