Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

101–110 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#101

Earlier quoted context omitted.

> Everything feels evolutionary. That's total "normal" for Microsoft at least from 2018, the year I started working with some of their products (Power BI mostly). They adopted a development model that is early release, fast iteration, and users as testers. No wonder everything feels experimental until much later. Back then I just couldn't use Power BI. But fast forward a few years, I think it got a lot better since m…

> You just have to stick with it for a few years. So, you have to be a paying tester? Incredible that MS can keep enough businesses as hostage to be able to operate like that.

[deleted]

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#103
post #98

Earlier quoted context omitted.

Absolute contempt for their users at every level. It’s so transparent. This is the end game of anticompetitive practices for decades— they just don’t have to try anymore… for now. Some day they’ll either have to compete in good faith or sink. I doubt that will happen soon, but someday.

It's hard to argue against contempt but... I'm gonna try. It feels like at the end of the line it's just a checkbox someone gets without having to consider the consequences of the changes. Either it's too big or there's too many levels where decisions get made and handed down to drones (or AI), but the people who decide seem to have no concept of what their products are used for and the people who implement features…

Microsoft was always afraid of being IBM. They are more IBM than IBM.

When they started flying people in the beg that I buy 100 Surface Laptops, that was the confirmation of everything I had been thinking. All I could think of was IBM flying a dude from Italy in to talk for 15 minutes about their version of TeamViewer back in the day. We ended up talking about shoes.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#104
post #54
post #40

Earlier quoted context omitted.

Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?

It is also the only SSO flow I have ever seen that fundamentally cannot work if you have more than one account remembered on your device. So far the only way I’ve found to get it to let you log out of account A and then log into account B is to clear all cookies otherwise it gives you permission denied errors. Have no idea how it can be this horrible

Would container tabs solve that? They're pitched as helping separate work and personal logins.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#107
post #47

Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for any MSA / Azure AD / Government AD user. They downplayed the severity. Just imagine if that level of access was used to pull a Stryker on a nation-wide scale. That is an economic disaster waiting to happ…

I'll do you one better: stealing the signing key was not even necessary. https://www.bleepingcomputer.com/news/security/microsoft-ent...

because time to market is more important than security (at microsoft)

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#108
post #95

Earlier quoted context omitted.

Ugh this sounds like when I worked at Oracle/OCI. Some environments required a VPN, some a jumpbox, and some required logging into a virtual desktop, and then logging into a jumpbox. Just thinking about it gives me PTSD

any sufficiently large organization that is around for a decade or two trends towards spaghetti-access

Yup, same boat here (mid-size company).

All the corporate stuff is behind Okta, so that easy enough.

But all the dev/test systems are a mix of SSO, individual logins, etc. At least they're all behind the same VPN (except when they aren't, but that's less common).

And of course, if you're a cloud engineer (vs "normal" software engineer), you also have to deal with AWS access, which is a whole different can of worms.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#109

Earlier quoted context omitted.

> Everything feels evolutionary. That's total "normal" for Microsoft at least from 2018, the year I started working with some of their products (Power BI mostly). They adopted a development model that is early release, fast iteration, and users as testers. No wonder everything feels experimental until much later. Back then I just couldn't use Power BI. But fast forward a few years, I think it got a lot better since m…

I worked at a hospital in that timeframe and they rolled out Teams. Up until they, shadow IT teams were running Slack just fine. Man, what a horrendous pile of crap Teams was back then. The Slack teams were griping that they should just buy Slack, but Teams was the "enterprise solution." The problems were amplified during remote COVID work. Teams is fine now, but how many corporations went through years of frustratio…

Yeah that's the thing. Management who made the deals are never put into that frustration, or very rarely, and I always wonder, at least for the big corporations, if there is any greasy palms...

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#110

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

That’s Microsoft. 1000s of features and none of them really work the way they are supposed to.

it's "Enterprise" grade software! need to check the boxes for the procurement process (actually working is a separate department)
Post reply on HN