Live data from Hacker News

Microsoft lost its keys, and the government got hacked

techcrunch.com

121–130 of 151 posts

Re: Microsoft lost its keys, and the government got hacked

#121

Earlier quoted context omitted.

After spending 5 years of corporate work having to wrestle with Azure (in a ci/cd capacity) I would never recommend Microsoft's cloud offerings to anyone. Problem is that there is no other provider I would rather recommend. They are all bad in one way or another.

"Problem is that there is no other provider I would rather recommend. They are all bad in one way or another." Could you explain a little further what you don't like about Azure and why you would still recommend it over the competitors?

Not the OP, but: it’s just sloppy. There is zero QA other than end-users bitching.

I recently collected some notes of bugs and errors for an MS rep. I was setting up just a .NET web app with a SQL back end, as simple and vanilla as it gets.

I found 60 bugs.

SIXTY!!!

Re: Microsoft lost its keys, and the government got hacked

#122
post #67

Earlier quoted context omitted.

This really surprised me when I learned of this story on the weekend. Very little discussion, very little reception in IT news. Someone hacked Azure AD [1] and accessed the data of 25+ orgs and the reaction is *crickets*? [1] I'm not exactly sure which Azure component was hacked and the MS communication seems intentionally unclear and obtuse on this. It sounds like the private keys of Azure-internal auth servers were…

Microsoft has published a more technical analysis[1] which was submitted in two of those HN stories mentioned above (which received no interest). Microsoft have two identity services being MSA and AAD. MSA is used for consumer Microsoft accounts for use with products like Xbox. AAD is Azure AD that businesses use. When a client wants to authenticate to a Microsoft service, it asks MSA to sign a token for services acc…

Wow. It's hard to say which is worse "our internal apps to control 1P MS properties were marked multi-tenant and did no real AuthZ"... or... "we leaked an MSA signing key and had our token validation so f**ked that (presumably) any signing key was valid for any key-under-test, regardless of expected configuration".

Just stunningly bad and would make me reconsider how much MSFT I hold, except that no one seems to care.

Re: Microsoft lost its keys, and the government got hacked

#123
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

Microsoft exists to make money. If it made good products, it would not make money.

Re: Microsoft lost its keys, and the government got hacked

#124
post #32

I hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the…

what does this have to do with the article, though? You just had a rant ready for when you saw a Microsoft-is-at-fault story came up?

It's unrelated to the article, and blatantly violates the HN guidelines:

> Eschew flamebait. Avoid generic tangents. Omit internet tropes.

https://news.ycombinator.com/newsguidelines.html

I flagged it - I suggest you do, too.

Re: Microsoft lost its keys, and the government got hacked

#125

Earlier quoted context omitted.

> Everything is seamless and just works. I have zero confidence in that testimonial, given my own experience with open source desktop environments, and KDE. zero confidence whatsoever.

I'm 12 years into Linux on the desktop. It's amazing. Converted my non computer friend to it. My partner freaked when windows 10 tried to install itself years ago, and she switched. I play triple A games on it via steam. Our TV PC runs it. The experience is so much better I really don't get this mentality.

It's not a "mentality" - it's an opinion born from actual experience with broken Linux setups. I can find you literally hundreds of HN comments about all sorts of ways that their Linuxen have broken, and I can name a few dozen (possibly up to a hundred) myself.

Re: Microsoft lost its keys, and the government got hacked

#126
post #116

Earlier quoted context omitted.

Linux on the desktop is here. Go all-in on KDE. Everything is seamless and just works.

None of the comments here seem to address desktop OS in enterprise/government environment, which is what this article about. Linux desktop OS your personal computer? Sure. In an organization where most users are not technical, and where vendors do not release their software? Good luck.

> Sure. In an organization where most users are not technical, and where vendors do not release their software?

Most of these enterprise software (for non technical users) these days is just a web app so a vendor not releasing their software is not a problem here.

Re: Microsoft lost its keys, and the government got hacked

#127
post #31

This headline does a good job of pointing out why we shouldn't allow backdoors in encryption.

Wasn't there a time when Microsoft shared it's code with China govt on a locked computer in a locked room with access to only a few people as a demonstration that there product did not have backdoors for western countries to spy on China?

Re: Microsoft lost its keys, and the government got hacked

#128

Any Windows product/system is a liability. I'm not sure how to put this lightly. It was designed to create a monopoly first before any other goal. And it's not that the alternatives are perfect, but Windows is as secure as swiss cheese.

Heartbleed did not affect windows.

Re: Microsoft lost its keys, and the government got hacked

#129
post #91

Earlier quoted context omitted.

As a counterpoint: I've worked with both Azure cloud and Azure DevOps (or whatever the feck they call it now) for a long time (maybe 10 years?), a lot in a corporate setting, but also for my startup. Apart from the same price issues that exist across all the big 3 cloud providers, I actually really like Azure.

I love the conceptual framework and high level architecture of Azure: Resource Manager, sane naming compared to AWS, etc… What I hate is the unfathomably sloppy implementation that their developers refuse to fix unless held at gun point. You literally have to have an MS account manager about to miss out on millions of dollars to force a trivial fix through their pipeline. They have zero “customer obsession.”

Actually I'd say they have customer obsession but that it's for a small minority of what We consider thier customers (to them the small fry including smbs are not thiet customers, they're just the chaff they have to deal with and control in order to properly get the wheat out of the whole).

BIG businesses and governmenta are thier customers, demanding maintenance of terrible legacy issues because they literally use bugs as features in thier even more poorly made and maintained custom systems built by some fly by night dev shop 2+ decades ago....

MS doesn't care about individuals, individuals are just eyeballs to them.

Re: Microsoft lost its keys, and the government got hacked

#130

Earlier quoted context omitted.

Mentioning China negatively is the kiss of death.

I feel I can't discuss some foreign nations anymore in a critical way since I fear giving mentally unstable war mongers ideas.

What do you mean? I can't say I have ever seen war mongering on HN.
Post reply on HN