Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

111–120 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#111
post #54

Earlier quoted context omitted.

It is also the only SSO flow I have ever seen that fundamentally cannot work if you have more than one account remembered on your device. So far the only way I’ve found to get it to let you log out of account A and then log into account B is to clear all cookies otherwise it gives you permission denied errors. Have no idea how it can be this horrible

Would container tabs solve that? They're pitched as helping separate work and personal logins.

I just run completely separate browser profiles to separate work and personal stuff. And I still sometimes need private mode or a throwaway profile to get some random thing to work.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#112

Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for any MSA / Azure AD / Government AD user. They downplayed the severity. Just imagine if that level of access was used to pull a Stryker on a nation-wide scale. That is an economic disaster waiting to happ…

Oh please, that could happen at any company. Humans screw up.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#113
post #56

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

The problem is modern MS doing three contradictory things at the same time: - FB's move fast and break things . Constantly launching new libs. - Linus's we do not break user space . Great commitment to backwards compatibility. - Never deprecating dead products until they've been de facto abandoned for like decades. This combination means every MS product is a labyrinth of overlapping APIs with no guidance as to which…

Well said. It feels like Microsoft is willing to release the intern’s poorly thought out product, and then commits to support the garbage design for all time.

Microsoft, you are a behemoth. There are few domains where you actually compete. Give your products a minute to breath before you cast them in stone.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#116

It's not very clear from the article, but I get the feeling from the context that the 'pile of shit' quote referenced the package of documentation about the service rather than the service itself. (That seems to be the main complaint, that Microsoft never provided the clear information required to conduct the assessment properly).

> The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica. > > Or, as one member of the team put it: “The package is a pile of shit.”

Yes, it seems pretty clear from that quote that the reviewer said the security package was a `pile of shit`, and propublica went on to extend that to the cloud itself. Not that I want to comment on the merits of Azure's security, but that sounds pretty clickbaity from propublica to me. A more appropriate title would have been

> Federal Cyber Experts Thought Microsoft’s Cloud Security documentation Was “a Pile of Shit.”

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#117
post #99

The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't…

I sometimes wonder if I would feel the same about AWS if I hadn’t already invested a significant amount of time learning the entire ecosystem, nomenclatures, patterns/best practices, etc.

As someone who has worked with all three in many capacities, as is the worst by a mile. Don’t get me wrong. They are all very bad, but Azure is the king of shit.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#118
This is my opinion only, I'm sure some have had different experiences - but:

Azure's success as a cloud provider is mostly a result of their sales team and having an existing relationship with non-technical leadership. "We already pay them for Office and Exchange, let's just buy this new 'cloud' thing from them too".

Azure is barely considered an option at all within tech companies, yet is surprisingly widely adopted by non-technical companies that don't know any better (ie, that don't have a technical / engineering voice or representation within leadership).

AWS = Likely technically the best, for now. Mostly unreasonable pricing, and less motivation to seriously negotiate given they are the 'default' cloud provider for most of the industry. Kind of feels like they have peaked though, and are slipping more recently. Inevitable, or bad leadership changes?

OCI = New-comer, attractive pricing and hungry for business. Might be able to avoid mistakes other providers have made? Reliability struggles though. Parent company has a bad reputation in some circles - but probably not with decision makers. Making huge (unwise?) investments - that will either come crashing down in 5 years, or seriously pay off. Layoffs, but going for massive growth...huh?

GCP = Notably different underlying technical choices than other providers. Folks are maybe a bit less pragmatic, and more academic. This helps them in unique services (Spanner?) but hurts in most other areas. They've matured, and are btwn AWS and OCI in reliability. They are probably not as hungry for business as they should be given how far behind they are.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#119
Suddenly everyone on HN is an expert on Azure infrastructure.

it isn't the best but it's really great at a lot of things feature-wise. top-notch documentation as well (despite what these "experts" said).

Most companies literally run on Azure these days. Persistent hackers will get into any network, that's a guarantee, that's APT 101. It's law of averages. If it truly is "a pile of shit" given how it is probably the most used cloud platform by the most customers, including governments, and endless plethora of features and services it offers, shouldn't there be more compromises? 2-3 in a decade is hardly above what you expect for law of averages right?

Screw ups happen, but if it is systemic, you can't use one instance as evidence, you must establish a pattern of mishaps.

Post reply on HN