Live data from Hacker News

Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

news.ycombinator.com

121–130 of 148 posts

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#121
post #48

Earlier quoted context omitted.

I hope not. Failures are on a spectrum and this was unfortunate but probably not malicious. All things considered this should be a lesson learned. There should be more failsafe mechanisms in place so juniors can fail safely and learn from them. The absolute worst thing we can do is shame an individual so they don’t attempt to try new things in fear of ridicule.

> There should be more failsafe mechanisms in place so juniors can fail safely and learn from them. And if not, whoever put the junior in that role is the person responsible for the problem.

well theoretically you could argue the structure of this task should have 'dual control' / multiple people should be involved in the process checking each others work. preferably even split it up people who do not know or interact with each other on a regular basis. yes it would be slower but its important to get it correct.

might as well throw in some automated poke-yoke or whatever too.

in that case there is no fault in any of the juniors or operators, the fault is in management for failing to implement infrastructure to force a critical process to have more than one control

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#122

An entry-level admin is now unemployed, just before the holidays.

> An entry-level admin is now unemployed, just before the holidays. I highly doubt that entry-level admins at Microsoft have access to DNS for their primary domain. My guess is that this incident is a lot more interesting than that.

Yep, this doesn't seem like the kind of thing that you can just toss a couple approvals on and change at a company as big as Microsoft. How this made it through the review process would be very interesting

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#123
post #42
post #16

for uninitiated (me), why is it bad?

Well in my case (and a lot of other people), 192.168.1.1 is the local address of my home router. So if I go to microsoft.com I have a 1 in 7 chance of getting my home router instead (if I ignore the certificate warning). Other random breakage will happen depending on what that local address is assigned to for you. In theory this could be leveraged for hacking, but I think that would require setup in advance.

yep. If a hacker can somehow control 192.168.1.1 or 192.168.0.1 they get access to your microsoft.com cookies at least. I'm sure there are more microsoft specific ways to leverage this too (e.g. data/updates hosted on microsoft.com that misuse HTTPS as a poor man's authentication. The curl | sh crowd are especially susceptible to this problem.)

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#127

Earlier quoted context omitted.

This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…

Microsoft also has some of the phishiest looking domains when you are redirected around the O365 cloud.

Indeed, take a look at the lists of azure and o365 domains, they're all over the place:

https://learn.microsoft.com/en-us/microsoft-365/enterprise/u...

https://learn.microsoft.com/en-us/azure/security/fundamental...

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#129
post #90

Earlier quoted context omitted.

100%. Starting with "onmicrosoft.com". A phisher wouldn't really have to control Microsoft.com to take advantage of confusion.

There were several phishing attempts from that domain, onmicrosoft.com, to my personal email account this past week.

Microsoft.com has been constantly trying to fool me into subscribing to their Office tools.
Post reply on HN