Live data from Hacker News

Microsoft Chose Profit over Security, Whistleblower Says

propublica.org

251–260 of 318 posts

Re: Microsoft Chose Profit over Security, Whistleblower Says

#252

Earlier quoted context omitted.

>Stealing an OAuth key is just as bad What is an "OAuth key"? Do you mean an OAuth token? No, Golden SAML is worse than stealing an OAuth token, because an OAuth token is valid for 1 user, but Golden SAML can be used to impersonate any user. Also, OAuth tokens expire, but Golden SAML doesn't expire (although if you steal an OAuth refresh token, that won't expire). >I fail to see how in this particular incident its Mi…

> "disabling seamless SSO" It is never going to happen in the corporate. Never.

The article says Andrew Harris worked with the NYPD to disable it for their setup.

And Microsoft themselves advised customers to disable it after Solarwinds.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#254

Earlier quoted context omitted.

>Stealing an OAuth key is just as bad What is an "OAuth key"? Do you mean an OAuth token? No, Golden SAML is worse than stealing an OAuth token, because an OAuth token is valid for 1 user, but Golden SAML can be used to impersonate any user. Also, OAuth tokens expire, but Golden SAML doesn't expire (although if you steal an OAuth refresh token, that won't expire). >I fail to see how in this particular incident its Mi…

I think there is too much confusion in the details of the actual attack. You have to steal the private key for the SAML signing certificate for an app. The correct answer would be to scope any token to only have access to what the app has access to, the second layer which is documented in their 2020 article, is to require mfa on admin actions, and the 3rd layer is to disconnect azure admin accounts from on-prem admin…

If all those other solutions are better, why does the article say this:

>In the immediate aftermath of the attack, Microsoft advised customers of Microsoft 365 to disable seamless SSO in AD FS and similar products — the solution that Harris proposed three years earlier.

And did Microsoft advise those other solutions prior to Solarwinds happening?

Re: Microsoft Chose Profit over Security, Whistleblower Says

#255
post #62

Earlier quoted context omitted.

Would that be securities fraud, because they're lying to investors? (Going by Matt Levine's "everything is securities fraud" logic here to see if that might actually change behavior…)

I think securities law usually only applies to things you tell investors? I could be wrong here though, I am not a lawyer.

[deleted]

Re: Microsoft Chose Profit over Security, Whistleblower Says

#256

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

I read a quote once that a CISO's job was to do enough public talks that when their company inevitably got popped because nobody values security, they've got their next job lined up already.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#257

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

There is nothing wrong with processes per se, From civil engineering to automotive to aviation there is a tangible outcome to all the laborious audits and paperwork.

These systems are lot safer after regulations were put in place however onerous and ineffective they seem

Re: Microsoft Chose Profit over Security, Whistleblower Says

#258
post #47

Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue beca…

So software developers should be criminally liable for introducing security bugs?

Management that knowingly chooses to ignore a major issue should be charged with criminal negligence. The creation of the bug is a common and difficult to avoid mistake. But once it has been found, choosing not to change it despite being warned if the consequences makes you responsible for those consequences.

Re: Microsoft Chose Profit over Security, Whistleblower Says

#259
post #83

The misaligned incentives between security and profit, especially in public companies, is not really a fixable problem without a massive cultural shift. I'm not sure at this point what could even trigger one. I've always dabbled in cybersecurity, taking on the hat in various roles over the years but have refused to go full time into it due to what I have personally seen in the industry - an overwhelming focus on comp…

This is exactly it. There is no incentive to prioritise security. It is not visible to customers, except in terms of compliance, most likely a check-list approach. I think it needs a massive cultural shift, but from customers. If customers were willing to evaluate security (consumers cannot, but enterprise can) properly, demand binding assurances, and make buying choices accordingly industry would respond. Of course…

> If customers were willing to evaluate security

Many big, famous firms (especially Microsoft) would not exist

Re: Microsoft Chose Profit over Security, Whistleblower Says

#260
post #258

Earlier quoted context omitted.

So software developers should be criminally liable for introducing security bugs?

Management that knowingly chooses to ignore a major issue should be charged with criminal negligence. The creation of the bug is a common and difficult to avoid mistake. But once it has been found, choosing not to change it despite being warned if the consequences makes you responsible for those consequences.

So if send an email "Fix all your bugs or else bad stuff will happen", and if they don't fix all their bugs now I can put their devs in jail ?
Post reply on HN