Live data from Hacker News

Microsoft Teams: 1 feature, 4 vulnerabilities

positive.security

81–90 of 264 posts

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#81
post #38

MS Teams is the worst software I've ever used. This is not hyperbole. A room full of monkeys on a typewriter would never create something as bad as teams.

> A room full of monkeys on a typewriter would never create something as bad as teams. Monkeys could barely create software if at all. That means you have set a low badness bar for Teams to surpass.

https://en.m.wikipedia.org/wiki/Infinite_monkey_theorem

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#83
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

As an anecdote I know of a certain top-100 company that ditched their in-house competitor to Teams because MS made them a sweeter O365 deal. For a time management forced them to use Teams even though they were still developing AND licensing the in-house competitor to other companies.

MS is really aggressive with Teams marketing (specially for large bureaucratic enterprise) and I could totally see them doing what you mention.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#84
post #61
post #36

Earlier quoted context omitted.

I remember when they stories came out they were released in a suspiciously coordinated way. Once one died off another was released to build up momentum again and keep the idea humming in the public consciousness. I figured that it was done by a big party that had a trusted relationship with tech journalists because they bigged up vulnerabilities that were relatively minor to journalists who didnt seem to be aware of…

The pattern of stories indicated that it was a thing that got attention, so people went digging for whatever they could find and push. You don't need a conspiracy for something to get way more attention than others.

I am not trying to say Microsoft did anything unlawful. However, I am suspicious that these events in 2020 were coordinated.

I remember we knew about Zoom vulnerabilities in 2018 as well but I rarely used video conferencing and definitely not for "daily stand ups" however, I wouldn't discount Microsoft tried its best to "educate" reporters.

http://paulgraham.com/submarine.html

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#85
post #11

> We reported the issues to Microsoft in March 2021, who has only remediated one so far I feel that I read something like this almost every single time Microsoft is mentioned in a vulnerability disclosure. What makes the company so bad at dealing with security reports? I don't expect it to be a lack of talents or resources, or is it?

Nine months to fix a simple issue is cracking on for the Teams division. Their tempo is almost as ponderous as their product.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#86

MS Teams is the worst software I've ever used. This is not hyperbole. A room full of monkeys on a typewriter would never create something as bad as teams.

One day they just completely fucked the ability to paste code. It worked flawlessly before and then suddenly it removes indenting, bugs out and doesn't let you exit the preformatted code block. It's so bugged, it's like they didn't even test it. They couldn't have, one day it literally worked fine and the next it was unusable and could be replicated every single time. And why there isn't the ability to just delete th…

The latest Teams bug I've encountered is an inability to write a bulleted list with more than one bullet. Each newline splits the list into a new message. No combination of Shift/Ctrl/Alt + Enter worked.

This changed, as in broke, around a week ago. At least for me, on Win 11.

Edit: Just remembered another Teams bug from a few days ago: cut text from the middle of paragraph, paste it back in earlier in the same paragraph, ... and it appears in a smaller font.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#87
post #32

Earlier quoted context omitted.

Don't forget the directory traversal vulnerability too!

What’s remarkable, to me, is how publicized these issues in Zoom became vs other software. Google also seems to have pointed their vulnerability researchers at it. I remember thinking at the time they were getting a lot more scrutiny than most software in that realm, which has the same types of issues. Maybe it just entered the public Zeitgeist and it’s all a coincidence, but as a long time infosec consultant that do…

My take on it at the time was that while technically more knowledgable people were all happily having video calls in-browser for free, less tech savvy people were, by the millions, excitedly installing a pretty ropey app with root privileges and a whole bunch of vulnerabilities. It felt like a very necessary step when the normies thought they were entering the matrix.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#88
post #70

Earlier quoted context omitted.

> the MacOS and Linux versions are left to die basically. I hate Teams as much as the next guy, but I'm not sure what you mean by this. On Linux, I have version 1.4.00.26453, vs 1.4.00.32771 on Windows 11 (installed fresh today). Also, the Windows experience is just as atrocious as on Linux, so for once I don't get the feeling that Linux is a second-class citizen. If anything, all citizens are last-class.

The version numbers are lying. The Linux version is missing important features, like seeing more than 4 participants at the same time, or blurring the background. Also, for some reason it is often not possible to see the camera picture of participants when they start screen sharing (if they are using the Linux version, that is).

I don't know about the number of participants, luckily I've never been in a mammoth call. As for the background blur, it may be related to a missing feature in Electron. I seem to remember that another conferencing app (might have been zoom, not sure) didn't support this while running on Chrome/Linux, so I figure it's related.

To me, the main missing feature on Linux is the "native notifications" feature (as opposed to the bespoke window that pops up).

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#89
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

What I know is that almost every company I have to deal with use Office 365, so they use Teams, and almost every school in my area use Google Suite (BigG got quite good at being the new Microsoft), so they use Google Meet. Almost no one use Zoom anymore simply becase it's not integrated with anything.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#90
This preview link vulnerability appears to be an easily implemented mistake. I wonder if having vertical development teams (client, api, etc) vs horizontal teams for a particular product makes this type of defect more likely. I could see how a client team would be likely to consume the preview link API without considering its internal implementation or that it could probe internal cloud infrastructure. The API mistake could have been easily made by any developer, particularly more green developers. Lack of a larger number of people involved with the entire horizontal stack could make this type of issue more likely to not be found.

My organization is considering restructuring teams from 1-3 horizontal teams (full stack) for a given product to 1-3 teams that focus only on one slice of the product. Seeing articles like this makes me contemplate if there’s more security risk with this approach.

Post reply on HN