Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

321–330 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#321

Earlier quoted context omitted.

Establishing that ability costs money (i.e. having snapshots & co.), and actually executing it costs further money. Absent either customers paying for it, or regulations requiring it, Microsoft certainly won't sink money out of the goodness of their heart. I don't believe there are a lot of regulations for this — and how many customers do you think would pay for something like this? Realistically? :-(

I mean, they at least have SOC2 compliance, and obviously a lot more (FEDRAMP). To get those certifications an auditor is going to make sure you have basic shit in place like logging, etc.

yeah, but SOC auditors barely understand the stuff you’re providing as proof.

Re: Everything authenticated by Microsoft is tainted

#322
post #308

Earlier quoted context omitted.

The problem is that you have no way to verify what may or may not have been done by malicious actors using compromised keys in the meantime. If you have immutable, permanent audit logs, you can go through all actions authenticated with something directly or indirectly signed by the leaked key. However, building such an audit log in a way that someone with maximum permissions still can't tamper with it is not easy — a…

Could this be said for just about _any_ intrusion? Once you’ve been compromised, is there any way to know that no back doors were installed? Is this situation different than others?

Well, it really depends on the maximum privilege achieved by the intrusion, a user getting compromised hopefully can't do much more than exfiltrate data they have access to; local admin could compromise the OS or even the BIOS, then there's possibly multiple levels of domain admin, and then there's a compromise of the authentication system itself…

Re: Everything authenticated by Microsoft is tainted

#323
post #130

Earlier quoted context omitted.

I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.

Fastmail is very good and has been running for 24 years, with good deliverability. Migadu I hear is good. There's quite a few email providers that aren't Microsoft or Google that have their shit together.

Yeah, fastmail is pretty close to office 365. As long as you're not dependent on Aszure for other components. I suggest businesses think about migrating away from 03 65 because this problem will probably get worse in the future, since Microsoft is either too big, or not able to secure their own security implementation.

Re: Everything authenticated by Microsoft is tainted

#324

Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…

> I feel like the conclusions being drawn are extreme.

You linked Microsoft's investigation report on the exploit.

The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that, dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its intended purpose and then executed on that.

And you don't believe they left persistent backdoors in some high-profile targets?

The conclusions being drawn are … entirely appropriate. Your argument maaaaaybe makes some sense applied to general public random cloud customers. Backdooring indiscriminately just increases the risk of discovery. But large companies and government users? You have to assume compromise, anything else is incredulously naïve.

cf.:

https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...

> Storm-0558 operates with a high degree of technical tradecraft and operational security. The actors are keenly aware of the target’s environment, logging policies, authentication requirements, policies, and procedures. Storm-0558’s tooling and reconnaissance activity suggests the actor is technically adept, well resourced, and has an in-depth understanding of many authentication techniques and applications.

Re: Everything authenticated by Microsoft is tainted

#325
post #273

Earlier quoted context omitted.

> Of course you patch it, but you don’t assume that every system affected by this 0-day got exploited. Uhh, what? Of course you do. Why give the benefit of the doubt to hackers who hacked you with malicious intentions? That's the type of security nonsense that I'd expect from... Well, Microsoft lol

So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.

If you find yourself owned by, and not only from a 0-day, then yes, you wipe everything clean and re-build with mitigations in place from the start as to not get reinfected in the process.

That's pretty much the only option if you safeguard valuable data for your customers. Yes, it's expensive to get breached, so take precautions to make it a rare event and contain it as much as possible when it happens.

I don't think the article is unreasonable. This is cloud infrastructure sold to companies with defense industry contracts where breaches are taken seriously.

Re: Everything authenticated by Microsoft is tainted

#326

Earlier quoted context omitted.

I mean, they at least have SOC2 compliance, and obviously a lot more (FEDRAMP). To get those certifications an auditor is going to make sure you have basic shit in place like logging, etc.

yeah, but SOC auditors barely understand the stuff you’re providing as proof.

It's gonna depend on the auditor, but yeah of course SOC2 doesn't mean "you're secure" but unless you actively lie to your auditor you're going to have some basic stuff in place.

Re: Everything authenticated by Microsoft is tainted

#327

Earlier quoted context omitted.

So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.

If you find yourself owned by, and not only from a 0-day, then yes, you wipe everything clean and re-build with mitigations in place from the start as to not get reinfected in the process. That's pretty much the only option if you safeguard valuable data for your customers. Yes, it's expensive to get breached, so take precautions to make it a rare event and contain it as much as possible when it happens. I don't thin…

I mean, yes, obviously, you have malware on a box you rotate that box. They had keys and they rotated the keys. But the implication here is that the attacker could have done anything and therefor they have to destroy everything, which is unreasonable.

Re: Everything authenticated by Microsoft is tainted

#328
post #127

Earlier quoted context omitted.

Have you checked if you have a Microsoft CA installed to your system?

More seriously, on my Debian stable system: $ dpkg -l ca-certificates Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-===============-============-============-================================= ii ca-certificates 20230311 all Common CA certif…

Are you aware of what applications and services are verified by these keys? I am thinking it might be worth removing these specific root certificates if they are used only for a select number of purposes, considering that the vast majority of 'normal' websites use other CAs like DigiCert or Let's Encrypt.

Re: Everything authenticated by Microsoft is tainted

#329
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

I keep my secrets in a safe with an old school lock. My elderly aunt keeps her secrets on a notepad in her desk. I suppose a spy or a housecleaner (if she had one) could know her secrets but it won't be "hacked". The whole "you have no privacy or no security" is false and only impacts the terminally online. Do what the intelligence agencies do. Stop letting other people store your secrets. Put them in a nice heavy lo…

I think that would be a bit simplistic - a burglar who specifically wants your personal digital secrets could put a hidden camera on your ceiling, a bug between your PC and USB keyboard, or just hold you hostage for it! Having a safe is pretty useful, but is neither a guarantee of security nor strictly necessary.

Having a firearm only works as protection if (A) you are present and armed 24/7 to protect your safe, (B) you are actually willing to shoot and (C) capable of doing so better than your assailant.

In a business context, if the company is large enough, it might well be worth hiring day-and-night security guards and heavy steel safes. But for the average PC user, the security can be improved much more effectively with simple improvements like creating passwords with 'diceware' or using separate accounts for financial tasks.

Re: Everything authenticated by Microsoft is tainted

#330

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor.

Can you explain this more? What's wrong with AWS compared to Azure?

Post reply on HN