Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

31–40 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#32

The government does most things poorly and with little regard to budget or quality. They can't solve problems that are much simpler than cloud computing, so why should I expect them to perform better at a more complex problem?

Basically false. They're better at health care. Better at education. Better at feeding people. Better at charity.

Theres no need to be THIS cynical.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#33
Is this just a case of MS needing to merge a lot of platforms, and there are gaps and overlaps.?

Maybe the critical question, are they making continuing improvements? Especially to merge conflicting functions.

Like when they bought Minecraft, or Skype. Each already had user management. Xbox was a mess. Merging them all took a lot of years.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#34
Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying.

I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for any MSA / Azure AD / Government AD user. They downplayed the severity. Just imagine if that level of access was used to pull a Stryker on a nation-wide scale. That is an economic disaster waiting to happen.

[1] https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#35

Frustrating that FedRAMP is both a pain to get compliant with and also apparently is not a strong signal of actual security.

I see you've never worked in a compliance environment before.

And may such evil days never come to past

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#38

Azure is easily the most expensive, least reliable and worst cloud available. It's borderline scam. An example today, I provisioned high IOPS SSDs (supposedly) and what is actually connected to the instance? A spinning hard drive! I didn't even know they were still made, but I guess Azure uses them and scams their users into thinking you're getting an SSD for $700/mo when its really an old hard drive. I would warn an…

I’d love to see proof of your claim that they provisioned a hard disk when you requested an SSD, or, at the very least, tests that showed that the IOPS you requested were not delivered. Can you show us the receipts?

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#39
post #29

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

Same here, except with Minecraft and XBox One. I don’t understand how they have non-zero market share.

For Minecraft they inherited a gigantic userbase from Mojang and then made it 10x harder to add new users.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#40

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?
Post reply on HN