It should really horrify everybody that Microsoft is not investing more into Azure considering they host the worlds most known LLM (and used?).
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
61–70 of 116 posts
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#62Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#63Earlier quoted context omitted.
Ah yes, back when the US actually had cyber defence and experts capable of working in their respective fields.
They're the ones that had the Microsoft tech procured and implemented.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#64Earlier quoted context omitted.
It's true, they lied. But, paradoxically, in this case, while they lied about details, the conclusion is still true: Azure is very far from AWS and GCP as far as security is concerned. I have my own suspicions why it is so, but the reasons are not important, what counts is the final conclusion: if you really care for security, you'd better chose one of the other two.
“Fake but accurate.” ProPublica has an agenda, and they slant their reporting to push it. You can like their agenda and support this effort, but it’s not journalism.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#65Puts me in mind of this scathing report from CISA on how a state-sponsored group broke into Microsoft and then into the State Department and a bunch of other agencies. Reads like a heist movie. https://www.cisa.gov/sites/default/files/2024-03/CSRB%20Revi... What I found most incredible about the story is that it wasn't Microsoft who found the intrusion. It was some sysadmin at State who saw that some mail logs did no…
Don't worry CISA and any other involved regulator were gutted by DOGE.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#66Imagine if Microsoft spend more attention on making Windows suck less and Azure better, because in my eyes it is not as awful as whatever the heck AWS' dashboard is supposed to be. Azure has a rich set of developer libraries for their offerings, and their dashboard isn't nearly as awful as AWS. I've never used GCP so I can't comment on theirs, or their libraries. It should really horrify everybody that Microsoft is n…
A bug in the software is a bug in the process, and the process is the job of leadership. They've never cared about software quality. They'll put out lots of books about it, lots of talks, lots of claims. But they won't actually put out quality software. It's not in their DNA, never was.
It's not their size nor their age that makes this hard for them. Plenty of larger, older companies put out better product ever day. It's just them. Someone in each size class is the best, and someone else is the worst. MS has been the worst the entire time.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#67Earlier quoted context omitted.
Every security engineer I know working at Azure is on the verge of self-harm because of the current situation, or is the dumbest IC I've ever met and somebody I think should have never become a security engineer. Sample size ~12.
That is quite the indictment.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#68Earlier quoted context omitted.
They're the ones that had the Microsoft tech procured and implemented.
This, exactly. There are so many "cyber experts" working for the U.S. government, and the vast majority are just cogs in a machine constructed by executive leadership who will always prefer inertia over radical changes.
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#69Earlier quoted context omitted.
Don't worry CISA and any other involved regulator were gutted by DOGE.
Is that true or you’re just assuming it’s so?
Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
#70Earlier quoted context omitted.
Don't worry CISA and any other involved regulator were gutted by DOGE.
Is that true or you’re just assuming it’s so?
---
[1] https://techcrunch.com/2025/03/11/doge-axes-cisa-red-team-st...