Live data from Hacker News

Data accidentally exposed by Microsoft AI researchers

wiz.io

11–20 of 238 posts

Re: Data accidentally exposed by Microsoft AI researchers

#11
post #4

Just proves how hard it cloud security now. 1-2 mistake and you expose TB's. Insane.

My wife and I just rewatched WarGames for the millionth time a few nights ago. The level of cybersecurity incompetency in the early 80's makes sense; computers (and in particular networked computers) were still relatively new, and there weren't that many external users to begin with, so while the potential impact of a mistake was huge (which of course was the plot of the movie), the likelihood of a horrible thing hap…

> Cybersecurity protocols are of course much more mature now

At technical level, sure. At the deployment, configuration and management level, not quite. Overall things are so bad that news aren't even reporting the hospitals taken over by ransomware anymore. It's still happening almost every week and we're just... used to it.

Re: Data accidentally exposed by Microsoft AI researchers

#12
post #5

Part of me thought "this is fine as very few could actually download 38TB". But that's not true as it's just so cheap to spin up a machine and some storage on a Cloud provider and deal with it later. It's also not true as I've got a 1Gbps internet connection and 112TB usable in my local NAS. All of a sudden (over a decade) all the numbers got big and massive data exfiltration just looks to be trivial. I mean, obvious…

How do you have your NAS configured? The more specifics, the better; I’ve wanted one.

Do you worry about failure? In your hardware life I mean, not your personal life.

Re: Data accidentally exposed by Microsoft AI researchers

#13
> This case is an example of the new risks organizations face when starting to leverage the power of AI more broadly, as more of their engineers now work with massive amounts of training data.

It seems like a stretch to associate this risk with AI specifically. The era of "big data" started several years before the current AI boom.

Re: Data accidentally exposed by Microsoft AI researchers

#16
post #10
post #5

Part of me thought "this is fine as very few could actually download 38TB". But that's not true as it's just so cheap to spin up a machine and some storage on a Cloud provider and deal with it later. It's also not true as I've got a 1Gbps internet connection and 112TB usable in my local NAS. All of a sudden (over a decade) all the numbers got big and massive data exfiltration just looks to be trivial. I mean, obvious…

At the rack rates of $.05/GB, that’d come out to $1,945 per copy that’s downloaded. So not only do you have the breach, you also have a fat bill too.

> $.05/GB

That's just a scam rate by AWS. The true price is 1/100th of that, if that.

Re: Data accidentally exposed by Microsoft AI researchers

#17

Just proves how hard it cloud security now. 1-2 mistake and you expose TB's. Insane.

Hard coded secrets in shareable URL’s with almost infinite time windows and an untraceable ability to audit what’s made and shared and at what level? Sounds like it’s as hard as it’s always been. Pretty basic and filled with humans

I feel like it's harder.

It's no longer hierarchical, with organization schemes limited to folders and files. People no longer talk about network paths, or server names.

Mobile and desktop apps alike go to enormous effort to abstract and hide the location at which a document gets stored, instead everything is tagged and shared across buckets and accounts and domains...

I expect that the people at this organization working on cutting-edge AI are pretty sharp, but it's no surprise that they don't entirely understand the implications of "SAS tokens" and "storage containers" and "permissive access scope" on Azure, and the differences between Account SAS, Service SAS, and User Delegation SAS. Maybe the people at Wiz.io are sharper, but unless I missed the sarcasm, they may be wrong when they say [1] "Generating an Account SAS is a simple process." That looks like a really complicated process!

We just traced back an issue where a bunch of information was missing from a previous employee's projects when we changed his account to a shared mailbox. Turns out that he'd inadvertently been saving and sharing documents from his individual OneDrive on O365 (There's not one drive! There are many! Stop trying to pretend there's only one drive!) instead of the "official" organization-level project folder, and had weird settings on his laptop that pointed every "Save" operation at that personal folder, requiring a byzantine procedure to input a real path to get back to the project folder.

[1]: https://i.imgur.com/6V7VLLd.png

Re: Data accidentally exposed by Microsoft AI researchers

#18
post #4

Just proves how hard it cloud security now. 1-2 mistake and you expose TB's. Insane.

My wife and I just rewatched WarGames for the millionth time a few nights ago. The level of cybersecurity incompetency in the early 80's makes sense; computers (and in particular networked computers) were still relatively new, and there weren't that many external users to begin with, so while the potential impact of a mistake was huge (which of course was the plot of the movie), the likelihood of a horrible thing hap…

That modem setup in Wargames is still a thing for many organizations including some banks and telcos. Not naming names but I suspect the modems will be around for a very long time. Some have a password on their modem but they are usually very simple. Their only saving grace is that they are usually in front of a mainframe speaking proprietary MML that only old fuddy duddies like me would remember. There are a few of us here
Post reply on HN