Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

1–10 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#4
post #2

Will someone accuse Microsoft of publishing vulnerable software?

The issue is not that a random guy on the internet hacks the software, but a _state_ actor.

The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft.

I feel bad for the admins who are stuck with these systems.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#5
They are making accusations on China based on "educated" guesswork. The smoking gun is missing to "prove" provenance and attribution. In fact that is incredibly hard to prove.

In Stuxnet for example, the alleged perpetrators hinted that they were behind it.

Will the same countries and allies now condemn known, disclosed and proven cyberattacks sourced from other countries (with known state involvement and complicity) on activists and journalists that lead to imprisonment and death?

And Microsoft has a very long history of vulnerabilities and hiding it. And then they will refuse to patch known vulnerabilities in lower versioned software trying to force large customers to do unwanted version upgrades and to adopt the more expensive SaaS offerings.

They are now trying to force all customers off of the already paid for and cheaper on-prem Microsoft Exchange which is still the dominant software in the directory services market and trying to get all corporates onto Azure AD.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#7
post #4

Earlier quoted context omitted.

The issue is not that a random guy on the internet hacks the software, but a _state_ actor.

The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft. I feel bad for the admins who are stuck with these systems.

So you think that a Linux mail server is unhackable for a state actor?

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#8
post #2

Will someone accuse Microsoft of publishing vulnerable software?

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

If the property management company demanded that I use Insecure Brand locks on my front door, I'd have an issue with that. Of course that wouldn't excuse the robbers, but continuing to use Insecure Brand locks wouldn't be advisable. I'd also take exception if IB Locks or the property management company marketed themselves as a security oriented company.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#9
post #2

Will someone accuse Microsoft of publishing vulnerable software?

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility.

(Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the driving force behind buying security measures is not the (unlikely) possibility of being a victim of a break-in, but the (more likely) possibility of not getting insurance to cover it.)

Post reply on HN