Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

161–170 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#161

Unrelated, but this afternoon Microsoft decided I couldn’t use my laptop for 10 minutes for mandatory updates, which was a serious problem. And now the search feature doesn’t work anymore. If it wasn’t for the game support being important for work I’d happily leave and avoid every aspect of their ecosystem. What other reasons do people have for sticking with Microsoft apart from software compatibility?

Many people prefer the traditional Windows UX over the Apple and Linux offerings. I’m saying “traditional” because Microsoft has been trying hard at sabotaging it since Windows 8.

Regarding mandatory updates, try Reboot Blocker.

Re: Everything authenticated by Microsoft is tainted

#162

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

Blatent case of Microsoft derangement syndrome. Hard to take your comments seriously with such obvious disdain against the company and ridiculous victim blaming.

Can you instead adress the Op’s concerns rather than calling names?

Re: Everything authenticated by Microsoft is tainted

#163

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> deserve what they get sadly This is incredibly insensitive and dismissive, and victim-blaming.

Hard disagree. This is professional negligence. How would you feel if your doctor only prescribed medicine from one single supplier?

Re: Everything authenticated by Microsoft is tainted

#164
post #159
post #157

Earlier quoted context omitted.

Is it? Every large company has a well compensated CTO whose job it is to think through these sorts of hypotheticals. But “nobody gets fired for choosing Microsoft”, and so the monopoly continues…

"A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional and orthodox way along with his fellows, so that no one can really blame him"

The worst part is that very poor diversification / groupthink is exactly what creates financial bubbles and financial crises. We seem to be reaching that uncomfortable too-big-to-fail scale in computing / cyber security.

Re: Everything authenticated by Microsoft is tainted

#165

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

[flagged]

Re: Everything authenticated by Microsoft is tainted

#166

Earlier quoted context omitted.

> „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. Disagree. You don't need 10 years in IT to understand the meaning of: "M$ allowed customers to use their house-keys to open everyone's office safe, lied about it for 2 years, and still doesn't have a plan for fixing it". McNeally was simply wrong, but despair is easier than fixing things, so a lot of people went with despa…

Nah, no one outside tech cares.

And not even that they shouldn't care. They just don't pay attention and don't care.

Re: Everything authenticated by Microsoft is tainted

#167

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> own ways to do anything but be a slave to Microsoft

I guarantee 99/100 humans on this forum either currently host with AWS/GCP/Azure or have worked at a shop that does. And I bet an outsized portion of those AWS/GCP shops also host on Azure for Azure AD.

There is no one that is ready for a de-Microsofted world. Even Linux distros have been increasing their support for integrating into the MS ecosystem and forsaking alternatives because how prevalent AD is. Even the most prominent alternative FreeIPA is designed to compliment an AD installation, not replace it. The best supported directory/central login server on Linux is AD.

Re: Everything authenticated by Microsoft is tainted

#168
post #93
post #73

Earlier quoted context omitted.

Mastodon is often really slow. The krebs link loaded after like two minutes with an error, then a soft refresh finally loaded it. That happens regularly with Mastodon links for me

there isn't a single Mastodon server. It's a web application (like Wordpress which frequently gets hugged to death when linked here).

Right, so instead of:

> HN buried Mastodon as a viable social media platform a year ago.

It should be:

> HN buries Mastodon as a viable social media platform every time an HN user posts a moderately popular link to Mastadon.

I want to love Mastodon but until they figure some stuff out they're never going to be a viable platform to (for instance) explain to all those who need to know how one of the largest cloud providers is deeply compromised.

Re: Everything authenticated by Microsoft is tainted

#169
post #133
post #55

Earlier quoted context omitted.

For on-prem or cloud, you need some engineers (either SRE or SysEng) to handle your hosting infrastructure. So, not much difference in cost there. Then, there is all of that compute. Currently, an AMD EPYC 7551 system can be put together for about $2.2K USD. That’s 64 threads, 256GB of RAM, redundant 2TB NVMe in RAID1, plus chassis, power and such. The equivalent amount of compute being available 24/7 is going to be…

I also held this view for a long time but what you are talking about is basically Amazon EC2. There are, what, 200-250 AWS services, however, and that's where things begin to become more interesting. Can you replace any of them with in house solutions? Certainly. But the costs of doing so might not be favorable. You could operate an on premise bakery but most companies just order donuts.

At a decent sized shop, having a couple of people making fresh-baked breads, croissants etc. would be such a perk ... Order in donuts? No imagination.

Re: Everything authenticated by Microsoft is tainted

#170
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

>While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect.

Well we expect people and corporations to fix a problem when confronted with it. That is what we expect.

> „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society.

Have to give you a pass on "normal" people. I don't know any. I see no reason why we cannot go without the (by the way) unmentioned services or why we cannot change them to be more privacy conscious.

>Wouldn’t it be more reasonable to teach:

No it would be more reasonable to teach that privacy is vitally important to have a functioning society and economy. Anyone claiming different think they can exploit the information disparity between you and them to make money in the short term.

>1. You have no privacy, it is impossible to ensure or guarantee privacy, and there’s no incentive at all for anyone to ensure privacy. (Scott McNeally of Sun said that already in the late 1990s).

Well I respect Scott, but this is not his great moment. Let's change this to be still completely true: You have no property, it is impossible to ensure or guarantee property and there's no incentive at all for anyone to ensure property. Well we did find a way to actually do ensure property. It is called the law (and a government to enforce it). Just an idea to use this tried and tested concept on privacy as well.

>2. There is no security and every kind of security has been, was designed to, or will be compromised.

First this has always been true. Every lock can be picked. Fortunately not everyone can pick a lock. That is the reason why most of us still lock the door.

>3. All your digital information is already public or will become public at some point. (btw: Every top-tier consultancy operates under that assumption)

You mean those top-tier consutancy firms mentiond in this book: "The Big Con" by Muzzucato and Collington, Penguin, 2023? I can see that they sell the assumption, but they are not operating by it. If that were true McKinsey for example would have known their advice to Purdue Pharma would become public and they would lose big on it.

In short people who claim privacy is not important mean: _your privacy_ is not important and they are overly confident they can keep ahead of the information disparity to keep themselves private. See how hard, ironically, Google is working to keep all their information private in a public anti-trust trail.

Post reply on HN