Earlier quoted context omitted.
Establishing that ability costs money (i.e. having snapshots & co.), and actually executing it costs further money. Absent either customers paying for it, or regulations requiring it, Microsoft certainly won't sink money out of the goodness of their heart. I don't believe there are a lot of regulations for this — and how many customers do you think would pay for something like this? Realistically? :-(
I mean, they at least have SOC2 compliance, and obviously a lot more (FEDRAMP). To get those certifications an auditor is going to make sure you have basic shit in place like logging, etc.
Everything authenticated by Microsoft is tainted
321–330 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#322Earlier quoted context omitted.
The problem is that you have no way to verify what may or may not have been done by malicious actors using compromised keys in the meantime. If you have immutable, permanent audit logs, you can go through all actions authenticated with something directly or indirectly signed by the leaked key. However, building such an audit log in a way that someone with maximum permissions still can't tamper with it is not easy — a…
Could this be said for just about _any_ intrusion? Once you’ve been compromised, is there any way to know that no back doors were installed? Is this situation different than others?
Re: Everything authenticated by Microsoft is tainted
#323Earlier quoted context omitted.
I think of our company as an "indie" startup and we use Office365 for email. There are a bunch of things that I hate about it but what are the plausible alternatives? Before we moved to O365 85%+ of our emails landed in spam folders.
Fastmail is very good and has been running for 24 years, with good deliverability. Migadu I hear is good. There's quite a few email providers that aren't Microsoft or Google that have their shit together.
Re: Everything authenticated by Microsoft is tainted
#324Such hyperbole. This was a bad breach, for sure, and we may not fully understand its scope at this point. But... > They were able to implant #backdoors, self-made keys, ... all over the place. I mean, emphasis on able to , as in "in theory, based on what I know, it is POSSIBLE", not that they did . > If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get ri…
You linked Microsoft's investigation report on the exploit.
The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that, dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its intended purpose and then executed on that.
And you don't believe they left persistent backdoors in some high-profile targets?
The conclusions being drawn are … entirely appropriate. Your argument maaaaaybe makes some sense applied to general public random cloud customers. Backdooring indiscriminately just increases the risk of discovery. But large companies and government users? You have to assume compromise, anything else is incredulously naïve.
cf.:
https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...
> Storm-0558 operates with a high degree of technical tradecraft and operational security. The actors are keenly aware of the target’s environment, logging policies, authentication requirements, policies, and procedures. Storm-0558’s tooling and reconnaissance activity suggests the actor is technically adept, well resourced, and has an in-depth understanding of many authentication techniques and applications.
Re: Everything authenticated by Microsoft is tainted
#325Earlier quoted context omitted.
> Of course you patch it, but you don’t assume that every system affected by this 0-day got exploited. Uhh, what? Of course you do. Why give the benefit of the doubt to hackers who hacked you with malicious intentions? That's the type of security nonsense that I'd expect from... Well, Microsoft lol
So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.
That's pretty much the only option if you safeguard valuable data for your customers. Yes, it's expensive to get breached, so take precautions to make it a rare event and contain it as much as possible when it happens.
I don't think the article is unreasonable. This is cloud infrastructure sold to companies with defense industry contracts where breaches are taken seriously.
Re: Everything authenticated by Microsoft is tainted
#326Earlier quoted context omitted.
I mean, they at least have SOC2 compliance, and obviously a lot more (FEDRAMP). To get those certifications an auditor is going to make sure you have basic shit in place like logging, etc.
yeah, but SOC auditors barely understand the stuff you’re providing as proof.
Re: Everything authenticated by Microsoft is tainted
#327Earlier quoted context omitted.
So every time a 0day is released you buy a net new device? Cause there are 0days like... every day.
If you find yourself owned by, and not only from a 0-day, then yes, you wipe everything clean and re-build with mitigations in place from the start as to not get reinfected in the process. That's pretty much the only option if you safeguard valuable data for your customers. Yes, it's expensive to get breached, so take precautions to make it a rare event and contain it as much as possible when it happens. I don't thin…
Re: Everything authenticated by Microsoft is tainted
#328Earlier quoted context omitted.
Have you checked if you have a Microsoft CA installed to your system?
More seriously, on my Debian stable system: $ dpkg -l ca-certificates Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-===============-============-============-================================= ii ca-certificates 20230311 all Common CA certif…
Re: Everything authenticated by Microsoft is tainted
#329While the post is great, terrifying, and seems to contain only true and verifiable information, I’m not sure what we expect. „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society. Wouldn’t it be more reasonable to teach: 1. You have no privacy, it is impossible to ensure or guarantee…
I keep my secrets in a safe with an old school lock. My elderly aunt keeps her secrets on a notepad in her desk. I suppose a spy or a housecleaner (if she had one) could know her secrets but it won't be "hacked". The whole "you have no privacy or no security" is false and only impacts the terminally online. Do what the intelligence agencies do. Stop letting other people store your secrets. Put them in a nice heavy lo…
Having a firearm only works as protection if (A) you are present and armed 24/7 to protect your safe, (B) you are actually willing to shoot and (C) capable of doing so better than your assailant.
In a business context, if the company is large enough, it might well be worth hiring day-and-night security guards and heavy steel safes. But for the average PC user, the security can be improved much more effectively with simple improvements like creating passwords with 'diceware' or using separate accounts for financial tasks.
Re: Everything authenticated by Microsoft is tainted
#330This issue is specific to Azure and Microsoft. I find AWS and GCP to be fine. Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure. The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing. I als…
Can you explain this more? What's wrong with AWS compared to Azure?