Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

371–380 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#371

Earlier quoted context omitted.

The "start from scratch" (or as we used to call it, 'nuke from orbit') approach is the only feasible one. If an attacker had full root across the org for an undetermined (but not short) period, I'm unsure what other approach you think you could take? You can't just run MalwareBytes and call it a day.

Nuke it from orbit applies to a workstation, not an enterprise environment.

Nukes can be applied to all kinds of shit. It's easy enough to understand the implication of the phrase that there's no need to pretend it can only apply to specific items.

Re: Everything authenticated by Microsoft is tainted

#372
post #357

Earlier quoted context omitted.

Are you serioulsy implying that everyone had hundreds of MB to spare, the knowledge, the material and the time to do it ? I'm talking about the beginning of the century when the only connection was through 56k. I'm talking about being an underage kid who discovers computing, through whatever exists in the store, and you think downloading an iso is straightforward ?

You said 'until recently' but you're describing a situation from the 90s.

It's still true today, machines with Linux can barely be found in stores. You can find them online but that's not always easier for people who are not knowledgeable

Re: Everything authenticated by Microsoft is tainted

#373
post #372

Earlier quoted context omitted.

You said 'until recently' but you're describing a situation from the 90s.

It's still true today, machines with Linux can barely be found in stores. You can find them online but that's not always easier for people who are not knowledgeable

It's not true today at all lol. You talked about not having access to Linux and only having dial up speed - that's strictly a 90s problem.

You don't see them in stores because there is not enough demand for them, and because stores are dying anyway. Very easy to find them online to buy.

Re: Everything authenticated by Microsoft is tainted

#374

Earlier quoted context omitted.

drown in champagne or drown in filthy sea water? for some, this sounds like a nonsensical choice. for others, a defining moment of leadership.

https://nationalpost.com/news/canada/charles-joughin-titanic... >How a baker survived the Titanic sinking by getting really drunk Bottoms up!

just coming back a few later to say thanks, you tha real mvp.

Re: Everything authenticated by Microsoft is tainted

#375

Earlier quoted context omitted.

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

Win 2K Pro IIS5 would have been limited to 10 conconnections. Not exactly useful for a web server beyond development. FWIW, I had an Apache box running on Slack which got fork bombed around the same timeframe. Security was largely up to the competence of the individual. I was learning Linux :-)

There is a book on Linux Hardening that helps secure Linux.

Win 2K Pro is limited to 10 connections. In 2002 I worked for a surgical tool company with sterilizing software for 300 clients and they tried to do it on Win 2K Pro, so I switched them to Server with SQL Server 2000 instead of Excel.

Re: Everything authenticated by Microsoft is tainted

#376
post #372

Earlier quoted context omitted.

It's still true today, machines with Linux can barely be found in stores. You can find them online but that's not always easier for people who are not knowledgeable

It's not true today at all lol. You talked about not having access to Linux and only having dial up speed - that's strictly a 90s problem. You don't see them in stores because there is not enough demand for them, and because stores are dying anyway. Very easy to find them online to buy.

> only having dial up speed - that's strictly a 90s problem.

Dial up was widespread well into the early 2000's, and even then ADSL started to spread slowly.

> You don't see them in stores because there is not enough demand for them

There is no demand because, again, the market is a lie. One OS is forced to consumers, on the computers they buy in the stores, they use at school, they use at work. That's exactly what I'm saying.

> Very easy to find them online to buy.

Computer literacy of the population is not comparable to the one of people on HN, so no, I wouldn't say it is as easy as buying a linux computer online than buying any computer offline.

Re: Everything authenticated by Microsoft is tainted

#377
post #376

Earlier quoted context omitted.

It's not true today at all lol. You talked about not having access to Linux and only having dial up speed - that's strictly a 90s problem. You don't see them in stores because there is not enough demand for them, and because stores are dying anyway. Very easy to find them online to buy.

> only having dial up speed - that's strictly a 90s problem. Dial up was widespread well into the early 2000's, and even then ADSL started to spread slowly. > You don't see them in stores because there is not enough demand for them There is no demand because, again, the market is a lie. One OS is forced to consumers, on the computers they buy in the stores, they use at school, they use at work. That's exactly what I'…

Bro you are really arguing for the sake of arguing now.

> Dial up was widespread well into the early 2000's, and even then ADSL started to spread slowly.

Cable became common in the early 2000s, and even if you couldn't get it at home you could go somewhere that had decent speed, certainly to download a 600mb ISO.

Not bothering to address the rest of your contrarian points.

Re: Everything authenticated by Microsoft is tainted

#378
post #197
post #42

Earlier quoted context omitted.

Microsoft is luring in non-tech companies with Active Directory and Office 365 and then catches them with promises about good integration into all services. Once the companies are in the Azure dashboard, why not try those fancy services they offer? It's all smoke and mirrors but it works.

From what I've heard from cloud consultants in Scandinavia (which is going through a huge move to the cloud as many places) the Microsoft Azure sales machine is on another level compared to competitors. Microsoft will show up with 10 sales engineer, while others might just be a contractor or a zoom call. They present themself as the authority for non-technical business and is winning a lot on that. They're good at ca…

One incentive spells kickback. When money, and not quality is the measurement.

Re: Everything authenticated by Microsoft is tainted

#379

Earlier quoted context omitted.

> I feel like the conclusions being drawn are extreme. You linked Microsoft's investigation report on the exploit. The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that , dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its in…

I think there's a huge difference between "maybe there is a backdoor" versus "literally all of microsoft, across all orgs, is owned and they have to shut it all down and start from scratch", call me crazy.

To me it sounds more like: Most likely backdoors have been planted.

So the question is how you handle such a situation.

Re: Everything authenticated by Microsoft is tainted

#380

Earlier quoted context omitted.

Establishing that ability costs money (i.e. having snapshots & co.), and actually executing it costs further money. Absent either customers paying for it, or regulations requiring it, Microsoft certainly won't sink money out of the goodness of their heart. I don't believe there are a lot of regulations for this — and how many customers do you think would pay for something like this? Realistically? :-(

I mean, they at least have SOC2 compliance, and obviously a lot more (FEDRAMP). To get those certifications an auditor is going to make sure you have basic shit in place like logging, etc.

They're not going to make sure of anything, in my experience, except that an org's IT management had a disappointing conversation with their team and then aspirationally checked boxes claiming to have things in place.
Post reply on HN