Live data from Hacker News

Data accidentally exposed by Microsoft AI researchers

wiz.io

121–130 of 238 posts

Re: Data accidentally exposed by Microsoft AI researchers

#121
post #89

This seems to be a common occurrence with Big Tech and Big Government, so we better get used to it: https://qbix.com/blog/2023/06/12/no-way-to-prevent-this-says... https://qbix.com/blog/2021/01/25/no-way-to-prevent-this-says...

Is this stuff regularly happening to AWS and GCP? This is like the 3rd insane security incident from Microsoft in the past year.

Re: Data accidentally exposed by Microsoft AI researchers

#123

This stands out > Our scan shows that this account contained 38TB of additional data — including Microsoft employees’ personal computer backups. Not even Microsoft has functioning corporate IT any more, with employees not just being able to make their own image-based backups, but also having to store them in some random A3 bucket that they're using for work files.

Why not even?

Security was never a strong part of Microsoft.

Re: Data accidentally exposed by Microsoft AI researchers

#125

The article tries to play up the AI angle, but this was a pretty standard misconfiguration of a storage token. This kind of thing happens shockingly often, and it’s why frequent pentests are important.

It didn’t seem to be focused on AI except for the very reasonable concerns that AI research involves lots of data and often also people without much security experience. Seeing things like personal computer backups in the dump immediately suggests that this was a quasi-academic division with a lot less attention to traditional IT standards: I’d be shocked if a Windows engineer could commit a ton of personal data, passwords, API keys, etc. and first hear about it from an outside researcher.

Re: Data accidentally exposed by Microsoft AI researchers

#126
post #22

Earlier quoted context omitted.

I strongly support the “no hello” concept but I also fear being seen as “that guy” so I never mention it. Sigh

I make it my status message.

The people who need it aren’t the type of people who’d read it.

Re: Data accidentally exposed by Microsoft AI researchers

#127
post #75
post #46

Earlier quoted context omitted.

Pentests where people actually get out of bed to do stuff (read code, read API docs etc) and then try to really hack your system are rare. Pentests where people go through the motions, send you report with a few unimportant bits highlit while patting you on the back for your exemplary security so you can check the box on whatever audit you're going through are common.

From my understanding as a non security expert: Pentest comes across more as checking all the common attack vectors don’t exist. Getting out of bed to do the so-called “real stuff” is typically called a bug bounty program or security researching. Both exist and I don’t see why most companies couldn’t start a bug bounty program if they really cared a lot about the “real stuff”

pentest means penetration testing which mean one need to take the attacker hat and try to enter your network or the app infrastructure and get as much data as he can, be it institutionnal or customer data. It can be through technical means as well as social engineering practices. And then report back.

This is in no way related to a bug bounty program.

Re: Data accidentally exposed by Microsoft AI researchers

#128
post #91
post #88

Earlier quoted context omitted.

Let me tell you about the laptop connected to our network with a cellular antenna we found in a locked filing cabinet after getting a much-delayed forced-door alert. This, after some social engineering attempts that displayed unnerving familiarity with employees and a lot of virtual doorknob-rattling. They may be rare, but "real" pentests are still a thing.

Ouch. How did that ended up?

[deleted]

Re: Data accidentally exposed by Microsoft AI researchers

#129
post #22
post #9

On a lighter note - I saw a chat message that started with "Hey dude! How is it going". I'm disappointed that the response was not https://nohello.net/en/ .

I strongly support the “no hello” concept but I also fear being seen as “that guy” so I never mention it. Sigh

I have seen people never ask their question after multiple days of saying "hello @user", despite having nohello as a status. And despite having asked them in the past to just ask their question and I'll respond when I can.

You just can't win.

Re: Data accidentally exposed by Microsoft AI researchers

#130

Two of the things that make me cringe are mentioned. Pickle files and SAS tokens. I get nervous dealing with Azure storage. Use RBAC. They should depreciate SAS and account keys IMO. SOC2 type auditing should have been done here so I am surprised of the reach. Having the SAS with no expiry and then the deep level of access it gave including machine backups with their own tokens. A lot of lack of defence in depth goin…

Many SOC2 audits are a joke. We were audited this year and were asked to provide screenshots of various categories (but most being of our own choosing in the end). Only requirement was screenshots needed to show date of the computer on which the screenshot had been taken, as if it couldn't be forged as well as the file/exif data.
Post reply on HN