Earlier quoted context omitted.
They still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that. I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.
It's true, they lied. But, paradoxically, in this case, while they lied about details, the conclusion is still true: Azure is very far from AWS and GCP as far as security is concerned. I have my own suspicions why it is so, but the reasons are not important, what counts is the final conclusion: if you really care for security, you'd better chose one of the other two.
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
91–100 of 116 posts
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#92Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#93Earlier quoted context omitted.
Europeans bizarrely love Azure.
from my experience it's more of a business guy/executive thing, they see Microsoft as a reliable, low-risk vendor which can speak their language. "nobody ever got fired for buying IBM" type thing
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#94Puts me in mind of this scathing report from CISA on how a state-sponsored group broke into Microsoft and then into the State Department and a bunch of other agencies. Reads like a heist movie. https://www.cisa.gov/sites/default/files/2024-03/CSRB%20Revi... What I found most incredible about the story is that it wasn't Microsoft who found the intrusion. It was some sysadmin at State who saw that some mail logs did no…
"Azure's Security Vulnerabilities Are Out of Control" - https://www.lastweekinaws.com/blog/azures_vulnerabilities_ar...
"Microsoft comes under blistering criticism for “grossly irresponsible” security" - https://arstechnica.com/security/2023/08/microsoft-cloud-sec...
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#95IIRC, (& I don't remember if I reported it), but Azure's audit logs don't reflect reality when you delete a client secret from the UI, either. If I remember the issue right, we lost a client secret (it just vanished!) and I went to the audit logs to see who dun it. According to the logs, I had done it. And yet, I also knew that I had not done it. I eventually reconstructed the bug to an old page load. I had the page…
That's crazy and a pretty good point. The human in the loop doesn't really control what gets done, it only expresses intend to the frontend.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#96Earlier quoted context omitted.
Don't worry CISA and any other involved regulator were gutted by DOGE.
Is that true or you’re just assuming it’s so?
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#97Earlier quoted context omitted.
Isn't it an age thing mostly? Younger admins hate Microsoft with a passion it seems to me. Or is just my circle of acquaintances?
Europeans bizarrely love Azure.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#98There's a big tradeoff here though: IT admins really love buying Microsoft. And when the dog tries to complain about the dogfood, the dogfood purchaser tends to not understand very well.
I’m at some legacy business that depends on some .Net Framework LOB application, some random SaaS web software along with usual office stuff. I need to manage Windows machines, identity for everyone include integration with random SaaS web software and enforce random policies that Security swears if I don’t, we fail PCI audit and that business ending. Oh yea, our funding and salaries for department wouldn’t cover one scrum team at FAANG. What is my solution, go!
For most, they default to Microsoft solution because it works well enough to collect meager paycheck and go home.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#99The state of cyber-security is a joke given that the entirety of civilization depends on these systems to function. It's like we transferred all our stuff into a boat with a gaping hole in the bilge plugged with a wad of duct tape and started sailing towards the open ocean. Forget putting the cart before the horse, the old mare is still in the barn and cart is about 3 counties over, upended in a ditch.
Worse yet the industry insists you can fix the hole by putting more guard towers with machine gun nests on the deck
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#100Is this a bad move? What should I tell them?