Live data from Hacker News

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

trustedsec.com

91–100 of 116 posts

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#91
post #25

Earlier quoted context omitted.

They still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that. I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.

It's true, they lied. But, paradoxically, in this case, while they lied about details, the conclusion is still true: Azure is very far from AWS and GCP as far as security is concerned. I have my own suspicions why it is so, but the reasons are not important, what counts is the final conclusion: if you really care for security, you'd better chose one of the other two.

[flagged]

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#92

Earlier quoted context omitted.

Europeans bizarrely love Azure.

As a European, you’re on your own there…

I see azure in more European job ads (and .net) than I ever did in California…

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#93
post #71

Earlier quoted context omitted.

Europeans bizarrely love Azure.

from my experience it's more of a business guy/executive thing, they see Microsoft as a reliable, low-risk vendor which can speak their language. "nobody ever got fired for buying IBM" type thing

I figured they were risk averse and picking based on name familiarity.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#94

Puts me in mind of this scathing report from CISA on how a state-sponsored group broke into Microsoft and then into the State Department and a bunch of other agencies. Reads like a heist movie. https://www.cisa.gov/sites/default/files/2024-03/CSRB%20Revi... What I found most incredible about the story is that it wasn't Microsoft who found the intrusion. It was some sysadmin at State who saw that some mail logs did no…

Azure security has been a joke since like ever. Its incredible how they managed to start from scratch, and still brought into their Cloud, the same issues they had in Windows since inception. Only Cloud to have not one, but two security events, that broke isolation barriers between tenants...

"Azure's Security Vulnerabilities Are Out of Control" - https://www.lastweekinaws.com/blog/azures_vulnerabilities_ar...

"Microsoft comes under blistering criticism for “grossly irresponsible” security" - https://arstechnica.com/security/2023/08/microsoft-cloud-sec...

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#95
post #27

IIRC, (& I don't remember if I reported it), but Azure's audit logs don't reflect reality when you delete a client secret from the UI, either. If I remember the issue right, we lost a client secret (it just vanished!) and I went to the audit logs to see who dun it. According to the logs, I had done it. And yet, I also knew that I had not done it. I eventually reconstructed the bug to an old page load. I had the page…

That's crazy and a pretty good point. The human in the loop doesn't really control what gets done, it only expresses intend to the frontend.

[dead]

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#96
post #65
post #10

Earlier quoted context omitted.

Don't worry CISA and any other involved regulator were gutted by DOGE.

Is that true or you’re just assuming it’s so?

I definitely remember DOGE gutting CISA. Other cuts were not always due to DOGE. A good chunk of the FBI's computer security and counter intelligence people got reassigned to immigration enforcement. The committee investigating the US cell network hacks got cut extensively but I don't remember who did it.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#97

Earlier quoted context omitted.

Isn't it an age thing mostly? Younger admins hate Microsoft with a passion it seems to me. Or is just my circle of acquaintances?

Europeans bizarrely love Azure.

I guess it's not so much Europe but "non IT-core companies" might prefer it, also the convenience of having everything into the same bill (workstation licenses, cloud, etc)

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#98

There's a big tradeoff here though: IT admins really love buying Microsoft. And when the dog tries to complain about the dogfood, the dogfood purchaser tends to not understand very well.

They don’t LOVE but they don’t have other options.

I’m at some legacy business that depends on some .Net Framework LOB application, some random SaaS web software along with usual office stuff. I need to manage Windows machines, identity for everyone include integration with random SaaS web software and enforce random policies that Security swears if I don’t, we fail PCI audit and that business ending. Oh yea, our funding and salaries for department wouldn’t cover one scrum team at FAANG. What is my solution, go!

For most, they default to Microsoft solution because it works well enough to collect meager paycheck and go home.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#99
post #72

The state of cyber-security is a joke given that the entirety of civilization depends on these systems to function. It's like we transferred all our stuff into a boat with a gaping hole in the bilge plugged with a wad of duct tape and started sailing towards the open ocean. Forget putting the cart before the horse, the old mare is still in the barn and cart is about 3 counties over, upended in a ditch.

Worse yet the industry insists you can fix the hole by putting more guard towers with machine gun nests on the deck

I thought they want to fix these by adding a A4 sheet with text "Do not break!". Surely people won't just walk in, when asked nicely. At least any nice, law abiding people. I guess others are envouraged to walk in, then.
Post reply on HN