Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

231–240 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#231

Earlier quoted context omitted.

Wait a minute. It is owned by Microsoft.

Ctrl + Shift + Alt + Windows Key + L

Does this really work? It’s so awful.

https://www.pcgamer.com/ctrlshiftaltwinl-is-the-most-cursed-...

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#232

Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for any MSA / Azure AD / Government AD user. They downplayed the severity. Just imagine if that level of access was used to pull a Stryker on a nation-wide scale. That is an economic disaster waiting to happ…

Oh please, that could happen at any company. Humans screw up.

Any company where this happens is being mismanaged.

The whole point of having companies is to overcome limitations of humans acting individually.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#233
post #67

Earlier quoted context omitted.

I love https://github.com/lucagrulla/cw , it's like tail for cloudwatch. It's super fast.

That's great but that's not really the problem. The real problem is Amazon likes to release services that depend on other services, but leave the integration work to us. I'm convinced Amazon has many teams crapping out new features but they don't have the political clout (or manpower) to create a comprehensive product. They are mandated by management to use existing services, and thus we the users suffer because we h…

Which ones are a good example of how things could be?

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#234
post #54

Earlier quoted context omitted.

It is also the only SSO flow I have ever seen that fundamentally cannot work if you have more than one account remembered on your device. So far the only way I’ve found to get it to let you log out of account A and then log into account B is to clear all cookies otherwise it gives you permission denied errors. Have no idea how it can be this horrible

Would container tabs solve that? They're pitched as helping separate work and personal logins.

I am not sure how, but at one point even private browser mode would still have me logged in to Entra ID. Couldn’t log out of main browser and same session would follow me to private.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#236

The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't…

As a Microsoftie of more than a decade... Yeah, I see this. We have an internal system called Cosmos[0] that does a great job of processing huge quantities of data very fast. And we sat on it for years while the rest of the industry moved to Spark and its derivatives. We finally released it as Azure Data Lake Analytics (ADLA) but did a shit job of supporting/promoting it. We built Synapse, and it's garbage. We've now…

Make it 7, there's also the Sentinel datalake or whatever now!

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#237

Earlier quoted context omitted.

> Not criticizing FedRAMP Think it's very important to criticize FedRAMP. The FedRAMP board is extremely slow moving and continuously disregards industry feedback. As a result, FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave. This has a sticker p…

> FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave Having been through FedRAMP twice, I can this is absolute fiction. What does Palantir have to do with anything?

Palantir FedStart is a new program, and a quick look at the FedRAMP marketplace will show you there are literally 0 tech startups listed that are there without jumping on Palantir’s ATO. I find it difficult to believe you have been through FedRAMP twice but would declare something as ‘absolute fiction’ when it can be easily proven

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#238
post #40

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?

Speaking of redirects, I haven't been able to use Outlook 365 in Firefox for years – every single time I get redirect after redirect, only to then end up on yet another log-in screen. Meanwhile, in Chromium-based browsers everything works fine.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#239

Earlier quoted context omitted.

> Not criticizing FedRAMP Think it's very important to criticize FedRAMP. The FedRAMP board is extremely slow moving and continuously disregards industry feedback. As a result, FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave. This has a sticker p…

> Going through FedRAMP yourself requires a staff who is willing to put in a dedicated effort on the compliance paperwork But couldn’t you say the same for CMMC 2.0, NIST 800-171, RMF, JSIG, STIG, etc?

I am, CMMC 2.0 requires and is essentially satisfied by FedRAMP Moderate, and NIST 800-171 is a subset of FedRAMP. Notably both CMMC and FedRAMP were met with immense criticism from industry which was mostly ignored.

It would be better to compare this to commercial, like SOC 2, which is achievable even for small startups without much effort and on much more affordable budgets.

Notably SOC 2 full service is $20k including tooling (Vanta + Workstreet + audits), NIST is $20-30k (Vanta + partners), while FedRAMP is $500k-1M (Coalfire) just for implementation before getting into tooling and audits.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#240

Earlier quoted context omitted.

> FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave Having been through FedRAMP twice, I can this is absolute fiction. What does Palantir have to do with anything?

Palantir FedStart is a new program, and a quick look at the FedRAMP marketplace will show you there are literally 0 tech startups listed that are there without jumping on Palantir’s ATO. I find it difficult to believe you have been through FedRAMP twice but would declare something as ‘absolute fiction’ when it can be easily proven

We obtained an ATO in our own right, which is slow but otherwise really not that hard.
Post reply on HN