Live data from Hacker News

Everything authenticated by Microsoft is tainted

graz.social

311–320 of 381 posts

Re: Everything authenticated by Microsoft is tainted

#312
post #310

Earlier quoted context omitted.

Hi, person here who said that this is hyperbole. I said that because it states unfounded things in an extremely confusing way that implies that they are facts. No question, this was a very bad breach and I hope to learn more about it as the investigation continues. Anyways, I've worked at companies that are absolutely targeted by nation states.

We are not talking about a vulnerability in Azure's system here, we are talking about a vulnerability that was exploited . The worst has happened, somebody got in and grabbed that key. The idea that an attacker went to this length to get the key and then did nothing with it is absurd.

No one is saying they did nothing with it. In fact, we know at least that they accessed a ton of emails of Gov't employees.

Re: Everything authenticated by Microsoft is tainted

#313

Earlier quoted context omitted.

So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.

A released 0day is an oxymoron..

I have a 0 day. I release it. I released the 0 day.

Re: Everything authenticated by Microsoft is tainted

#314
post #221

Earlier quoted context omitted.

Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.

FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8

Thanks. I used to have that on a piece of paper taped to my tower. I don't have that tower but instantly recognized it.

Re: Everything authenticated by Microsoft is tainted

#315
post #221

Earlier quoted context omitted.

One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.

Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.

[Laughs in Trusting Trust Problem]

Re: Everything authenticated by Microsoft is tainted

#316
post #306

Earlier quoted context omitted.

So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.

Evertime a 0day thar granted privilege escalation was found on installed bins/libs, we ran a script that looked at setsuids on anything and everything and did a report on what was found. We managed to find a crypto miner once. Obviously I won't run it on my personal computer, but i'm not renting my pc to anyone.

Literally no one is suggesting that they don't perform a thorough investigation.

Re: Everything authenticated by Microsoft is tainted

#318
post #44

Earlier quoted context omitted.

Funny as this was one of the winning arguments when we went to the cloud, couldn’t possible be safer to host your own, right ? RiGhT?

This has largely held true for AWS and I think it's still a meaningful argument in a broader discussion when determining how you want to build your company infrastructure.

I do too, but we are talking about a major vendor here.

Re: Everything authenticated by Microsoft is tainted

#319

Earlier quoted context omitted.

I'm not so convinced a LLM remixing all the tutorial blogs its ingested is a meaningful quality step above those tutorial blogs themselves. Earlier this year we had a linux task that was above the normal complexity my team deals with. So a few people threw it at chatgpt and were amazed at how good the results were. In reality, it was full of outright factual inaccuracies and non-breaking bad decisions. But their skil…

You should point out to all of them now what the consequences would have been of blindly following the LLM. It's an important lesson they can and should learn from.

Nah dog, I'm good. I'm not young, eager and naive anymore. "Growing the team's skills" and "working towards company goals" are siren calls. I know how to swim in my own lane.

Re: Everything authenticated by Microsoft is tainted

#320
post #270

Earlier quoted context omitted.

Why is there no way of knowing? I would think Microsoft is able to do forensic snapshot comparisons for their datacenters -- at least, I would assume a trillion dollar company does.

Establishing that ability costs money (i.e. having snapshots & co.), and actually executing it costs further money. Absent either customers paying for it, or regulations requiring it, Microsoft certainly won't sink money out of the goodness of their heart. I don't believe there are a lot of regulations for this — and how many customers do you think would pay for something like this? Realistically? :-(

I mean, they at least have SOC2 compliance, and obviously a lot more (FEDRAMP). To get those certifications an auditor is going to make sure you have basic shit in place like logging, etc.
Post reply on HN