Live data from Hacker News

Microsoft blamed for "a cascade of security failures" in Exchange breach report

arstechnica.com

21–28 of 28 posts

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#21
post #3

Earlier quoted context omitted.

For key rotation, it may not be as simple as it sounds. I expect better from MS as well but for example, for on-prem AD, the krbtgt account should be rotated yearly but in practice, it carries a huge risk of outages for accounts that depend on it a lot for kerberos ticketing. I don't know the details but knowing MS, they may have copied over the key distribution design of kerberos to azure ad (hence the "skeleton key…

>For key rotation, it may not be as simple as it sounds. I expect better from MS as well but for example, for on-prem AD, the krbtgt account should be rotated yearly but in practice, it carries a huge risk of outages for accounts that depend on it a lot for kerberos ticketing. If only there were internal development resources that Microsoft could leverage to build a more robust system, maybe one that allows for phasi…

In hindsight yeah, they could have done better but I suspect they were focused migration to cloud from on prem, doing a whole new robust directory system wasn't top priority. I doubt it is now either unless the government twists their arms. They instead rebranded as entra id lol.

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#22

Earlier quoted context omitted.

As a random example, they charge customers to store audit logs. That would be “fine”, except that they charge something like 7x what AWS does for the equivalent service. The AWS pricing is already what I would call “too high”, which makes Azure’s log analytics pricing highway robbery. It can cost more than the VMs it is auditing! Another fun problem is that their audit logs only log the identity of the person that tr…

Oh, you paid 15k more? I'd say that's a feature.

Me? No. The government did… with your taxes.

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#23
post #20

Earlier quoted context omitted.

I've done an objective comparison of cloud provider security capabilities and Azure's is the worst by a large margin [ . . . ] could you say a little more about this—if only to list some security-related functionality that's default or comes with 'base ' licensing in other public clouds, but that Microsoft offers only as add-on? probably a fair list considering the sheer number of tier and add-on SKUs. but anything s…

Can't share details but we basically listed mitre tactics and what out of box detection/prevention/logging each CSP provides.

anything nonspecific enough to share re: results? how'd/s Azure fare relative?

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#24

The linked story from 2023 has insane details. I’m pretty sure I had heard this before, but blocked it out due to some sort of normalcy bias. This plus the latest State Dept. hack deserves pulling the CEO in front of Congress. It is known that there used to be a saying at Microsoft ~”Don’t get Bill pulled in front of Congress“ to avoid making bad decisions. That should be a thing again. > He also faulted Microsoft fo…

Oh Microsoft has a security failure? Imagine that. Only 40 years of non stop security failures in its history. Why anyone would use Microsoft products is beyond me. You can only blame yourself. Fool me once shame on you, fool me for 40 years shame on me.

Yep. I don’t understand why anyone ever uses Exchange; it was a joke 25 years ago, it’s still a joke.

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#25
post #3

The linked story from 2023 has insane details. I’m pretty sure I had heard this before, but blocked it out due to some sort of normalcy bias. This plus the latest State Dept. hack deserves pulling the CEO in front of Congress. It is known that there used to be a saying at Microsoft ~”Don’t get Bill pulled in front of Congress“ to avoid making bad decisions. That should be a thing again. > He also faulted Microsoft fo…

For key rotation, it may not be as simple as it sounds. I expect better from MS as well but for example, for on-prem AD, the krbtgt account should be rotated yearly but in practice, it carries a huge risk of outages for accounts that depend on it a lot for kerberos ticketing. I don't know the details but knowing MS, they may have copied over the key distribution design of kerberos to azure ad (hence the "skeleton key…

> the krbtgt account should be rotated yearly but in practice, it carries a huge risk of outages for accounts

Bad example, since the krbtgt password needs to be rotated twice, since the old one is stored as well, precisely to avoid outages.

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#26

The linked story from 2023 has insane details. I’m pretty sure I had heard this before, but blocked it out due to some sort of normalcy bias. This plus the latest State Dept. hack deserves pulling the CEO in front of Congress. It is known that there used to be a saying at Microsoft ~”Don’t get Bill pulled in front of Congress“ to avoid making bad decisions. That should be a thing again. > He also faulted Microsoft fo…

Oh Microsoft has a security failure? Imagine that. Only 40 years of non stop security failures in its history. Why anyone would use Microsoft products is beyond me. You can only blame yourself. Fool me once shame on you, fool me for 40 years shame on me.

That's edgy without being interesting. I could replace you with a small script.

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#27

The linked story from 2023 has insane details. I’m pretty sure I had heard this before, but blocked it out due to some sort of normalcy bias. This plus the latest State Dept. hack deserves pulling the CEO in front of Congress. It is known that there used to be a saying at Microsoft ~”Don’t get Bill pulled in front of Congress“ to avoid making bad decisions. That should be a thing again. > He also faulted Microsoft fo…

Oh Microsoft has a security failure? Imagine that. Only 40 years of non stop security failures in its history. Why anyone would use Microsoft products is beyond me. You can only blame yourself. Fool me once shame on you, fool me for 40 years shame on me.

I would love to know of a major tech company/product that has NOT had a security failure. This goes double for companies that provide hosting of services that hold juicy personal information.

Re: Microsoft blamed for "a cascade of security failures" in Exchange breach report

#28
post #20

Earlier quoted context omitted.

Can't share details but we basically listed mitre tactics and what out of box detection/prevention/logging each CSP provides.

anything nonspecific enough to share re: results? how'd/s Azure fare relative?

Basically, they had products for most categories bur unlike other CSPs they were paid and optional and the payment model makes it hard to predict cost. Applying those features across a large number of subscriptions is also not a trivial task. You can compare ASC alerts vs SCC (gcp) yourself and see.
Post reply on HN