Live data from Hacker News

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

trustedsec.com

51–60 of 116 posts

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#51

Earlier quoted context omitted.

Isn't it an age thing mostly? Younger admins hate Microsoft with a passion it seems to me. Or is just my circle of acquaintances?

Silicon Valley likes to pretend Microsoft doesn't exist. I... get it. The FAANGS needed to scale to a level where paying per-core licensing fees for an operating system was simply out of the question, not to mention the lack of customisability. As a consequence, they all adopted Linux as their core server operating system. Then, as their devs made millions in share options, they all scattered and made thousands of li…

That may have been the story, but avoiding paying per-core licensing fees for an operating system is the only sane decision.

Operating systems and other applications that demand per-core licensing fees exist only because the people who buy them do not use their own money for this, so they do not care how much money they are wasting.

Most companies waste huge amounts of money not only for software, but for many other things, because those who have the power to make purchasing decisions have personal interests that are not aligned with what is really optimum for the company, while those who might have the best interests of the company in mind do not have the knowledge that would allow them to evaluate whether such purchasing decisions are correct.

The survival of Windows Server is not justified by any technical advantages. A few such advantages exist, but they do not compensate the huge PITA caused by licensing. I worked at a few companies where Windows Server was used and replacing it with either Linux or FreeBSD was always a great improvement, less by removing the payments for the licensing fees, but by providing complete freedom to make any changes in the environment without the friction caused by the consequences that such changes could have in modified licensing fees.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#52
post #25

Earlier quoted context omitted.

And they weren’t wrong

They still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that. I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.

Titles are editorialised and space limited. The first couple lines in the article linked above make the nuance pretty clear.

[edit: 'pretty' instead of 'perfectly']

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#53
post #10

Puts me in mind of this scathing report from CISA on how a state-sponsored group broke into Microsoft and then into the State Department and a bunch of other agencies. Reads like a heist movie. https://www.cisa.gov/sites/default/files/2024-03/CSRB%20Revi... What I found most incredible about the story is that it wasn't Microsoft who found the intrusion. It was some sysadmin at State who saw that some mail logs did no…

Don't worry CISA and any other involved regulator were gutted by DOGE.

[flagged]

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#54

Earlier quoted context omitted.

> This wasn't about the GDPR; you were being told to sod off. Vast misunderstanding of GDPR by the clowns implementing it is also possible; or just "can't be arsed so hide it all"

More generously, they were applying GDPR rules in the correct manner, but to a different scenario: Microsoft customers being supported by Microsoft subcontractors that don't need to know the customer PII to do their job. Most businesses using a public cloud need to log the activities of their staff accessing their own systems, which has an entirely different set of policies. A similar example is Azure Application Ins…

This has nothing to do with being within the jurisdiction of the GDPR or not. There are a variety of national laws worldwide which effectively overlap with or subset the GDPR (because most governments do seem to find protection of personal data worthwhile for their citizens), and Microsoft has to deal with those (either at the behest of their customers or because they are required to).

But Microsoft can totally handle applying the GDPR correctly. They have a lot of countries as customer which use Azure in some capacity and where the need for comprehensive audit logging exists. What you were seeing is a bug; or rather a design flaw, marked as WONTFIX. Some customer rep was giving you the two-fingered salute by starting with 'but GDPR…'.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#55
post #19

Puts me in mind of this scathing report from CISA on how a state-sponsored group broke into Microsoft and then into the State Department and a bunch of other agencies. Reads like a heist movie. https://www.cisa.gov/sites/default/files/2024-03/CSRB%20Revi... What I found most incredible about the story is that it wasn't Microsoft who found the intrusion. It was some sysadmin at State who saw that some mail logs did no…

Ah yes, back when the US actually had cyber defence and experts capable of working in their respective fields.

They're the ones that had the Microsoft tech procured and implemented.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#56

Earlier quoted context omitted.

Isn't it an age thing mostly? Younger admins hate Microsoft with a passion it seems to me. Or is just my circle of acquaintances?

Silicon Valley likes to pretend Microsoft doesn't exist. I... get it. The FAANGS needed to scale to a level where paying per-core licensing fees for an operating system was simply out of the question, not to mention the lack of customisability. As a consequence, they all adopted Linux as their core server operating system. Then, as their devs made millions in share options, they all scattered and made thousands of li…

This is definitely not it. If you want free use of an OS in CI/CD and testing, use Linux. If you want Docker or Kubernetes, use Linux. No one thinks it's the only option, but you'd have to have a really good reason to pay to use Windows on the server.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#57
post #21

Azure Entra is an example of making a system so complex that nobody can understand it entirely. I'm fairly experienced in access control systems, OIDC, crypto, etc. but I was not able to understand how it all fits together. Google Cloud is simplistic in comparison. AWS is full of legacy complexity (IAM policies, sigh) but it's fairly self-contained and can be worked around by splitting stuff into accounts. I have not…

> I have not looked at Oracle cloud yet. Is it any better than MS?

At last glance it's far more like infrastructure leasing, with some Oracle twists, such as hosted Oracle databases, than it is full on cloud services. But this was a few years ago.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#58
post #25

Earlier quoted context omitted.

They still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that. I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.

It's true, they lied. But, paradoxically, in this case, while they lied about details, the conclusion is still true: Azure is very far from AWS and GCP as far as security is concerned. I have my own suspicions why it is so, but the reasons are not important, what counts is the final conclusion: if you really care for security, you'd better chose one of the other two.

“Fake but accurate.”

ProPublica has an agenda, and they slant their reporting to push it.

You can like their agenda and support this effort, but it’s not journalism.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#59

Earlier quoted context omitted.

Isn't it an age thing mostly? Younger admins hate Microsoft with a passion it seems to me. Or is just my circle of acquaintances?

Europeans bizarrely love Azure.

As a European, you’re on your own there…

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#60
The state of cyber-security is a joke given that the entirety of civilization depends on these systems to function. It's like we transferred all our stuff into a boat with a gaping hole in the bilge plugged with a wad of duct tape and started sailing towards the open ocean. Forget putting the cart before the horse, the old mare is still in the barn and cart is about 3 counties over, upended in a ditch.
Post reply on HN