Live data from Hacker News

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

trustedsec.com

71–80 of 116 posts

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#71

Earlier quoted context omitted.

Isn't it an age thing mostly? Younger admins hate Microsoft with a passion it seems to me. Or is just my circle of acquaintances?

Europeans bizarrely love Azure.

from my experience it's more of a business guy/executive thing, they see Microsoft as a reliable, low-risk vendor which can speak their language. "nobody ever got fired for buying IBM" type thing

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#72

The state of cyber-security is a joke given that the entirety of civilization depends on these systems to function. It's like we transferred all our stuff into a boat with a gaping hole in the bilge plugged with a wad of duct tape and started sailing towards the open ocean. Forget putting the cart before the horse, the old mare is still in the barn and cart is about 3 counties over, upended in a ditch.

Worse yet the industry insists you can fix the hole by putting more guard towers with machine gun nests on the deck

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#74
post #52
post #25

Earlier quoted context omitted.

They still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that. I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.

Titles are editorialised and space limited. The first couple lines in the article linked above make the nuance pretty clear. [edit: 'pretty' instead of 'perfectly']

You are defending not just clickbait, but libelous clickbait.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#75
post #25

Earlier quoted context omitted.

They still lied, because they didn't say "X is shit" but "Z said that X is shit", however Z apparently never said that. I have become very cautious of such stories for this very reason. Who gets how much blame has a lot to do with "culture" or momentum. Bashing Microsoft for example is always super fine, but at multiple occasions I found the facts to be much more nuanced.

If a slop engine calls a slop company slop, has anyone really lost?

We lost, for one of us got tricked to bring it here.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#77

Yesterday ProPublica and ArsTechnica published a takedown of Azure: "Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway" ... https://arstechnica.com/information-technology/2026/03/feder...

In which one expert called the documentation provided "a pile of shit", which propublica took the liberty of extending to Azure itself

In those types of reviews/audits, documentation is the first indicator of whether a security organization has their act together. It's about building a trust relationship between the accreditor and contractor that will have to endure for years, as nation-state level actors throw their resources at finding vulnerabilities. MS couldn't do this or couldn't be bothered to do this. So shit documentation -> shit security processes and operations -> shit security -> shit cloud product in a government context. So the title wasn't that much of a stretch.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#78
post #74
post #52

Earlier quoted context omitted.

Titles are editorialised and space limited. The first couple lines in the article linked above make the nuance pretty clear. [edit: 'pretty' instead of 'perfectly']

You are defending not just clickbait, but libelous clickbait.

It's only libelous if it's not true. This vulnerability says otherwise.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#80
post #19

Earlier quoted context omitted.

Ah yes, back when the US actually had cyber defence and experts capable of working in their respective fields.

They're the ones that had the Microsoft tech procured and implemented.

There's a decent chance they're the ones who said "no!" and got overruled.

(See also: quite a few bits of COVID mitigation)

Post reply on HN