Live data from Hacker News

Data accidentally exposed by Microsoft AI researchers

wiz.io

51–60 of 238 posts

Re: Data accidentally exposed by Microsoft AI researchers

#51
post #4

Earlier quoted context omitted.

My wife and I just rewatched WarGames for the millionth time a few nights ago. The level of cybersecurity incompetency in the early 80's makes sense; computers (and in particular networked computers) were still relatively new, and there weren't that many external users to begin with, so while the potential impact of a mistake was huge (which of course was the plot of the movie), the likelihood of a horrible thing hap…

That modem setup in Wargames is still a thing for many organizations including some banks and telcos. Not naming names but I suspect the modems will be around for a very long time. Some have a password on their modem but they are usually very simple. Their only saving grace is that they are usually in front of a mainframe speaking proprietary MML that only old fuddy duddies like me would remember. There are a few of…

> I suspect the modems will be around for a very long time.

No they won't.

'Dial up' modems need a PSTN line to work. The roll out of full fibre networks means analogue PSTN is going the way of the dodo. You cannot get a new PSTN line anymore in Blighty. In Estonia and the Netherlands (IIRC) the PSTN switch off is already complete.

Re: Data accidentally exposed by Microsoft AI researchers

#52
post #31
post #5

Part of me thought "this is fine as very few could actually download 38TB". But that's not true as it's just so cheap to spin up a machine and some storage on a Cloud provider and deal with it later. It's also not true as I've got a 1Gbps internet connection and 112TB usable in my local NAS. All of a sudden (over a decade) all the numbers got big and massive data exfiltration just looks to be trivial. I mean, obvious…

with a 1Gbps connection you're still looking at ~248 hours to download, and that's if the remote server can keep up, which it almost certainly can't this is assuming by 1Gbps you mean 1 Gigabit/s rather than 1 Gigabyte/s

But you don't need to download everything. Even 1/10th of that could be juicy enough. Or 1/100th.

Re: Data accidentally exposed by Microsoft AI researchers

#53
post #31
post #5

Part of me thought "this is fine as very few could actually download 38TB". But that's not true as it's just so cheap to spin up a machine and some storage on a Cloud provider and deal with it later. It's also not true as I've got a 1Gbps internet connection and 112TB usable in my local NAS. All of a sudden (over a decade) all the numbers got big and massive data exfiltration just looks to be trivial. I mean, obvious…

with a 1Gbps connection you're still looking at ~248 hours to download, and that's if the remote server can keep up, which it almost certainly can't this is assuming by 1Gbps you mean 1 Gigabit/s rather than 1 Gigabyte/s

Not sure where 248 hours came from.

38 terabytes = 304 terabits.

304 terabits / 1 gigabit/second = 304,000 seconds

304,000 seconds =~ 84 hours. Add 20% for not pegging the line the whole time and the limits of 1gbps ethernet, and perhaps 100 hours is reasonable.

Re: Data accidentally exposed by Microsoft AI researchers

#54
post #4

Just proves how hard it cloud security now. 1-2 mistake and you expose TB's. Insane.

My wife and I just rewatched WarGames for the millionth time a few nights ago. The level of cybersecurity incompetency in the early 80's makes sense; computers (and in particular networked computers) were still relatively new, and there weren't that many external users to begin with, so while the potential impact of a mistake was huge (which of course was the plot of the movie), the likelihood of a horrible thing hap…

> wardialing

Get a load these guys honey, you could just dial straight into the airline.

Re: Data accidentally exposed by Microsoft AI researchers

#56

> This case is an example of the new risks organizations face when starting to leverage the power of AI more broadly, as more of their engineers now work with massive amounts of training data. It seems like a stretch to associate this risk with AI specifically. The era of "big data" started several years before the current AI boom.

[deleted]

Re: Data accidentally exposed by Microsoft AI researchers

#57
post #5

Part of me thought "this is fine as very few could actually download 38TB". But that's not true as it's just so cheap to spin up a machine and some storage on a Cloud provider and deal with it later. It's also not true as I've got a 1Gbps internet connection and 112TB usable in my local NAS. All of a sudden (over a decade) all the numbers got big and massive data exfiltration just looks to be trivial. I mean, obvious…

The article mentions that it wasn't a read-only token, meaning you could at least edit and delete files too.

Re: Data accidentally exposed by Microsoft AI researchers

#58
This stands out

> Our scan shows that this account contained 38TB of additional data — including Microsoft employees’ personal computer backups.

Not even Microsoft has functioning corporate IT any more, with employees not just being able to make their own image-based backups, but also having to store them in some random A3 bucket that they're using for work files.

Re: Data accidentally exposed by Microsoft AI researchers

#59

Earlier quoted context omitted.

That modem setup in Wargames is still a thing for many organizations including some banks and telcos. Not naming names but I suspect the modems will be around for a very long time. Some have a password on their modem but they are usually very simple. Their only saving grace is that they are usually in front of a mainframe speaking proprietary MML that only old fuddy duddies like me would remember. There are a few of…

what does this have to do with a "modem" per se?

The parent comment was about the movie Wargames and the questionable security of the 80's that is still in use today. That security in Wargames was a modem that provided access to a subsystem of the WOPR mainframe named "Joshua". Joshua had super-user privs on the mainframe.

It was likely meant to be a temporary means for the system architect to monitor and improve the system after it was deployed but then life changing circumstances may have distracted his attention away from decommissioning the modem. The movie still holds up today and is worth a watch. Actually it may be more pertinent now than ever.

Re: Data accidentally exposed by Microsoft AI researchers

#60
post #5

Part of me thought "this is fine as very few could actually download 38TB". But that's not true as it's just so cheap to spin up a machine and some storage on a Cloud provider and deal with it later. It's also not true as I've got a 1Gbps internet connection and 112TB usable in my local NAS. All of a sudden (over a decade) all the numbers got big and massive data exfiltration just looks to be trivial. I mean, obvious…

Agree, this is extremely dubious:

5gbps and 10gbps residential fiber connections are common now.

12TB hd's cost under $100, so you would only need about $400 of storage to capture this, my SAN has more capacity than this and I bought basically the cheapest disks I could for it.

It only takes one person to download it and make a torrent for it to be spread arbitrarily.

People could target more interesting subsets over less interesting parts of the data.

Multiple downloaders could share what they have and let an interested party assemble what is then available.

Post reply on HN