Live data from Hacker News

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

trustedsec.com

111–116 of 116 posts

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#111

Earlier quoted context omitted.

Well, yeah, their agenda is reporting on fraud and illegal actions. If you do more fraud or illegal actions, you will have more stories about you. Trump does more fraud and illegal actions, objectively. If you’re a Trump supporter, reality may make you sad and angry when in conflict with the mental model. I don’t mind pension bailouts, compared to tax cuts for the very wealthy and unnecessary military action in the M…

Here’s an article on their front page today on a few thousand dollars in campaign contributions, no allegations of fraud or anything illegal: https://www.propublica.org/article/sean-duffy-michael-alfons... The Teamsters bailout was something like a million times that, from a Democratic president to a critical Democratic constituency.

Teamsters members in a majority voted for Trump. Google it. Biden helped people who didn’t value it. You blame Biden for “buying support” when it didn’t help Democrats; he did it because it was the right thing to do to protect the retirement promises made to union workers.

Can’t fix uneducated, unsophisticated voters I suppose.

https://www.theguardian.com/us-news/2024/sep/18/election-tea...

https://www.currentaffairs.org/news/sean-obrien-sold-labor-t...

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#112

Earlier quoted context omitted.

I worked at a place where someone made the deliberate decision to migrate from Google Workspace to Microsoft 365 / Outlook / whatever it's called today. "Most of our partners use Microsoft", so we have to suffer with it, too.

If you're trying to sell to people who use teams, sharepoint and whatnot, and you won't, you're putting yourself in a commercial disadvantage. I was very happy after I got away from MS-stack companies, but I totally understand why one would switch to MS.

Yep, I get the reasoning. It's just a terrible experience if you're used to gmail.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#113

Earlier quoted context omitted.

Here’s an article on their front page today on a few thousand dollars in campaign contributions, no allegations of fraud or anything illegal: https://www.propublica.org/article/sean-duffy-michael-alfons... The Teamsters bailout was something like a million times that, from a Democratic president to a critical Democratic constituency.

Teamsters members in a majority voted for Trump. Google it. Biden helped people who didn’t value it. You blame Biden for “buying support” when it didn’t help Democrats; he did it because it was the right thing to do to protect the retirement promises made to union workers. Can’t fix uneducated, unsophisticated voters I suppose. https://www.theguardian.com/us-news/2024/sep/18/election-tea... https://www.currentaffairs…

I’m not arguing the merits of the policy. I’m arguing that if the Big Beautiful Bill contained a $70B slush fund for the administration to hand out to its tech buddies, ProPublica would have gone wall to wall.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#114
Few years ago I was evaluating some Azure VPN offering. It was still new and it worked, but it wouldn't log connection successes or denies. I opened a case for this seemingly critical defect. They finally acknowledged it and told me to go log it on their feedback site so people can vote the "new feature" up or down.

That's when i realized that i'm really done with them. They will never change and with Azure they're getting worse, not better.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#115
post #96

Earlier quoted context omitted.

I definitely remember DOGE gutting CISA. Other cuts were not always due to DOGE. A good chunk of the FBI's computer security and counter intelligence people got reassigned to immigration enforcement. The committee investigating the US cell network hacks got cut extensively but I don't remember who did it.

telcos already have strong teams themselves who monitor towers.

Regardless China was monitoring everything very easily.

https://www.pcmag.com/news/chinas-salt-typhoon-hacked-at-lea...

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#116

Earlier quoted context omitted.

> This wasn't about the GDPR; you were being told to sod off. Vast misunderstanding of GDPR by the clowns implementing it is also possible; or just "can't be arsed so hide it all"

More generously, they were applying GDPR rules in the correct manner, but to a different scenario: Microsoft customers being supported by Microsoft subcontractors that don't need to know the customer PII to do their job. Most businesses using a public cloud need to log the activities of their staff accessing their own systems, which has an entirely different set of policies. A similar example is Azure Application Ins…

> More generously, they were applying GDPR rules in the correct manner, but to a different scenario: Microsoft customers being supported by Microsoft subcontractors that don't need to know the customer PII to do their job.

They were not. If it was applied in correct manner, there would be a role of PII data administrator that could be given people in the system that is allowed to access that, just like the org is supposed to handle the data, designate people with access and range of the access they have to this data.

Post reply on HN