Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…
Everything authenticated by Microsoft is tainted
331–340 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#332He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…
This is exactly the same attitude people got to Web3. So many scam tokens and rugpulls, they’re like “what are you gonna do? it’s the wild west.” Worse than that, when Celsius, FTX and other centralized companies imploded due to unsustainable and negligent practices many people were led to conflate that with Web3 blockchain smart contracts ecosystem. The ironic part is that Bitcoin and Ethereum, altcoins like Filecoi…
If cryptocurrency-based financial instruments were regulated and protected to the same degree as traditional companies - but with the relevent technical competence to match! - I'm sure 'pay with ETH' and the like would be as common as PayPal and VISA.
Re: Everything authenticated by Microsoft is tainted
#333This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…
> The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. Can you explain this more? What's wrong with AWS compared to Azure?
Re: Everything authenticated by Microsoft is tainted
#334Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…
> I feel like the conclusions being drawn are extreme. You linked Microsoft's investigation report on the exploit. The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that , dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its in…
Re: Everything authenticated by Microsoft is tainted
#335Earlier quoted context omitted.
One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.
Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.
Re: Everything authenticated by Microsoft is tainted
#336Is this the reason why GitHub asked me two days ago to enable 2fa Authentication? https://stackoverflow.com/questions/77186232/how-to-use-gith...
Re: Everything authenticated by Microsoft is tainted
#337Earlier quoted context omitted.
> I feel like the conclusions being drawn are extreme. You linked Microsoft's investigation report on the exploit. The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that , dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its in…
I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.
(… especially when you're not even bringing up the fact that the compromised key was mainly usable to access e-mail)
Re: Everything authenticated by Microsoft is tainted
#338https://rakkhi.substack.com/p/microsoft-hack-zero-trust-arch...
Re: Everything authenticated by Microsoft is tainted
#339Earlier quoted context omitted.
MS is still probably somewhere in the supply chain of software you use. They have contributed to the Linux Kernel, they own GitHub and NPM, they make an extremely popular editor, among other things. It’s a different set of risks than depending on them directly, but they’re still there.
Contributing to something and owning it are wildly different levels of control. The rest of it is reasonable, but Linux doesn't belong in your list.
Re: Everything authenticated by Microsoft is tainted
#340This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…
> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Blame CTOs and system admins who are either married to the stack because it's the most familiar OR they were forced onto it by a CTO because, "no one ever got fired for picking a Gartner upper right quadrant option."