Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

331–340 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#331

Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…

[dead]

Re: Everything authenticated by Microsoft is tainted

#332
post #154

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

This is exactly the same attitude people got to Web3. So many scam tokens and rugpulls, they’re like “what are you gonna do? it’s the wild west.” Worse than that, when Celsius, FTX and other centralized companies imploded due to unsustainable and negligent practices many people were led to conflate that with Web3 blockchain smart contracts ecosystem. The ironic part is that Bitcoin and Ethereum, altcoins like Filecoi…

You are spot on with this; you don't need distributed systems and cryptography to run a fraudulent bank! Indeed, much of the 'trust' that comes with traditional financial institutions comes not from an inherent advantage in competence compared to cryptocurrency developers, but the fact that most national governments will bail out bank failures and reimburse vast sums of their citizens' losses.

If cryptocurrency-based financial instruments were regulated and protected to the same degree as traditional companies - but with the relevent technical competence to match! - I'm sure 'pay with ETH' and the like would be as common as PayPal and VISA.

Re: Everything authenticated by Microsoft is tainted

#333
post #330

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. Can you explain this more? What's wrong with AWS compared to Azure?

The sentence is worded a little confusingly, but my interpretation of it is that for certain companies, since Amazon is a competitor in the business domain of that company, AWS is a nonstarter even if it's product offerings are a better choice. Walmart is the canonical example.

Re: Everything authenticated by Microsoft is tainted

#334

Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…

> I feel like the conclusions being drawn are extreme. You linked Microsoft's investigation report on the exploit. The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that , dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its in…

I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.

Re: Everything authenticated by Microsoft is tainted

#335
post #221

Earlier quoted context omitted.

One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.

Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.

You can but you need to install NT4 first, then do all the upgrades

Re: Everything authenticated by Microsoft is tainted

#336

Is this the reason why GitHub asked me two days ago to enable 2fa Authentication? https://stackoverflow.com/questions/77186232/how-to-use-gith...

They have been asking this for longer than 2 days. I think I got pestered a couple of weeks ago.

Re: Everything authenticated by Microsoft is tainted

#337

Earlier quoted context omitted.

> I feel like the conclusions being drawn are extreme. You linked Microsoft's investigation report on the exploit. The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that , dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its in…

I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.

That's really wishful thinking. Which is fine if you're a small company throwing non-sensitive things into Azure. If OTOH you were working as a SIEM at some company providing 2nd-order cloud services, this is where I would start questioning your qualifications and that company's overall policies.

(… especially when you're not even bringing up the fact that the compromised key was mainly usable to access e-mail)

Re: Everything authenticated by Microsoft is tainted

#339

Earlier quoted context omitted.

MS is still probably somewhere in the supply chain of software you use. They have contributed to the Linux Kernel, they own GitHub and NPM, they make an extremely popular editor, among other things. It’s a different set of risks than depending on them directly, but they’re still there.

Contributing to something and owning it are wildly different levels of control. The rest of it is reasonable, but Linux doesn't belong in your list.

Fair point.

Re: Everything authenticated by Microsoft is tainted

#340

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. Blame CTOs and system admins who are either married to the stack because it's the most familiar OR they were forced onto it by a CTO because, "no one ever got fired for picking a Gartner upper right quadrant option."

It’s not just workloads, but all of the Azure AD and Active Directory things along with office 365. It’s a ton of services and few companies actually don’t use AD.
Post reply on HN