Live data from Hacker News

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

trustedsec.com

81–90 of 116 posts

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#81

IIRC, (& I don't remember if I reported it), but Azure's audit logs don't reflect reality when you delete a client secret from the UI, either. If I remember the issue right, we lost a client secret (it just vanished!) and I went to the audit logs to see who dun it. According to the logs, I had done it. And yet, I also knew that I had not done it. I eventually reconstructed the bug to an old page load. I had the page…

This is a great example for educating devs on the dangers of “set” operations vs. “pull/delete” in contexts where data can be edited concurrently.

I would say that the audit log was accurate, though, even though the bad UI design caused unintended consequences.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#84

Earlier quoted context omitted.

Well, as far as my experience, we the old generation despise Microsoft even more

Classic to pat yourself on the back, push blame, and have no evidence to show you made any kind of change about it. Classic!

wtf does this even mean? Did you reply to the correct thread?

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#85
post #78
post #74

Earlier quoted context omitted.

You are defending not just clickbait, but libelous clickbait.

It's only libelous if it's not true. This vulnerability says otherwise.

It is libelous because it is a claim that "X said Y", not "Y".

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#86
post #85
post #78

Earlier quoted context omitted.

It's only libelous if it's not true. This vulnerability says otherwise.

It is libelous because it is a claim that "X said Y", not "Y".

Ah, so you're worried about the review team being misrepresented, not that Azure is shit.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#88
post #74
post #52

Earlier quoted context omitted.

Titles are editorialised and space limited. The first couple lines in the article linked above make the nuance pretty clear. [edit: 'pretty' instead of 'perfectly']

You are defending not just clickbait, but libelous clickbait.

I doubt this reaches the bar for libel by a long shot.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#90

Bypassing logging feels relatively unimportant compared to some of the recent EntraID vulns we’ve seen

I dunno. It seems kinda bad that core auth log - which should be a primary source of truth during, say, a security audit - seems to work on a best-effort basis?
Post reply on HN