Live data from Hacker News

Microsoft Teams: 1 feature, 4 vulnerabilities

positive.security

11–20 of 264 posts

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#11
> We reported the issues to Microsoft in March 2021, who has only remediated one so far

I feel that I read something like this almost every single time Microsoft is mentioned in a vulnerability disclosure. What makes the company so bad at dealing with security reports? I don't expect it to be a lack of talents or resources, or is it?

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#12
post #4
post #3

Earlier quoted context omitted.

Make all software which isn't released as open source liable for the cost of security breaches?

great way to not have any software released ever

Somehow we still have medicine (they do a lot of testing before they release anything!) and doctors (they have insurance!).

It would increase the barrier to releasing software massively (possibly killing the startup scene altogether), but it doesn't mean software development would end.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#13
One in this temperament: try accidently pasting a very large amount of data in the chatbox in Teams. Then spend the next 40 minutes re-starting Teams to try to remove the data from said box while your laptop tries to fly away and Teams keeps many processors and gigs of memory lit trying to parse your data.

Microsoft should (but won't) reconsider the idea that one chatbox to rule many underlying types of software is a good idea.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#15
I think the first vulnerability could also lead to a DoS if they point the server to its own lookup route?

Also sad to see how Microsoft is treating security researchers, instead of thanking them with a small bug bounty. Especially for the one (or maybe two) DoS vulns

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#16
post #4
post #3

Earlier quoted context omitted.

Make all software which isn't released as open source liable for the cost of security breaches?

great way to not have any software released ever

Parent suggested free software would be the exception to this rule. Personally, i don't understand why it's even legal to publish binary code without the corresponding source, but at least their point made sense: volunteer-run projects need to be exempted from such regulation, and there's exactly zero reason a volunteer-run project should not be free-software.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#17
In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked.

This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management.

This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leave a room password unprotected bad people will enter". The level of press coverage was off the scale compared to what Teams got for far worse issues.

The vulnerabilities werent nothing but they werent even in the same ballpark as the MS teams vulnerabilities foisted on us for "security reasons" like this howler they tried to cover up https://www.techradar.com/news/microsoft-may-have-downplayed...

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#18
post #10

Still waiting for these guys to update their MacOS app, we use it in our company and it's so bad that our own team uses Slack.

Not to mention it's an Intel only binary, what's the point of using these dreadful electron cross-platform apps if they can't even be built as universal binaries.

I know right? Plus MS Teams is the among the most used apps in the enterprise world how come the only good version of it is only available in Windows 11 where most workplaces aren't even pushing it to their users.

The way Microsoft handles Teams annoys the crap out of me the MacOS and Linux versions are left to die basically.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#19
post #11

> We reported the issues to Microsoft in March 2021, who has only remediated one so far I feel that I read something like this almost every single time Microsoft is mentioned in a vulnerability disclosure. What makes the company so bad at dealing with security reports? I don't expect it to be a lack of talents or resources, or is it?

Their SOC Team for consumer/prosumer oriented apps is terrible. I knew someone working there that left to join the Azure team within the company so go figure...

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#20
post #10

Earlier quoted context omitted.

Not to mention it's an Intel only binary, what's the point of using these dreadful electron cross-platform apps if they can't even be built as universal binaries.

I know right? Plus MS Teams is the among the most used apps in the enterprise world how come the only good version of it is only available in Windows 11 where most workplaces aren't even pushing it to their users. The way Microsoft handles Teams annoys the crap out of me the MacOS and Linux versions are left to die basically.

It is (by far) the most horrific piece of software I'm forced to used, the UI/UX is confusing, it's a battery killer, eats all the ram (though - that's common with all electron garbage), it somehow manages to make Bluetooth headsets drop out, it significantly impacts network performance when sharing video, a lot of bugs in the calendaring system.... I could go on, but damn I just hate it.
Post reply on HN