Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

361–370 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#361

Earlier quoted context omitted.

I'm honestly surprised they haven't been trying to bundle GitHub more (or vice versa). It does work and it is very compelling, at least on the tin. The problem is convincing powers that be that it doesn't do what it says is borderline impossible. The most they've built is equal parts astounding and terrifying. In a sort of funny twist I feel like this is an area Google could really excel in if they got their shit tog…

Observation from german companies (smaller eg 250 employees, mid, big): Azure DevOps is used. Noone uses GitHub. I am sure it's widespread, but rather for small companies

In many many many ways, they’re the same thing. GitHub Actions is Azure DevOps.

Re: Everything authenticated by Microsoft is tainted

#362

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure.

Because they’re not financially liable for the mistakes of Microsoft. They go to these services because they sign contracts offloading that risk to another company. If Microsoft leaks your entire datastore because of poor security on their end, you sue them for damages because ensuring the protection of your digital property is part of the reason these companies are enticing to use in the first place. They use Microsoft because everyone uses Office 365 because it integrates well with Active Directory which they’ve used for their corporate directory for 20+ years.

Re: Everything authenticated by Microsoft is tainted

#363
post #357

Earlier quoted context omitted.

You can just install it after the fact. Do you lack internet?

Are you serioulsy implying that everyone had hundreds of MB to spare, the knowledge, the material and the time to do it ? I'm talking about the beginning of the century when the only connection was through 56k. I'm talking about being an underage kid who discovers computing, through whatever exists in the store, and you think downloading an iso is straightforward ?

You said 'until recently' but you're describing a situation from the 90s.

Re: Everything authenticated by Microsoft is tainted

#364

Earlier quoted context omitted.

I have a 0 day. I release it. I released the 0 day.

Hehe pedant but after that action, it's no longer a 0day...

It's named so because you have "0 days" to patch it; it's not referring to the age of the vuln.

Re: Everything authenticated by Microsoft is tainted

#365

Earlier quoted context omitted.

I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.

The "start from scratch" (or as we used to call it, 'nuke from orbit') approach is the only feasible one. If an attacker had full root across the org for an undetermined (but not short) period, I'm unsure what other approach you think you could take? You can't just run MalwareBytes and call it a day.

Step 1 is to review your existing telemetry. You determine the possible scope of the attack based on the evidence you find. You remediate based on that. You may also want to consider scope that you don't have evidence for but that you lack telemetry for and that you believe an attacker could have accessed - that's fine too.

This comes down to a risk assessment. No company has a breach and just shuts everything down, that is insane. When we perform IR we build a detailed timeline, we collect the scope of potential access, and we form a remediation plan. We don't just go "well hey, anything can happen right? shut it all down".

Re: Everything authenticated by Microsoft is tainted

#366

Earlier quoted context omitted.

Revoke everything? Everything ? I have literally done incident response I am well aware of what the investigation process is like.

Everything a potentially compromised key has signed, yes. What are we discussing here? This is standard procedure by every compliance processes I have ever had the misfortune to work with, but for quite good reasons. Hope alone won't pass an audit.

OK but "everything" and "everything the key may have signed" are obviously so insanely different.

Re: Everything authenticated by Microsoft is tainted

#367
post #214

Earlier quoted context omitted.

Observation from german companies (smaller eg 250 employees, mid, big): Azure DevOps is used. Noone uses GitHub. I am sure it's widespread, but rather for small companies

Where I work (globally well-known brand) GitHub is chosen as the future platform, since apparently that is where MS invests more. DevOps is seen as legacy. Curious if others have different info.

ADO was dead, until customers told Microsoft ADO wasn’t dead.

Once Microsoft learned that ADO was not, indeed, dead, they began to reformulate the path forward for ADO and have actually released a fair amount of preview and release features since the pivot back.

Enterprises like ADO and even when ADO was “legacy”, MSFT continued to see an uptick in adoption. ADO has better integration with Azure, at least for the web app space I play in.

Re: Everything authenticated by Microsoft is tainted

#368

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

Win 2K Pro IIS5 would have been limited to 10 conconnections.

Not exactly useful for a web server beyond development.

FWIW, I had an Apache box running on Slack which got fork bombed around the same timeframe.

Security was largely up to the competence of the individual. I was learning Linux :-)

Re: Everything authenticated by Microsoft is tainted

#369

Earlier quoted context omitted.

I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.

The "start from scratch" (or as we used to call it, 'nuke from orbit') approach is the only feasible one. If an attacker had full root across the org for an undetermined (but not short) period, I'm unsure what other approach you think you could take? You can't just run MalwareBytes and call it a day.

Nuke it from orbit applies to a workstation, not an enterprise environment.

Re: Everything authenticated by Microsoft is tainted

#370

Earlier quoted context omitted.

I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.

That's really wishful thinking. Which is fine if you're a small company throwing non-sensitive things into Azure. If OTOH you were working as a SIEM at some company providing 2nd-order cloud services, this is where I would start questioning your qualifications and that company's overall policies. (… especially when you're not even bringing up the fact that the compromised key was mainly usable to access e-mail)

I did indeed bring that up in another comment. I don't feel the need to repeat all information across all of my comments.

I don't know what your point is.

Post reply on HN