This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".
Everything authenticated by Microsoft is tainted
51–60 of 381 posts
Re: Everything authenticated by Microsoft is tainted
#52In the end, it turns out it was not accepting expired certs -- there was another auth method superseding the certs -- but the behaviour I saw in this case was not unusual to encounter.
Microsoft has many excellent engineers, even in security. But decades of culture rot take longer than a few years to fix, and a lot of old-timer Microsofties have this "not my problem" viewpoint that can lead to major security risks. No doubt, the way Microsoft has handled this year's layoffs -- staggered, leaving people in the lurch and in serious stress for months on end -- has wiped out much of the progress they've made under Satya.
tl;dr I'm not surprised by (a) Microsoft having breaches and (b) Microsoft not dealing with security issues in a timely manner.
Re: Everything authenticated by Microsoft is tainted
#53This seems overly hyperbolic and alarmist. I do not think the sources prove the scope of breach the post asserts ("all of Microsoft"), seems more like a temporary key leak that was subsequently revoked.
[flagged]
Re: Everything authenticated by Microsoft is tainted
#54Earlier quoted context omitted.
These problems are specific to Microsoft though; outside of service outages and customer misconfiguration, AWS and GCP don't have a history of such incidents.
Was the Capital One breach not a result of gross internal malpractice on the part of Amazon? That allowed an Amazon employee to gain priviledged access to CC data in Capital One's environment.
There are multiple analysis of that breach available. Pick one.
Here’s a starter.
Re: Everything authenticated by Microsoft is tainted
#55Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.
On-prem is very expensive compared to cloud.
My current employer handles things where internal service at the org are on-prem while customer facing services are cloud. Even the cloud stuff backs up to an on-prem storage system (though it also gets backed up to an off-site S3 provider).
Re: Everything authenticated by Microsoft is tainted
#56This story has been widely under-reported and the impact is potentially huge. My beef with MS is this: the keys were leaked in 2021 and were still signing authentication tokens in 2023, but there's not a single Azure service that allows me to enter credentials with a 2 years duration. It's a classic case of "do as I say, not as I do".
Re: Everything authenticated by Microsoft is tainted
#57Re: Everything authenticated by Microsoft is tainted
#58Re: Everything authenticated by Microsoft is tainted
#59People fled from mainframes, now they are flocking to cloud...
I remember when the Network Computer was going to put Microsoft out of business. It was Sun providing the NC and JavaOS, Netscape providing the Web Browser and anyone who wanted to license the NC to make their own. Internet was too slow then as everything was stored on the Internet, which because the Cloud model. Microsoft bundled IE with Windows to destroy Netscape and made Dotnet destroy Java.
This is embarrassing for Microsoft. All their cloud services have been hacked. Data has been leaked. Could lead to lawsuits.
Re: Everything authenticated by Microsoft is tainted
#60Give it a few years and then on-prem hardware and simple server hosting will become fashionable again.
Also even for softwares deployed on on-prem hardware, big orgs will still need single sign on, which will still be open to these kind of attacks.