Microsoft Chose Profit over Security, Whistleblower Says
251–260 of 318 posts
Re: Microsoft Chose Profit over Security, Whistleblower Says
#252Earlier quoted context omitted.
>Stealing an OAuth key is just as bad What is an "OAuth key"? Do you mean an OAuth token? No, Golden SAML is worse than stealing an OAuth token, because an OAuth token is valid for 1 user, but Golden SAML can be used to impersonate any user. Also, OAuth tokens expire, but Golden SAML doesn't expire (although if you steal an OAuth refresh token, that won't expire). >I fail to see how in this particular incident its Mi…
> "disabling seamless SSO" It is never going to happen in the corporate. Never.
And Microsoft themselves advised customers to disable it after Solarwinds.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#253Re: Microsoft Chose Profit over Security, Whistleblower Says
#254Earlier quoted context omitted.
>Stealing an OAuth key is just as bad What is an "OAuth key"? Do you mean an OAuth token? No, Golden SAML is worse than stealing an OAuth token, because an OAuth token is valid for 1 user, but Golden SAML can be used to impersonate any user. Also, OAuth tokens expire, but Golden SAML doesn't expire (although if you steal an OAuth refresh token, that won't expire). >I fail to see how in this particular incident its Mi…
I think there is too much confusion in the details of the actual attack. You have to steal the private key for the SAML signing certificate for an app. The correct answer would be to scope any token to only have access to what the app has access to, the second layer which is documented in their 2020 article, is to require mfa on admin actions, and the 3rd layer is to disconnect azure admin accounts from on-prem admin…
>In the immediate aftermath of the attack, Microsoft advised customers of Microsoft 365 to disable seamless SSO in AD FS and similar products — the solution that Harris proposed three years earlier.
And did Microsoft advise those other solutions prior to Solarwinds happening?
Re: Microsoft Chose Profit over Security, Whistleblower Says
#255Earlier quoted context omitted.
Would that be securities fraud, because they're lying to investors? (Going by Matt Levine's "everything is securities fraud" logic here to see if that might actually change behavior…)
I think securities law usually only applies to things you tell investors? I could be wrong here though, I am not a lawyer.
Re: Microsoft Chose Profit over Security, Whistleblower Says
#256The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…
Re: Microsoft Chose Profit over Security, Whistleblower Says
#257The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…
These systems are lot safer after regulations were put in place however onerous and ineffective they seem
Re: Microsoft Chose Profit over Security, Whistleblower Says
#258Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…
So software developers should be criminally liable for introducing security bugs?
Re: Microsoft Chose Profit over Security, Whistleblower Says
#259The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…
This is exactly it. There is no incentive to prioritise security. It is not visible to customers, except in terms of compliance, most likely a check-list approach. I think it needs a massive cultural shift, but from customers. If customers were willing to evaluate security (consumers cannot, but enterprise can) properly, demand binding assurances, and make buying choices accordingly industry would respond. Of course…
Many big, famous firms (especially Microsoft) would not exist
Re: Microsoft Chose Profit over Security, Whistleblower Says
#260Earlier quoted context omitted.
So software developers should be criminally liable for introducing security bugs?
Management that knowingly chooses to ignore a major issue should be charged with criminal negligence. The creation of the bug is a common and difficult to avoid mistake. But once it has been found, choosing not to change it despite being warned if the consequences makes you responsible for those consequences.