Live data from Hacker News

The xz attack may be bad, but trusting Microsoft certs is worse

twitter.com

1–10 of 21 posts

Re: The xz attack may be bad, but trusting Microsoft certs is worse

#4
post #2

The CISA report is definitely worth a read and so is questioning Microsoft's security posture. Comparing the incident to the xz attack doesn't make a whole lot of sense though.

Yeah, they’re entirely different classes of failure (from a security pov, not personal failing, esp nothing the old xz maintainer did).

Also the only reason the xz attack isn’t overwhelmingly worse than the MS attack is because it was caught (by an MS person as well I think?) before it was deployed.

Re: The xz attack may be bad, but trusting Microsoft certs is worse

#5
post #4
post #2

The CISA report is definitely worth a read and so is questioning Microsoft's security posture. Comparing the incident to the xz attack doesn't make a whole lot of sense though.

Yeah, they’re entirely different classes of failure (from a security pov, not personal failing, esp nothing the old xz maintainer did). Also the only reason the xz attack isn’t overwhelmingly worse than the MS attack is because it was caught (by an MS person as well I think?) before it was deployed.

It was caught by a person on MS payroll, that's true, but it didn't get caught by any security processes institutionalized by Microsoft. So the credit goes to Andres Freund, who was working off-the-clock (according to The Verge) not to Microsoft.

Re: The xz attack may be bad, but trusting Microsoft certs is worse

#6
The submission title is editorialized (easy karma bait), the tweet doesn't say anything like that, not even mentioning xz or the word trust. And also it's an entirely different type of security incident.

You can make the first sentence of the tweet fit the HN submission word limit

"CISA and review board torches Microsoft response about the 2023 compromise"

Re: The xz attack may be bad, but trusting Microsoft certs is worse

#8
post #6

The submission title is editorialized (easy karma bait), the tweet doesn't say anything like that, not even mentioning xz or the word trust. And also it's an entirely different type of security incident. You can make the first sentence of the tweet fit the HN submission word limit "CISA and review board torches Microsoft response about the 2023 compromise"

Agreed, and flagged.

I'm not sure why there's a sudden surge of xz ragebait submissions.

Re: The xz attack may be bad, but trusting Microsoft certs is worse

#9
Sure the response can be excoriating, but the US government isn't giving up on Microsoft shit.

The USG is Linux-hostile, with exceptions like the NSA doing SELinux, Gidra, and other toolchains.

Linux would be the absolute best, along with things like OpenOffice and other FLOSS tools. The difference is to take the money you pay to MS and redirect them to FLOSS devs.

But, that'll never happen.

Re: The xz attack may be bad, but trusting Microsoft certs is worse

#10
post #4

Earlier quoted context omitted.

Yeah, they’re entirely different classes of failure (from a security pov, not personal failing, esp nothing the old xz maintainer did). Also the only reason the xz attack isn’t overwhelmingly worse than the MS attack is because it was caught (by an MS person as well I think?) before it was deployed.

It was caught by a person on MS payroll, that's true, but it didn't get caught by any security processes institutionalized by Microsoft. So the credit goes to Andres Freund, who was working off-the-clock (according to The Verge) not to Microsoft.

Oh yeah, I know it wasn’t ms security reporting it or anything, I just found it funny (and ironic I guess? given this report came out a few days later).

Wasn’t it an annoyed database administrator?

Post reply on HN