Live data from Hacker News

Despite doubts, federal cyber experts approved Microsoft cloud service

propublica.org

201–210 of 249 posts

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#201

> [...]And because federal agencies were allowed to deploy the product during the review, GCC High spread across the government as well as the defense industry. By late 2024, FedRAMP reviewers concluded that they had little choice but to authorize the technology — not because their questions had been answered or their review was complete, but largely on the grounds that Microsoft’s product was already being used acro…

I dunno, but for me ensuring security means reducing the number of problematic parts, and making sure the ones that have control over the ones that exist.

The most secure thing I could think of is a cluster of servers running in my basement under lock and key, running a conservative set of well-tested software.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#202

Earlier quoted context omitted.

Oh please, that could happen at any company. Humans screw up.

But it doesn't. Full authentication bypass exploits are extremely rare and unheard of among tech giants. Maybe account takeover/recovery, sure, but full bypass? It just never happens. Microsoft goes beyond that: they've managed to have a critical vulnerability in almost every authentication product they have ever created. It's exceptional.

> But it doesn't.

That we know of.

> It's exceptional.

I agree, but I look at it as a question of cost. would it make sense for Russia to spend on resources to compromise GCP or AWS? Microsoft's EntraID/AzureAD itself is an exceptional product in that organization's dependency on it, especially US government orgs, is exceptional.

If APTs target AWS, they will compromise it, period. Of course the caveat is time, skill and money which can all be acquired at cost.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#203
post #130

Suddenly everyone on HN is an expert on Azure infrastructure. it isn't the best but it's really great at a lot of things feature-wise. top-notch documentation as well (despite what these "experts" said). Most companies literally run on Azure these days. Persistent hackers will get into any network, that's a guarantee, that's APT 101. It's law of averages. If it truly is "a pile of shit" given how it is probably the m…

I ran a one of the largest multi-cloud service across azure, aws and gcp. Azure was hands down, obvious to everyone involved the worst technically. In capabilities, bugs/correctness, availability and support.

I can only speak from the perspective of someone who used/admined in all those 3 environments. I'm surprised you ranked google's support above microsoft. I've also seen bugs that would be unusual in other clouds, but other clouds have other pros/cons as well. GCP for example is capable, but it is tedious to use, and even harder to log/audit.

Of all 3 CSPs azure has the best identity management system. they're the worst in terms of charging for critical security measures that should be free, but when you pay for it, none of the other providers even come close to that capability.

The main reason people use Azure is easy integration. You're probably right when it comes to availability, no argument there, except maybe how AWS region outages seem to be a bi-annual holiday.

In practical terms, different CSPs might annoy people differently, but availability aside, I think they all suck in their own special way from a user experience perspective. AWS had to recently tell their devs/engs to have a senior dev review their vibe code because of all the outages it was causing.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#204
post #95

Earlier quoted context omitted.

Ugh this sounds like when I worked at Oracle/OCI. Some environments required a VPN, some a jumpbox, and some required logging into a virtual desktop, and then logging into a jumpbox. Just thinking about it gives me PTSD

any sufficiently large organization that is around for a decade or two trends towards spaghetti-access

Does Google have good SSO internally? Or Facebook?

(excluding things like administration of organization-wide infrastructure key material)

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#205
post #54

Earlier quoted context omitted.

It is also the only SSO flow I have ever seen that fundamentally cannot work if you have more than one account remembered on your device. So far the only way I’ve found to get it to let you log out of account A and then log into account B is to clear all cookies otherwise it gives you permission denied errors. Have no idea how it can be this horrible

Would container tabs solve that? They're pitched as helping separate work and personal logins.

Firefox's? Yep. Edge's? Bloody hell no.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#206

    “GCC High reviewers saw problems everywhere, both in what they were able to evaluate and what they weren’t. To them, most of the package remained a vast wilderness of untold risk.  Nevertheless, FedRAMP and Microsoft reached an agreement, and the day after Christmas 2024, GCC High received its FedRAMP authorization.”
How big was the ballroom donation?

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#207
post #56

Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.

The problem is modern MS doing three contradictory things at the same time: - FB's move fast and break things . Constantly launching new libs. - Linus's we do not break user space . Great commitment to backwards compatibility. - Never deprecating dead products until they've been de facto abandoned for like decades. This combination means every MS product is a labyrinth of overlapping APIs with no guidance as to which…

> and there's no way of knowing which are which

Especially not after the last round of cuts, some of the people they let go made my jaw drop.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#208
post #54

Earlier quoted context omitted.

It is also the only SSO flow I have ever seen that fundamentally cannot work if you have more than one account remembered on your device. So far the only way I’ve found to get it to let you log out of account A and then log into account B is to clear all cookies otherwise it gives you permission denied errors. Have no idea how it can be this horrible

Would container tabs solve that? They're pitched as helping separate work and personal logins.

I use temporary-containers on firefox and they are a marvel for working with microsoft's stuff, which absolutely doesn't anticipate two accounts working on one browser.

Of course "open in incognito mode" works for this as well, just less automatic.

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#209
It sucks so bad to be a software dev today. We simultaneously have to worry about:

- Market monopolies reducing options/leverage

- Outsourcing

- AI automation

- Complexity explosion

These days, every company which has money is using some horrible clunky platform/infra and we spend 99% of our time just working around limitations of those platforms; Problems which were created artificially and don't need to exist... And at the same time we're expected to meet deadlines while almost all of the challenges we face involve certain critical aspects that are totally outside of our control and require us to wait for someone else to fix stuff while we work around it with some crappy solution and we can't just switch platforms or write it from scatch (which would be easier for a lot of us) because the organization forces us to use a particular platform because of the pretext that they are SOC2 compliant. It's total BS!

Not only we have to worry about threats to our jobs, when you look at who is being rewarded in this industry; it's essentially people who create bloat/unnecessary complexity and build these horrible products.

The industry is full of horrible products that everyone uses. There is no incentive for software engineers to be competent because look at what the market rewards!

This in turn affects organization politics; everyone who has some leverage over the platforms is (at least subconsciously) looking for ways to sabotage the tech to maximize billable hours to fix it later... Fixing the platform is their bread and butter so of course they never want to fix it completely. Anyone who tries to do the right thing runs into issues with managers for missing deadlines which they have ZERO control over due to underlying constraints of the platforms they are forced to use. The people 'maintaining' the platforms don't have deadlines do they? They can keep making money from the shit they produce by ensuring they stay shitty and ensuring that the people who actually have deadlines and actually try to get stuff done can't meet them!

Re: Despite doubts, federal cyber experts approved Microsoft cloud service

#210
post #130

Earlier quoted context omitted.

I ran a one of the largest multi-cloud service across azure, aws and gcp. Azure was hands down, obvious to everyone involved the worst technically. In capabilities, bugs/correctness, availability and support.

I can only speak from the perspective of someone who used/admined in all those 3 environments. I'm surprised you ranked google's support above microsoft. I've also seen bugs that would be unusual in other clouds, but other clouds have other pros/cons as well. GCP for example is capable, but it is tedious to use, and even harder to log/audit. Of all 3 CSPs azure has the best identity management system. they're the wor…

The GCP support was fine, not great. For specific problems that you could provide data for and ideally a reproduction they were very good. But if you had feedback or concerns about how something was designed, or a missing feature they were useless (all of support, sales and product)
Post reply on HN