Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

201–210 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#201

Earlier quoted context omitted.

you still need a os. and i fail to see how nix would make video driver problem any better. the problem with running debian is that fixes are often not backported, specifically for things end users will care about, like libre office

> you still need a os. and i fail to see how nix would make video driver problem any better. That's actually easy to answer; video drivers can be really finicky to get working. If you screw it up, it's very easy to get into a state where you have no GUI. Nowadays I am proficient enough to work my way around the command line and I probably could fix a bad driver, but 13 years ago that wasn't really the case, and if I…

> Are there not more evergreen releases of Debian?

Debian sid or "unstable" is a perfectly fine rolling release distro.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#202

I work in infosec, and this sounds like a communication failure on the whistleblower's part. Contrary to what many people believe, the profits should be prioritized over security for the most companies, that's only natural (after all, they don't generate any profits themselves, typically). The key is finding the right balance for this tradeoff. Business leaders are the ones that are responsible for figuring out the a…

Microsoft was specifically told by the US Cyber Safety Review Board that they cross the line of risk vs. profit earlier this year. https://edition.cnn.com/2024/06/13/tech/microsoft-president-...

I seem to recall from another article that Microsoft as told by the review board that they need to start focusing on security, rather than work on new feature.

A company like Microsoft shouldn't need a whistleblower to know to focus on security. It seemed like Microsoft was on the right track to becoming a better company for a good number of years, but for the past year or two everything seems to fall a part again.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#203

Earlier quoted context omitted.

Sheesh you guys are annoying. - I do not see ads in “every nook and corner of Windows” and neither do you. - I do not have a recorder installed on my Windows machines and neither do you. - no one qualified to make that statement has said that Microsoft is the most secure platform. It is so hard to listen to anyone who exaggerates at this level. If anything, it drives interest in Microsoft because these are all obviou…

You're getting downvoted for your tone most likely, but I agree with this statement: > - I do not see ads in “every nook and corner of Windows” and neither do you. As a professional "Windows user" logging 8+ hours a day on my PC, I see no ads. Unless you count "OneDrive" ads which in that case, would mean I see iCloud ads on my iPhone too. I'm fine with classifying these as ads, but I'm certainly not seeing them "in…

> Are these ads only bundled with a certain versions of Windows?

Yes. Enterprise customers can get builds without them, but home users can't.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#206
I mean, I see the crappy level of security across the whole industry. And I am working at the bank.

I am not sure what exactly the reason - even if the profit aside - but I suspect that there are not many people who are actually competent developer and security engineers.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#207
post #155

So...Golden SAML isn't a vulnerability, as the CyberArk article quoted in the post reiterates, it's a type of attack that requires completely comprising the box before using. Unless I am misunderstanding something, I don't see any particular flaw, per se. As Microsoft (mocked in the article) would say, it's not crossing a security boundary. SSO will ALWAYS have this particular tradeoff. If your SSO infrastructure is…

Sounds like the vulnerability was one within AD FS and that exposed the private key, making golden SAML possible.

It was the SolarWinds hack that gave internal access and potential admin rights. It's no different than if a domain controller gets compromised. The attacker has gained control of the keys to kingdom; it's an inherent risk to SSO.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#208

Earlier quoted context omitted.

It would help if there weren't all these employees and ex-employees stepping forward to talk about how Microsoft is performative and naive about security. I won't go as far as to say that, but I will say I don't think my incentives as an IC lined up with the security-focused mindset that company execs tout publicly.

I don't think anything is going to help here; it's just a message board fixity that companies like Microsoft are unserious about security.

Same Microsoft got their master authentication secret stolen and they still don't know how that happened.

It's also turned out that it's impossible to revoke or cycle that secret. The whole issue is so hushed now, I don't know what happened at the end.

Same Microsoft one of their license golden keys on some installation media, too.

Even if they're serious about security, these events don't look good.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#209
post #11

Sounds like the same Microsoft culture as has always been. Like a cult. It can do no wrong. The conversation with Microsoft businesspeople at conferences was always the same: Microsoft has no deficiencies, there is nothing it isn't working on and it has a solution for every possible problem. Other sources of software do not exist. There is only Microsoft. Total illusion put forth by delusional employees. The outside…

To be honest, that sounds like every company that suffers from delusions of grandeur and wants to conquer the planet, one way or another. What you're saying is equally true for Apple, Google, Amazon and most other public companies today. You're never gonna get "Use this Microsoft product" as an answer from Apple support/engineer even if that product would solve your particular problem better.

The conferences always included representatives from other large, public companies in the same or similar industries, e.g., Apple or Amazon, as well as other, different industries. But there was always something cult-like about the folks from Microsoft, their level of BS and (deliberate?) ignorance, that I never experienced with the others.

To be clear, I could not make the same comment about Apple or Amazon businesspeople. While they may exhibit their own stigmatic qualities, they are, IME, different. Nothing like Microsoft.

Microsoft does not suffer from "delusions of grandeur". It achieved grandeur a long time ago, and then became delusional. Currently, it is either #1 or #2 on the list of the world's wealthiest companies. Comments suggesting that the company has "changed", and such comments have been popular on HN in recent years, are quite amusing.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#210

Earlier quoted context omitted.

Because as far as I can tell, there was no "vulnerability" here, it's just how the product works. Stealing an OAuth key is just as bad. Stealing a domain's krbtgt key is just as bad. Businesses want that when they login to a computer, they are SSO'ed in to all their apps. That's how ADFS works, you authenticate to it using kerberos and it issues you a SAML token. Here they stole apparently the key used to sign the SA…

>Stealing an OAuth key is just as bad What is an "OAuth key"? Do you mean an OAuth token? No, Golden SAML is worse than stealing an OAuth token, because an OAuth token is valid for 1 user, but Golden SAML can be used to impersonate any user. Also, OAuth tokens expire, but Golden SAML doesn't expire (although if you steal an OAuth refresh token, that won't expire). >I fail to see how in this particular incident its Mi…

> "disabling seamless SSO"

It is never going to happen in the corporate. Never.

Post reply on HN