Live data from Hacker News

Microsoft Teams: 1 feature, 4 vulnerabilities

positive.security

51–60 of 264 posts

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#51
post #20

Earlier quoted context omitted.

I know right? Plus MS Teams is the among the most used apps in the enterprise world how come the only good version of it is only available in Windows 11 where most workplaces aren't even pushing it to their users. The way Microsoft handles Teams annoys the crap out of me the MacOS and Linux versions are left to die basically.

It is (by far) the most horrific piece of software I'm forced to used, the UI/UX is confusing, it's a battery killer, eats all the ram (though - that's common with all electron garbage), it somehow manages to make Bluetooth headsets drop out, it significantly impacts network performance when sharing video, a lot of bugs in the calendaring system.... I could go on, but damn I just hate it.

I agree so much! It is baffling to me that so many companies/schools/individuals are actively using it. It is _so_ _bad_. Messages are lost, it reboots spontaneously, it crashes, one cannot turn off emoticons (I think (the UI doesn't help)), etc. It does not even take security seriously. What is good about that software?

And then when I talk about this with colleagues, they seem to be just fine with it...

Anyway, sorry about the rant. But it is just so nice to see that there are other people also dissatisfied with it, and that is not just me.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#52
post #49
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

At least in Germany the most common reason not to use Zoom has been privacy and data protection, not so much security. Haven't heard the security reason yet.

I believe that, at one point, it was possible for people to get into password-protected zoom rooms.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#53
post #11

> We reported the issues to Microsoft in March 2021, who has only remediated one so far I feel that I read something like this almost every single time Microsoft is mentioned in a vulnerability disclosure. What makes the company so bad at dealing with security reports? I don't expect it to be a lack of talents or resources, or is it?

Microsoft seemed to have responded to all of them though.

A response of "WONTFIX" is still a response, sure, but not the one most would want for a security-related issue.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#54
post #4

Earlier quoted context omitted.

great way to not have any software released ever

Somehow we still have medicine (they do a lot of testing before they release anything!) and doctors (they have insurance!). It would increase the barrier to releasing software massively (possibly killing the startup scene altogether), but it doesn't mean software development would end.

> Somehow we still have medicine (they do a lot of testing before they release anything!) and doctors (they have insurance!).

The fact that doctors are relatively frequently sued in the US is one of the reasons why US has very expensive healthcare. If you are rich that's fine, but almost everybody else would prefer more available (cheaper) healthcare with doctors who don't need to spend money on liability insurance.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#55
post #27

Still waiting for these guys to update their MacOS app, we use it in our company and it's so bad that our own team uses Slack.

I'm still reeling from the fact that the macOS teams app have a local privilege escalation to root vulnerability for a while. Why does ANY part of teams run as root?.

Probably to auto-update? I can't think of any other even remotely valid reason.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#56
post #33
post #13

One in this temperament: try accidently pasting a very large amount of data in the chatbox in Teams. Then spend the next 40 minutes re-starting Teams to try to remove the data from said box while your laptop tries to fly away and Teams keeps many processors and gigs of memory lit trying to parse your data. Microsoft should (but won't) reconsider the idea that one chatbox to rule many underlying types of software is a…

Even a very large amount of data pasted should not blow up a text box in 2021. I mean, on Windows you can paste an object referring to a data blob pretty sure, macOS surely has something similar and on X/Wayland you could sniff and size of data pasted in advance and do something useful. If it's plain text like JSON even 5G of plain text should not bring a text box to its knees when the memory is available, it's not b…

> still getting irritated by Firefox taking forever to render a 10M email source code in plain text when it could do something smart and render/view only the viewport that's showing.

How do you know what's supposed to be in the viewport, especially if the font isn't monospaced? You have to 'render' the entire thing at least once - at least to the point of measuring the dimensions of text (not a cheap thing) and figuring out where you have to force linebreaks. And whenever the user resizes their window horizontally or does various other things, you have to do it again.

Your typical browser is already pretty good at this - not to the point some dedicated text viewers/editors are, but pretty good.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#57
post #42
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

So you are blaming Zoom security issues coverage on Microsoft without any proof and the comment asking for evidence is flagged. What's going on HN ?

> the comment asking for evidence is flagged

The comment came from a banned account whose comments are dead by default and need to be vouched. Discussing that is as off-topic as discussing voting, and not surprisingly it’s just noise now.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#58

Earlier quoted context omitted.

> a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft Zoom had and continues to have a significant developer presence in China. Those individuals are subject to CCP coercion. There was also a time when they routed American calls through the mainland [1]. That has been fixed. But it remains excessive to cast all past criticism of Zoom as Microsoft's work. [1] https://techcrunch.com/2020/04/0…

Exactly. For all my harsh criticism of both Microsoft and Google I wish them well: I want them to tidy up and become trustworthy. Because the alternative where China becomes world leading is actually worse. For all their warts Americans and American companies have done much good and gotten way more criticism for their faults compared to others. That doesn't however mean that they should get off the hook easily, only…

No post body was provided.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#59
post #20

Earlier quoted context omitted.

I know right? Plus MS Teams is the among the most used apps in the enterprise world how come the only good version of it is only available in Windows 11 where most workplaces aren't even pushing it to their users. The way Microsoft handles Teams annoys the crap out of me the MacOS and Linux versions are left to die basically.

It is (by far) the most horrific piece of software I'm forced to used, the UI/UX is confusing, it's a battery killer, eats all the ram (though - that's common with all electron garbage), it somehow manages to make Bluetooth headsets drop out, it significantly impacts network performance when sharing video, a lot of bugs in the calendaring system.... I could go on, but damn I just hate it.

Teams is the only application that consistently has trouble finding any audio devices because it decides to manage them itself, poorly, instead of relying on system defaults.

Audio works in every other application, but sometimes Teams just decides it can't find any audio interface. Or worse, it finds one but decides "It's not working" and refuses to use it.

Using Teams in the browser is then a possible solution.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#60

Earlier quoted context omitted.

Somehow we still have medicine (they do a lot of testing before they release anything!) and doctors (they have insurance!). It would increase the barrier to releasing software massively (possibly killing the startup scene altogether), but it doesn't mean software development would end.

If we applied the same rigorous testing and verification processes in medicine to software, software development as we know it would definitely end. It would probably take years to convert a straight-forward requirement into a working piece of software. Something like Teams or VS Code that get new features added all the time would not be possible anymore and would cost tons of money. And while security issues should…

> If we applied the same rigorous testing and verification processes in medicine to software, software development as we know it would definitely end.

Good.

Post reply on HN