Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

351–360 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#351

Earlier quoted context omitted.

Apparently they might also be backdoored by the NSA: https://news.ycombinator.com/item?id=37571014

Frankly is this important? If the NSA is a threat to you do you have any business trusting MS?

No one has any business trusting Microsoft, apparently?

I’m under no delusions that an intelligence agency with ‘home team advantage’ wouldn’t already have the keys to the kingdom. If they are in the apparent habit of leaving the keys sitting around in random Cafes, the odds that other non-home team intelligence agencies have a copy increases dramatically too. Or even random miscreants.

As to if that matters? Eh.

Re: Everything authenticated by Microsoft is tainted

#352
Going through this article of the author https://karl-voit.at/cloud/ it seems to me that it is mainly Azure that has security issues. Google and especially AWS have no comparable incidents. If security would be important for the cloud market one would see now a movement away from Azure. But Microsofts office monopoly keeps everyone in the Azure cloud. The cloud market is broken and only huge antitrust cases against the cloud providers could fix that. But our government officials are all cowards nowadays.

Re: Everything authenticated by Microsoft is tainted

#353
post #268

Earlier quoted context omitted.

>Until recently I had no means to buy Linux, I was forced to buy Windows Huh, why not?

Because no computer was sold with Linux in it. There wasn't even an offer, let alone a market.

You can just install it after the fact. Do you lack internet?

Re: Everything authenticated by Microsoft is tainted

#354

Earlier quoted context omitted.

Rotating keys are far from enough. If your keys are compromised, you need to revoke everything. Then you need to assess what the impact is and wipe anything the compromised keys had access to during the period. This is not theoretical. When the openssl fiasco hit, I worked in a place under financial regulation. Not even the defense sector, which is under much stricter rules. We had to go through all logs to ascertain…

Revoke everything? Everything ? I have literally done incident response I am well aware of what the investigation process is like.

Everything a potentially compromised key has signed, yes. What are we discussing here? This is standard procedure by every compliance processes I have ever had the misfortune to work with, but for quite good reasons. Hope alone won't pass an audit.

Re: Everything authenticated by Microsoft is tainted

#355
post #352

Going through this article of the author https://karl-voit.at/cloud/ it seems to me that it is mainly Azure that has security issues. Google and especially AWS have no comparable incidents. If security would be important for the cloud market one would see now a movement away from Azure. But Microsofts office monopoly keeps everyone in the Azure cloud. The cloud market is broken and only huge antitrust cases against t…

Not so much Office monopoly, as Active Directory monopoly.

Re: Everything authenticated by Microsoft is tainted

#356

Earlier quoted context omitted.

I keep my secrets in a safe with an old school lock. My elderly aunt keeps her secrets on a notepad in her desk. I suppose a spy or a housecleaner (if she had one) could know her secrets but it won't be "hacked". The whole "you have no privacy or no security" is false and only impacts the terminally online. Do what the intelligence agencies do. Stop letting other people store your secrets. Put them in a nice heavy lo…

I think that would be a bit simplistic - a burglar who specifically wants your personal digital secrets could put a hidden camera on your ceiling, a bug between your PC and USB keyboard, or just hold you hostage for it! Having a safe is pretty useful, but is neither a guarantee of security nor strictly necessary. Having a firearm only works as protection if (A) you are present and armed 24/7 to protect your safe, (B)…

Almost no data breaches are targeted at a single user.

The value of your personal info individually is $1? Maybe $4?

If you can hit someone who has 100k records, hey that's a solid payday.

But no thief is gonna go break into a safe, risk being shot by an angry homeowner, or kick off targeted attacks over.. $4. Even your flatscreen tv is worth more and is MUCH easier to steal.

Almost all adversaries don't care about a specific target. They want an easy target. A safe + upset well armed owner is not an easy target.

Re: Everything authenticated by Microsoft is tainted

#357
post #268

Earlier quoted context omitted.

Because no computer was sold with Linux in it. There wasn't even an offer, let alone a market.

You can just install it after the fact. Do you lack internet?

Are you serioulsy implying that everyone had hundreds of MB to spare, the knowledge, the material and the time to do it ? I'm talking about the beginning of the century when the only connection was through 56k. I'm talking about being an underage kid who discovers computing, through whatever exists in the store, and you think downloading an iso is straightforward ?

Re: Everything authenticated by Microsoft is tainted

#358
post #194

From Microsoft’s blog post on the incident (Mitigation and Hardening section): - On June 26, OWA stopped accepting tokens issued from GetAccessTokensForResource for renewal, which mitigated the token renewal being abused. - On June 27, Microsoft blocked the usage of tokens signed with the acquired MSA key in OWA preventing further threat actor enterprise mail activity. - On June 29, Microsoft completed replacement of…

The problem is that you have no way to verify what may or may not have been done by malicious actors using compromised keys in the meantime. If you have immutable, permanent audit logs, you can go through all actions authenticated with something directly or indirectly signed by the leaked key. However, building such an audit log in a way that someone with maximum permissions still can't tamper with it is not easy — a…

The problem with THAT line of thinking is:

* We already have confirmation that the US government has been tapping internet infrastructure, accessing back doors in BigTech backends, and compromising industry-wide encryption and RNG standards.

So there is no way to prove that SOMEONE at the NSA doesn't have the ability to access all of the information on the internet.

And, since the NSA is just more humans, that means there's no way to prove that someone else hasn't sold that ability or specific subsets of the data to malicious actors.

Post Snowden revelations, you have to do risk analysis. Is some US or Five Eyes Government Agency able to access all your personal information or business competitive secrets? Probably Yes. Can one of your competitors? Probably Not. Can a malicious neighbor or drug cartel that would then use it to extort you for money? Probably not.

So even in this hypothetical example where everything authenticated by Microsoft is tainted, it's not clear if it actually changes this equation significantly.

Re: Everything authenticated by Microsoft is tainted

#359

Earlier quoted context omitted.

> I feel like the conclusions being drawn are extreme. You linked Microsoft's investigation report on the exploit. The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that , dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its in…

I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.

The "start from scratch" (or as we used to call it, 'nuke from orbit') approach is the only feasible one.

If an attacker had full root across the org for an undetermined (but not short) period, I'm unsure what other approach you think you could take? You can't just run MalwareBytes and call it a day.

Re: Everything authenticated by Microsoft is tainted

#360

Earlier quoted context omitted.

If you find yourself owned by, and not only from a 0-day, then yes, you wipe everything clean and re-build with mitigations in place from the start as to not get reinfected in the process. That's pretty much the only option if you safeguard valuable data for your customers. Yes, it's expensive to get breached, so take precautions to make it a rare event and contain it as much as possible when it happens. I don't thin…

I mean, yes, obviously, you have malware on a box you rotate that box. They had keys and they rotated the keys. But the implication here is that the attacker could have done anything and therefor they have to destroy everything , which is unreasonable.

> I mean, yes, obviously, you have malware on a box you rotate that box.

"The box" in this case is their entire org.

Post reply on HN