The xz attack may be bad, but trusting Microsoft certs is worse
1–10 of 21 posts
Re: The xz attack may be bad, but trusting Microsoft certs is worse
#2Re: The xz attack may be bad, but trusting Microsoft certs is worse
#3Re: The xz attack may be bad, but trusting Microsoft certs is worse
#4The CISA report is definitely worth a read and so is questioning Microsoft's security posture. Comparing the incident to the xz attack doesn't make a whole lot of sense though.
Also the only reason the xz attack isn’t overwhelmingly worse than the MS attack is because it was caught (by an MS person as well I think?) before it was deployed.
Re: The xz attack may be bad, but trusting Microsoft certs is worse
#5The CISA report is definitely worth a read and so is questioning Microsoft's security posture. Comparing the incident to the xz attack doesn't make a whole lot of sense though.
Yeah, they’re entirely different classes of failure (from a security pov, not personal failing, esp nothing the old xz maintainer did). Also the only reason the xz attack isn’t overwhelmingly worse than the MS attack is because it was caught (by an MS person as well I think?) before it was deployed.
Re: The xz attack may be bad, but trusting Microsoft certs is worse
#6You can make the first sentence of the tweet fit the HN submission word limit
"CISA and review board torches Microsoft response about the 2023 compromise"
Re: The xz attack may be bad, but trusting Microsoft certs is worse
#7Haven’t trusted Microsoft in a long time. So at least that’s not changing.
Re: The xz attack may be bad, but trusting Microsoft certs is worse
#8The submission title is editorialized (easy karma bait), the tweet doesn't say anything like that, not even mentioning xz or the word trust. And also it's an entirely different type of security incident. You can make the first sentence of the tweet fit the HN submission word limit "CISA and review board torches Microsoft response about the 2023 compromise"
I'm not sure why there's a sudden surge of xz ragebait submissions.
Re: The xz attack may be bad, but trusting Microsoft certs is worse
#9The USG is Linux-hostile, with exceptions like the NSA doing SELinux, Gidra, and other toolchains.
Linux would be the absolute best, along with things like OpenOffice and other FLOSS tools. The difference is to take the money you pay to MS and redirect them to FLOSS devs.
But, that'll never happen.
Re: The xz attack may be bad, but trusting Microsoft certs is worse
#10Earlier quoted context omitted.
Yeah, they’re entirely different classes of failure (from a security pov, not personal failing, esp nothing the old xz maintainer did). Also the only reason the xz attack isn’t overwhelmingly worse than the MS attack is because it was caught (by an MS person as well I think?) before it was deployed.
It was caught by a person on MS payroll, that's true, but it didn't get caught by any security processes institutionalized by Microsoft. So the credit goes to Andres Freund, who was working off-the-clock (according to The Verge) not to Microsoft.
Wasn’t it an annoyed database administrator?