Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

211–220 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#211

He's absolutely right, you really can't trust anything they sign anymore. This is why Microsoft has been so defensive about their stance since it occurred. I've said the same since the news got out, but all my Microsoft-y friends I told didn't care. In fact, they all shrugged it off like "what are ya gonna do?" That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To…

If it is the case that it is going to be extremely risky to run of MS supplied infrastructure (including Windows) we should see insurance premiums sky-rocket for companies and organisations using those platforms. Eventually, it will become cheaper to migrate off the MS platforms.

This is mixed with an ever increasing legislative push and higher fines for leaking PII.

Re: Everything authenticated by Microsoft is tainted

#212
Off-topic, but I was surprised to see that this was a Mastodon server created specifically for the people of Graz, Austria, a city I lived in for a semester in college and have very fond memories of. I like the idea of providing self-hosted services for their local region, and I wish them well. I'd consider joining myself if I wasn't so ashamed of my poor German skills...

Re: Everything authenticated by Microsoft is tainted

#213
post #182

I think this is a pretty big leap to conclusions. Some guy on Mastdon doesn’t know what Microsoft’s security team knows about the breach. It’s irresponsible to make broad claims like this, that everything in Microsoft’s cloud has to be replaced to mitigate the breach. That doesn’t pass the sniff test. I get that Microsoft has a vested interest in mitigating the PR aspect of it, but I doubt they’ve just done nothing t…

if you follow all the links you'll find out that the keys stolen gave the hackers (probably the Chinese state) access to all managed MS applications for all customers; and enabled faking having an organizational account for arbitrary MS customers.

This essentially makes all key western companies and public orgs, hosted on azure, probable targets. It's highly unlikely that they only stole state dept. emails, when they had access to banks, finical orgs, etc.

Indeed, their very ability to steal emails from the US state dept! makes it likely a breach at other less protected vital biz/orgs occured.

The whole of the azure cloud, and esp. the whole of managed MS apps at major institutions was compromised for at least a year. This is apocalyptic.

Re: Everything authenticated by Microsoft is tainted

#214

Earlier quoted context omitted.

I'm honestly surprised they haven't been trying to bundle GitHub more (or vice versa). It does work and it is very compelling, at least on the tin. The problem is convincing powers that be that it doesn't do what it says is borderline impossible. The most they've built is equal parts astounding and terrifying. In a sort of funny twist I feel like this is an area Google could really excel in if they got their shit tog…

Observation from german companies (smaller eg 250 employees, mid, big): Azure DevOps is used. Noone uses GitHub. I am sure it's widespread, but rather for small companies

Where I work (globally well-known brand) GitHub is chosen as the future platform, since apparently that is where MS invests more. DevOps is seen as legacy. Curious if others have different info.

Re: Everything authenticated by Microsoft is tainted

#215

Earlier quoted context omitted.

> be a slave to Microsoft Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business , I think you are completely fucking yourself over with this sort of attitude. How much business convenience are you willing to squander over thes…

This would sound like ChatGPT if I didn't know better... All of your arguments are "made up" arguments, they contradict themselves or each other or assume some very unlikely situations, especially on behalf of what the post you replied to wanted to say, where it's clear it's not what it wanted to say. Let's dive in! > So are you suggesting that the most practicable alternative is to be a slave Clearly, the post you r…

You said it best yourself: The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed.

While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Linux is intrinsically better?

Re: Everything authenticated by Microsoft is tainted

#216

Earlier quoted context omitted.

If the single supplier supplied the correct medicine, and it works, why worry?

Evidently it was not the correct medicine.

More like one batch was deficient and was recalled as soon as the issue was discovered.

Re: Everything authenticated by Microsoft is tainted

#217
post #76

Earlier quoted context omitted.

HSM’s are super inconvenient obviously, and as Mr. Robot showed not perfect. So why bother? /s

Apparently they might also be backdoored by the NSA: https://news.ycombinator.com/item?id=37571014

Frankly is this important? If the NSA is a threat to you do you have any business trusting MS?

Re: Everything authenticated by Microsoft is tainted

#218
post #187
post #148

The writeup by Microsoft is far more illustrative than the frankly confusing post and blog from the main article: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... Also, unlike what (I think) is being claimed here, Microsoft did fix the issue after learning about it: https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...

A lot later. The damage was done. Whoever had those keys could have had access to all MS accounts and services. And those people had already hacked an engineer's account. Because the chances of stumbling upon this key when only hacking one engineering account are very low, it's reasonable to assume many MS engineering accounts had already been hacked. Basically, your MS account is not safe.

> many MS engineering accounts had already been hacked

This isnt being focused on enough here. MS is set up in such a way that there are individual members of staff, with individual devices, that just need to be compromised for all their infrastructure is compromised.

This fact alone means that's its near certainly presently compromised. states have the resources to place an engineer at MS, let alone compromise one of their devices.

This, critically, is not necessary. There is nothing technologically necessary about one person, or one device, having the keys to the kingdom. It's security malpractice.

Re: Everything authenticated by Microsoft is tainted

#219
post #199
post #178

Earlier quoted context omitted.

My entire adult life and career has been MS free. It’s not that rare.

Your whole office? Like sure whatever, I don't use Windows but that doesn't count. The IT directory server is Azure AD and is the SSO for everything non-dev related Slack/JIRA/the office VPN.

I did work at google for 15 years and sun before that

Re: Everything authenticated by Microsoft is tainted

#220
> Security experts like Mike Kuketz think that most probably we need to consider all Microsoft systems that are using their cloud authentication including all Windows hosts are compromised.

This is a giant claim.

It does seem theoretically possible that a stolen signing key could have been used as part of a bigger attack to access critical services like Windows Update or the Azure control plane, but it does feel like someone would have noticed that kind of systemic compromise.

Post reply on HN