Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

171–180 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#171

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

I used to work as a federal contractor for the US Military in 1996-1997 and they replaced their Windows Web Servers with Macintosh ones because the Mac had better security. I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux. Microsoft may be popular, but they have big holes in their security. Always has been.

The better to sell you a product to patch that hole.

Like "antivirus".

Re: Everything authenticated by Microsoft is tainted

#172

Earlier quoted context omitted.

Surprised I don't see M$FT. It's like slashdot in the early 2000s. Edit: -4 downd00ts! Haha must have triggered a few oldies who never let go of their hate.

Don't forget that it was then Microsoft CEO Steve Ballmer who in 2001 compared Linux to cancer. If there is childish vitriol somewhere, it did start neither on HN nor on /.

Oh I know, all companies change over time and both Billy and Balmer have zero impact on the day to day operations at Microsoft.

The Microsoft today isn't the Microsoft of the 2000s.

Now I wish the same thing could be said about Google which is quickly becoming the Microsoft of the 2000s.

Re: Everything authenticated by Microsoft is tainted

#173
post #44

Earlier quoted context omitted.

But the cloud is much safer. It's not like someone is going to hack the whole Microsoft cloud. Oh, hang on ...

Funny as this was one of the winning arguments when we went to the cloud, couldn’t possible be safer to host your own, right ? RiGhT?

I feel like once google had enough of a stranglehold on email for gmail to start blocking independent email servers (for valid security purposes probably) it was basically game over. It became incredibly difficult for an individual to run their own communications platform, even when following best practices. Luckily there are solid paid services, but as you point out, those are still "the cloud."

Re: Everything authenticated by Microsoft is tainted

#174

Earlier quoted context omitted.

Surprised I don't see M$FT. It's like slashdot in the early 2000s. Edit: -4 downd00ts! Haha must have triggered a few oldies who never let go of their hate.

Why do you think people hated Microsoft? Let's see if you know actually know anything about their deep and wide business sociopathy. One of the big reasons that monopolies are really bad is that they are also inevitably incompetent. The fact those two things go hand in hand makes the inherent corruption of monopoly / cartels doubly damaging. ....almost all markets are cartels at a minimum these days

I get that, but the Microsoft of today isn't the Microsoft of the 90s or even 2000s.

Now if we want to talk about Google...

Re: Everything authenticated by Microsoft is tainted

#175

Maybe this explains why Defender (Microsoft's AV) became so overly aggressive during previous few months. They had a problem and acted in a semi-panic mode forcing Defender to mark nearly everything as a "virus" when its Cloud Protection mode was turned on.

Uh, are you certain of that? When security alarms start going off, “darn, they broke the detector!” isn’t the only explanation.

Re: Everything authenticated by Microsoft is tainted

#176

Earlier quoted context omitted.

Another reason I am in love with LLMs. You don’t need to know the software like the back of your hand - a new environment is like a new programming language, as long as you’re able to ask the right questions new environments will be far more accessible. Experienced admins should know the requirements, and not be limited to the tools. Migrating will be relatively cheap. No wonder they’re hobbling the tools (/tinfoil),…

I'm not so convinced a LLM remixing all the tutorial blogs its ingested is a meaningful quality step above those tutorial blogs themselves. Earlier this year we had a linux task that was above the normal complexity my team deals with. So a few people threw it at chatgpt and were amazed at how good the results were. In reality, it was full of outright factual inaccuracies and non-breaking bad decisions. But their skil…

You should point out to all of them now what the consequences would have been of blindly following the LLM. It's an important lesson they can and should learn from.

Re: Everything authenticated by Microsoft is tainted

#177

This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".

You can still create "app registration secrets" that last for up to two years. Until recently, you could create essentially unlimited-duration secrets.

It's only a limitation in the UI. Using powershell you can still create client secrets that are valid for hundreds of years.

Re: Everything authenticated by Microsoft is tainted

#178
post #167

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

> own ways to do anything but be a slave to Microsoft I guarantee 99/100 humans on this forum either currently host with AWS/GCP/Azure or have worked at a shop that does. And I bet an outsized portion of those AWS/GCP shops also host on Azure for Azure AD. There is no one that is ready for a de-Microsofted world. Even Linux distros have been increasing their support for integrating into the MS ecosystem and forsaking…

My entire adult life and career has been MS free. It’s not that rare.

Re: Everything authenticated by Microsoft is tainted

#179

This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…

> This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine.

This issue.

Services get compromised often, cloud or customer managed. Microsoft has a mature, professional and effective security team. They got compromised, due to implementation flaws and one or more (my conjecture) corrupted insiders. Most organizations would have no idea wtf happened and would not be able to identify what has been revealed to the public.

Hindsight is 20/20.

Re: Everything authenticated by Microsoft is tainted

#180
post #26

While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…

I keep my secrets in a safe with an old school lock.

My elderly aunt keeps her secrets on a notepad in her desk. I suppose a spy or a housecleaner (if she had one) could know her secrets but it won't be "hacked".

The whole "you have no privacy or no security" is false and only impacts the terminally online.

Do what the intelligence agencies do. Stop letting other people store your secrets. Put them in a nice heavy locking box. Guard them with a firearm.

Post reply on HN