One Token to rule them all – Obtaining Global Admin in every Entra ID tenant (13 days ago - 51 comment): https://news.ycombinator.com/item?id=45282497
The god mode vulnerability that should kill "Trust Microsoft" forever
21–30 of 33 posts
Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#22This article isn't just full of LLM-isms, it's unreadable because of it. When you completely delegate your editing to a machine, you're not just lazy, you're robbing yourself of the one thing that made you stand out --emdash-- your own voice. Moreover, as we navigate this evolving paradigm, we must carefully consider the balance between efficiency, authenticity and a third thing in this list. Maybe at the end of the…
I found the idea of a third thing in that list particularly persuasive.
Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#23> As long as someone or something holds it, it can be exploited.
Wide distribution, as opposed to centralization, seems to be the most reliable way to ensure continuity. Am I wrong in seeing this pattern in so many different areas? The distributed animal survives ecological or geological collapse in one region, the distributed activist group survives fed infiltration into one entity, the distributed army holds off the centralized one (with infinitely better funding and weaponry) for decades, the distributed political power survives demagogue takeover.
I might be abstracting way too far here, but it makes me wonder why we keep trying to centralize authority, when it keeps failing spectacularly.
Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#24Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#25Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#26Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#27Same story, but directly with the reporter: One Token to rule them all – Obtaining Global Admin in every Entra ID tenant (13 days ago - 51 comment): https://news.ycombinator.com/item?id=45282497
Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#28All the security and compliances require that someone operates it, not everyone can design systems like Linux in an year or so.
The more darker truth is the entire existence of proprietary codebases and architectures, there's a saying either ask the question or forever remain foolish
It's time we ask it ourselves and the companies which we depend on to allow atleast open auditing their architecture
It's just one step but it prevents the level of exploits like these
Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#29The real issue is, what do you use instead that you can make the non-technical users accept? You can certainly move to google and get an overall improvement in track record and end user experience, but the fundamental issue raised in the article is still there You can move to proton and get a pretty nice experience for mail and calendar, but it adds limitations regular users will be upset by. Their equivalent to word…
The solution in short: "...distributed in the form a key who’s pieces live across a decentralized network."
If looking for alternatives to Microsoft's products I would recommend Infomaniak [0]. They have a fairly complete solution of business tools (email, contacts, calendar, cloud storage, file sharing, chat, video meetings, docs and sheets).
Re: The god mode vulnerability that should kill "Trust Microsoft" forever
#30Earlier quoted context omitted.
I found the idea of a third thing in that list particularly persuasive.
You should. It was important in the classical study of rhetoric, given the name "tricolon". https://en.wikipedia.org/wiki/Isocolon#Tricolon