Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

21–30 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#21

We all ought to be using Qubes OS! We, as the Hacker News community, ought to be more concerned about making it easier to use reasonably secure systems. How do I buy a computer that runs Qubes? https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/

As someone who runs Qubes on one of my laptops (the travel one) I can assure you that your long battery life days are over.

Re: Everything authenticated by Microsoft is tainted

#23
This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine.

Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure.

The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing.

I also hope that Microsoft step up their security game but at this point it’s kind of a lost cause.

Re: Everything authenticated by Microsoft is tainted

#24

We all ought to be using Qubes OS! We, as the Hacker News community, ought to be more concerned about making it easier to use reasonably secure systems. How do I buy a computer that runs Qubes? https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/

Or get a Chromebook. Say what you want about Google but its one of the few who really care about security.

Re: Everything authenticated by Microsoft is tainted

#25
post #8
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

On-prem is very expensive compared to cloud.

And not guaranteed to solve problems like this. Because at the end of the day, the maintenance of a cloud infrastructure is irreducible complexity so you replace having a breach because a centralized controlling authority made a mistake with having a breach because your own hired staff made a mistake and you got infiltrated by either a lucky drive by or a persistent attacker against your organization.

Re: Everything authenticated by Microsoft is tainted

#26
While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect.

„Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society.

Wouldn’t it be more reasonable to teach:

1. You have no privacy, it is impossible to ensure or guarantee privacy, and there’s no incentive at all for anyone to ensure privacy. (Scott McNeally of Sun said that already in the late 1990s)

2. There is no security and every kind of security has been, was designed to, or will be compromised.

3. All your digital information is already public or will become public at some point. (btw: Every top-tier consultancy operates under that assumption)

Re: Everything authenticated by Microsoft is tainted

#27

We all ought to be using Qubes OS! We, as the Hacker News community, ought to be more concerned about making it easier to use reasonably secure systems. How do I buy a computer that runs Qubes? https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/

How would Qubes help here? Separately, Qubes runs fine on a framework laptop.

Re: Everything authenticated by Microsoft is tainted

#28
post #8
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

On-prem is very expensive compared to cloud.

Careful with blanket statements like these. Run a system with high sustained compute and data egress; even when accounting for engineer time (and people often neglect to account for time spent administering cloud infra), the cloud markup is huge. While it works for some companies, cloud is not universally cheaper.

Re: Everything authenticated by Microsoft is tainted

#29
post #3

Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.

Key part is simple. For some apps I wondered why I had them in the "cloud" in the first place. And then I had to do something every month or two because I had to migrate to some stupid new version of an environment, do some DNS entries because the apps couldn't send mails anymore, configure the shitty IAM of the cloud provider I didn't need. Register my apps for some stupid database access.

Now I have apps where I need 15 minutes of maintenance a year, install and configuration takes 5 minutes.

Some cloud providers have amazing stuff, but I feel they all start to bloat and I don't have use cases that need whole clusters.

Re: Everything authenticated by Microsoft is tainted

#30
post #2

I read a good analogy recently: The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.

How is that a good analogy when the cloud computing sector has been growing year on year? There's literally no evidence to support that analogy. It's not even remotely accurate.

I'm not saying cloud computing is the solution to every problem, and nor should it be, but calling it a sinking ship is simply absurd.

Frankly, I grow so tired of people thinking everything is a boolean choice. The real problem with the cloud is people who see things as binary statements: "cloud is cheaper", "cloud is more expensive", "self hosting is easier", "cloud is easier", "cloud is more secure", "on-prem is more secure", etc. All of those statements are true just as all of those statements are false. The reality is far more nuanced and it depends entirely on the constraints of your business at that point in time. Such as what engineers / skill sets do you have on your team? Capital to buy hardware, your physical location, the product you're trying to build... etc.

But the problem with nuanced arguments is they're subjective to the immediate problem you're trying to solve. So you cannot debate them with other people as those other people are trying to solve different problems with different teams and different tools. And thus we end up with people posting bullshit blanket statements like "the cloud is a sinking ship" or the linked article that boasts that the cloud is less secure.

Post reply on HN