Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

161–170 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#161
post #134

Why do they say "nation state actor", isn't "state actor" the correct term? I thought Russia, like the UK and many other states, is a multinational state, including numerous languages and cultures.

Yeah I find this particularly funny with infosec because the usual state {level,funded,sanctioned} actors are Russia, Iran, and North Korea, of which only one is a nation state.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#163
>Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold

If people at Microsoft reuse passwords than what we can expect from casual PC users?!

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#164
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

I like this bit ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. Yeah, at least they make a very small percentage of all Microsoft employees I guess

When having an incident like that, always figure out what is the largest denominator you could compare the exposure against.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#165

Earlier quoted context omitted.

That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.

The only defintion that matters is the practical definition that most people would think of, not what the “book” says. Whenever someone tells me “production is down” I think that customers are screwed. If they told me our internal email servers are down, I would smack them in the head cause my stress levels went up for nothing. Internal servers is not production.

> Internal servers is not production.

I’m going to take a wild guess here and say you don’t really run any kind of system. “Internal is not production” is the weirdest statement I have heard in a long time.

Of course these systems are production. Not only production, but _P1_ level production.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#166

Earlier quoted context omitted.

That is how it has been defined at every SAAS company I have worked for. When someone says there is an outage in production, it means your product .

In the context of an outage at a service provider this slightly sloppy language is sufficient to convey all relevant meaning. In the current context, this language is part of a pattern to carefully choose words in such a way as to downplay what has happened. As I said, the work of the CEO, the cybersecurity team and the legal team is part of the overall production process at a software company.

Okay, but then why also not consider chairs breaking in the office to mean part of the production is down? Or a coffee machine?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#167
post #58

How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.

I suspect more corpos have exposure like this than any of them would like to admit. E.g.: BigCo picks up a company SmallCo, and inherits their systems for some time. There's some cruddy ancient CRM, IT or travel system, and some random test tenant, that has hooks to email, and from there it's a short step to enumerate targets, send auto-generated emails from a trusted system and the hackers are off to the races.

Yes, it can be an endless headache. A company I worked for had acquired a smaller company with some products and services that nicely complimented our own products and services. From the outside it was a good match and for the most part, the integration went well but they had been using Rational Clearcase for over two decades and absolutely didn't want to migrate to git and the rest of our tool suite. They had very little turnover in their IT department and things ran very well for them but higher ups wanted everyone integrated into a single system and the accounting folks wanted to stop paying fees for all the Rational stuff, especially since they hated dealing with IBM. Infosec had pretty much no knowledge of how to best secure anything on that side and the acquired company had nearly no infosec capabilities of their own. When I left, it was still a point of contention that didn't look to get resolved any time soon.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#168

Earlier quoted context omitted.

No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.

That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.

Test environments serve the production purpose of testing software.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#169

Earlier quoted context omitted.

Definitely agree that Crowdstrikes naming veers past what is necessary. They even draw up supervillain graphics for them. https://www.crowdstrike.com/adversaries/arcane-kitten/

This is really cool and incredibly stupid. Like, who is this made to appeal to? Is this meant to make corporate executive browsing for cybersecurity solutions feel like they're in a spy movie?

Cybersecurity professionals, in general, eat this stuff up.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#170

Earlier quoted context omitted.

> Why do they say "nation state actor" A Nation-State is the idea of a homogenous nation governed by its own sovereign state—where each state contains one nation.

And that definition doesn't describe the Russian Federation. There are many nations within Russia, ones you may have heard of are Bashkortostan (in the news this month due to protests) and Chechnya (civil wars in the 1990s). It is not a homogeneous federation. https://en.wikipedia.org/wiki/Republics_of_Russia

Perhaps de jure it's not, but in reality it's clear that Russia is a hyper-centralised city-state (Moscow) in all respects.
Post reply on HN