Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

201–204 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#201

Earlier quoted context omitted.

Why would they have to be made public? They only have to be known to a handful of other nation states.

Because this discussion is about the comment "Nothing is stopping anybody here". I already conceded in my original response that if you hacked another group first, then yes, you can leave fake breadcrumbs.

My point is that this has already been done. It's not a question of if. Once that's done, these things can spread around.

And I'm also saying you don't necessarily need to hack another group to find their tools.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#202
post #69

Earlier quoted context omitted.

This kind of attack can happen on any tech stack where bad passwords have ever been allowed. The dunking is obviously fun, but the fact that the underlying technology happened to be Microsoft’s is largely irrelevant.

Ahh, a cult follower, let me guess, you are doing C# full time and it is the greatest programming language ever created ?

[deleted]

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#203

I am surprised they had logs for this long. Entra only comes with 30 days of audit logs by default which is utterly insane

Bet it might be because of a combination of compliance and cost. Storing logs at that scale is not cheap

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#204
post #203

I am surprised they had logs for this long. Entra only comes with 30 days of audit logs by default which is utterly insane

Bet it might be because of a combination of compliance and cost. Storing logs at that scale is not cheap

Who cares? a) their logs have 30% of information that is completely useless, maybe they should fix that then b) (especially) if you have a P1/P2 AD license this is just not acceptable, you are paying enough to at least have some decent storage for such critical piece of information

funny thing - if you have these things in default and someone deletes a user, you won't know who did such action after 30 days (meaning you not only can not recover the user, but also will not know who performed the action)

edit -as for the compliance, personally not aware of it, but you should be able to at least have a retention policy option for it and since most companies will just put it into a storage account or log analytics I don't think it's a matter of that

Post reply on HN