Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

51–60 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#51
The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't matter. To even think about using the product, you need to learn way more about the larger Azure ecosystem than you ever bargained for, and of course deal with Microsoft products that do not really integrate well because the teams don't talk to each other. Log formats, conventions, everything will be different as you float around to different parts of Azure. Basic security concepts, such as a SIEM will be implemented in such strange ways that you wonder if Microsoft has any idea what a SIEM even is.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#52
post #40

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?

I've always assumed the billions of redirects are setting cookies so all the various systems "work" but I have given up trying to understand it.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#53

The government does most things poorly and with little regard to budget or quality. They can't solve problems that are much simpler than cloud computing, so why should I expect them to perform better at a more complex problem?

I think this perspective has resolutely been debunked at this point.

The government has historically, routinely, consistently, solved problems more complex than cloud computing.

The only way you'd think otherwise is if you had some other motivation to pretend otherwise... some sort of ideology.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#54
post #40

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?

It is also the only SSO flow I have ever seen that fundamentally cannot work if you have more than one account remembered on your device. So far the only way I’ve found to get it to let you log out of account A and then log into account B is to clear all cookies otherwise it gives you permission denied errors. Have no idea how it can be this horrible

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#55
post #47

Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for any MSA / Azure AD / Government AD user. They downplayed the severity. Just imagine if that level of access was used to pull a Stryker on a nation-wide scale. That is an economic disaster waiting to happ…

I'll do you one better: stealing the signing key was not even necessary. https://www.bleepingcomputer.com/news/security/microsoft-ent...

I knew there was another incident that I was forgetting, insanity... I don't understand how Microsoft keeps getting away with this and everyone just forgets.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#56

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

The problem is modern MS doing three contradictory things at the same time:

- FB's move fast and break things. Constantly launching new libs.

- Linus's we do not break user space. Great commitment to backwards compatibility.

- Never deprecating dead products until they've been de facto abandoned for like decades.

This combination means every MS product is a labyrinth of overlapping APIs with no guidance as to which one is actually the good one. Some are abandoned garbage, some are brand new and incomplete, and some are both, and there's no way of knowing which are which even experts can mislead you.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#58

The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't…

Azure is the color of the face you have after Microsoft beats you with your own wallet. They don’t want to give you access to anything, they want to own it and make you pay for it.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#60
This fits perfectly with traditional Microsoft strategies of getting a foot in the door and then having the users’ internal pressure on the organization to help get the Microsoft product established.

Decades ago, Lotus 1-2-3 on top of MSDOS was the lever; today it’s GCC High.

Post reply on HN