250M Microsoft customer service and support records exposed on the web
comparitech.com
comparitech.com
There are zero consequences to anyone important when a data breach happens; therefore there is no incentive for companies to protect their user data and the number of breaches will continue to grow for the foreseeable future.
By 2025 at the latest, there will effectively be no such thing as privacy anymore. All personal data belonging to everyone will have been exfiltrated and will be available for sale.
You will be able to purchase the full medical history, all financial transactions, all addresses, phone numbers, location history (often with photo/video evidence), all account numbers, ID numbers (government and otherwise), biometric data, browser/search history, every email, sms or chat message they ever sent or received and any other information you can think of for the vast majority of people on earth.
Alice knows she didn't send this message, so it's from Bob, but she can't prove to anyone else that she didn't just fake it.
Bob knows he sent the message but he can deny it and there's no proof.
Eve has no idea what the message was, even if Alice or Bob show her the real message she can't verify they aren't lying.
Maybe more thought could be put into why this is, rather than normalizing it? How many people on this here web site pay their bills with the fruits of these breaches?
Does your 2025 prediction apply to black market sale or legal market sale?
Your comment bring back Microsoft's Project Bali news from my memory [1]; this supposed data bank allows users to "manage, control, share and monetize the data.". That was bit than year ago and it seems they abandoned the idea as page doesn't load anymore (at least for me).
[1] - https://www.zdnet.com/article/microsoft-is-privately-testing...
As much as I love the free market, we're completely failing to protect consumers. I think we need the government to step in and align incentives. I don't know if we need engineers to be personally liable in the case of data breaches, but I'm serious enough about this that I wouldn't take it off the table. Medicine has malpractice suits. Engineers have a professional duty of care. Builders have building codes. We need an equivalent for software engineering.
Its not the wild west anymore when we didn't know how to do this right. For almost all modern software, best practices are out there and well known. The way you secure a password database hasn't changed much in the last decade. Apparently people just don't care enough to learn and apply those techniques. Bootcamps don't even bother to teach any security practices. Given how much the world relies on our industry's ability and knowledge, that needs to change in a hurry.
>Medicine has malpractice suits. Engineers have a professional duty of care. Builders have building codes. We need an equivalent for software engineering.
The key difference is that when a doctor or engineer screws up, people die. The burden is on the people calling for regulation to show the tangible, measurable harm to peoples' health or finances resulting from these data breaches, otherwise the average person won't take them seriously.
It's also the case that doctors and engineers aren't dealing with adversarial input. If somebody blows up a bridge nobody blames the engineer, and if a patient deliberately harms themselves nobody blames the doctor. Yet web infrastructure is constantly dealing with adversaries across the world trying to breach it.
Except in the EU, you mean? Where the fine is what, up to 4% of global annual turnover.
So there are ways to do it, but occasionally you have to click a couple of dialogs on a website so they've been widely slated.
That still leaves medical and financial records, which is a tangle substantially more herculean.
probably not in the EU - at least not if some kind of negligence, as specified by the GDPR, took place.
The Windows parts of these records might be a good resource as it's probably part of the documentation which builds up to become the MSKB articles. Each support case was documented and linked to either a KB article, an internal "not yet KB article" or you had to submit it as a unique issue. After the "not yet KB articles" were referenced X times, then it would go to consideration as a KB article. Collectively, all this formed their internal KB.
Worked there. Pay was terrible once Convergy's took over. Then they moved everything to India and the support got terrible also. Too bad. They had quite the brain drain from that process. There were a lot of Windows gurus in that building. I learned far more than I needed to know about Windows and went way more in depth than I ever have tinkering with Linux.
Looking at the dates again, records I was part of was probably before this date. I believe I was gone by 2005. That may also be around the time the Tucson location moved from the IBM campus to the Convergy's buildings. I declined when they asked me if I was going to make the move.
I got there right after Convergy's took over from Keane. The training at that time was still really good. Tony Agee and John Mott were legends (unsure of spelling.) I credit this time with my beginnings in tech and learning how to think for troubleshooting. They taught linear, logical troubleshooting which was so simple and yet I still don't see much of it today. It was also a place to develop my search skills. It's incredibly valuable to be able to sift through a load of technical discussions and separate the signal from the noise.
I got stuffed into Windows 95/98 and then sucked into XP when it blew up.
XP manager was Rohn Eloul (originally from Palestine.)
The only person I keep in touch with is Pablo Bley.
Don't remember names of anyone else. We must have worked on that same floor though.
They need a solution to watch their solution that watches their configs.
For those who don't know the phrase: https://en.wikipedia.org/wiki/Quis_custodiet_ipsos_custodes%...
What tells you they wont just layoff some random people to save some money to pay for the fine?
The problem with companies is you can always shift the blame on someone, on some department, etc...
In the end, the people that made the shitty decisions are rarely held accountable for the mistakes.
Or maybe it ought to be modelled after medical malpractice? If a doctor fumbles and messes you up.
There are malpractice regimes all over the place, it just results in having real training and an assessment of risks and, y'know, not cowboy'ing, before making changes. "What difference does it make that this girder is 1/2" out of alignment? Nobody's perfect."
Over 8.5BB customer records were exposed last year; the estimate for this year is in excess of 10BB.
Haveibeenpwned is the same but doesn’t reverse the passwords.
[0]https://www.zdnet.com/article/company-behind-leakedsource-pl...
> An investigation by infosec journalist Brian Krebs claimed that a second suspect, a US man named Jeremy Wade, was also behind the service. He was never charged
According to American prosecutors, freedom of speech prevents prosecution in America without intent to commit a crime.
[0] https://nationalcrimeagency.gov.uk/news/weleakinfo-com-site-...
>(6) knowingly and with intent to defraud traffics (as defined in section 1029) in any password or similar information through which a computer may be accessed without authorization, if—
>(A) such trafficking affects interstate or foreign commerce; or
>(B) such computer is used by or for the Government of the United States;
The key text here is with intent to defraud as an element of the offense. Prosecutors in the USA must prove beyond a reasonable doubt that you had intent to defraud. This language is very clear due to the first amendment and they cannot speculate nor can they say ignorance alone proves intent. Obviously my earlier post of "without intent to commit a crime" was wrong, but should have read "without intent to defraud".
Edit: I just realized that you said prosecutors told you this. My guess is they lied so that you’d do it again when they were watching.
Which makes me wonder, is there information that's leaked so much it's no longer "private"? Names, addresses, phone numbers, contacts lists, photos, emails, cloud documents, IP address logs, search history...It's all there, waiting to be leaked...
And why the insistence on storing information for an unlimited period of time - it should be illegal to store data above 5+ years without explicit consent from the user (after reviewing the data and clicking "I am okay with this data continuing to be stored").
this might be something you're looking for.
Then the you can see that you're 880654th out of 1.1B people on the leaderboard and maybe feel slightly better.. or worse.
I appreciate that they sent something, but sometimes it'd be nice for them to allow someone to access the data related to them that was exposed as they say "our analysis of the support information indicates that specific personal or organizational identifiable information related to your support case was potentially visible." Okay, what specific personal or organizational identifiable information of mine was visible?
I assume the representative or I may've listed said info in our communications back and forth so let me see what was exposed so I can make a judgement of what, if anything, I should do here.
Or you could reach out to Microsoft's Data Protection Officer here: https://www.microsoft.com/en-us/concern/privacy
I'm not sure if that's the GDPR path, but it's what I came across.
Now, Microsoft does not necessarily have to tell you exactly what of your data was leaked. They probably do not know! In this case, they may just respond to your request with all of the personal data they hold.
The law just says that they have to notify you of the "nature of the personal data breach as well as recommendations for the natural person concerned to mitigate potential adverse effects".
https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-ove...
Security is difficult. Microsoft is supposed to be skilled at preventing data breeches and exploits, but apparently not. What can be done to prevent this sort of thing?
It's a wildly asymmetrical relationship that means 9 billion people get a try to knock you out and your team of what??? 25, 50, 100, 1000? Security specialists have to see everything possible and plan for any and all possibilities.
It's never going to happen.
This is the simple reality of the internet and I'm sure you know this, but I saw your comment and thought I'd add this for the next person who may not realize this.
I'm personally curious to know, because I'm no SecOps; if there is even a theoretical solution to the internet that would have greater integrity for the users or if this is as good as it gets.
Please don't do this. Something can be done, we all know it, but for some reason don't think it's possible? Prison sentences should have started with the Target CTO in 2013 (at the very latest), but the more the public is cowed by shrug emojis, the less likely companies will protect your data for anything other than commercial advantage.
But we do need much more oversight and serious punishment for companies that lose data like this.
US soldiers fight in combat knowing failure to obey orders can land them in jail for years. The US Code of Military Justice is not fun, and you sign up for it when you join implicitly. Is there an armed service staffing problem?
Our general US legal system is flawed, but cops can go to jail for ethical violations and criminal behavior for actions that are integral parts of their job function. Is there a cop staffing shortage?
I have argued this, ironically, about US Congresspeople: if we have a volunteer army with stringent legal codes with special punishment by virtue of their job, serving us, why are other classes of people not worthy of higher standards and why do we suspect people will shy away from that? How can we pay others more for higher probability of incompetence and less repercussions?
I am not trolling. When I suggested this shows the power of commitment in volunteer armies and I wish Congress had that kind of self respect people tell me I'm nuts. I would like a CTO and security industry jobs to mean something.
And considering the fact that no amount of competence will protect you from a sufficiently motivated and resourceful hacker, seems unfair.
Now if we come up with a framework and a security checklist that must be followed and certified by the CTO every quarter or something, and they don't do it, or lie, then sure, jail them.
We rely way too much on Other People's Computers to do stuff. The only real way to avoid issues is to make them technically impossible, not to rely on laws (that can be abused).
(yes, i know i am asking for putting the cat back in the bag long after the cat's own grandchildren have died...)
with enough attention on information theoretic security (or unconditional security), things may change
Even if that functionality is implemented with good intentions and the data is only intended to be used for responsible purposes, the biggest and most technically capable organisations in the world can still make mistakes and suffer data leaks, which are potentially a gift to criminals, commercial competitors, and so on.
If there's anything sensitive in there -- personal data, commercial information that was provided under NDA -- we're probably still on the hook for it legally, too.
Someone should grep this to find out how many times people were told to turn it off and turn it on again.
>The records contained logs of conversations between Microsoft support agents and customers
Check the dark web.
From the article, it was found, reporter and fixed within 24 hours
Being fixed within 24 hours of being reported does not mean it was only available for 24 hours. It could have been 24 days or 24 months.
they claim there's no sign of other unauthorized access.
Anyone smart enough to access this would also be smart enough to cover their tracks. When I was black hat in the 80's, this was Infiltration 101.
It’s like some executive saw a study showing customers like it when support understands their problem, so now the words MUST be spoken! Lmao.
Really quite incompetent. But we don’t know for sure anyone else actually accessed it.
If the DB server was configured so access was not logged, could you claim "We investigated, and we didn't see any evidence of access"?
There's been a lot of news along the lines of "We found an unsecured database of voters, and we don't even know who owns it", now those idiots I'd be more sure that they didn't turn on logging. With Microsoft, I'd believe them a bit more, because they'd be afraid of getting busted for using weasel sentences.
Unless you have some insider knowledge it sounds like you’re full of shit. If you’re going to claim that they’ve deliberately turned off all logging, you’ll need to show some evidence. (Or at the very least claim that you have some!)
I'd say it seems likely. But I only have domestic experience. People with industry experience, what do you think?
Services like greynoise provide an easy answer to “who’s scanning for elasticsearch?”, although most of those are trying to RCE and not exfil data.
It’s certainly possible that someone else found this ES and dumped the data during the few hours it was exposed, but I certainly wouldn’t call that likely.
What's your background? I'd be surprised to find corporate IPs were only scanned at the rate of domestic non-fixed IPs.
If a black hat cracker finds data they can exfiltrate do you think they'd just leave it; especially data like this that has obvious value to phishers/fraudsters?
I scan for a living, have been doing so for a better part of the last 10 years. I spend lots of time keeping up with what other people are scanning for.
> If a black hat cracker finds data they can exfiltrate do you think they'd just leave it
Yeah sure, if a malicious hacker had access and knew what they had access to they wouldn’t just leave the data there. Odds are this would just be discovered by scripts trying to drop malware for DDoS, or ransomware.
As a black hat hacker scanning for things like this I always had the problem that I was finding way more data than I could realistically store and process, I’m sure I missed hundreds of things like this in my results because of that. The criminals doing this stuff don’t have teams of people working for them analyzing the data.
Then there’s the fact that a very significant chunk of blackhat hackers just won’t be working in late december. I understand that this may not sound like such an convincing argument at first, but this’ll almost certainly exclude at least half of the malicious actors who could’ve possibly found it.
I’m not saying it’s impossible, I just don’t think it’s particularly likely.
I can’t imagine that even MS would be running ES on windows, although then you’d probably have even more data available.
By the way Microsoft has absolutely terrible azure support. If you have a legitimate issue and you dont have a dedicated support consultant good luck to you.
The rep was very helpful, but a bit puzzled that I wanted him to read me my ticket title. He seemed to think him knowing my name should be sufficient verification.
Note: I can never understand Microsoft's names for different levels of the same product. It might not be called a business account, maybe professional or pro or small business or something.
Simply stating that your network configuration prevents access isn't the best answer.
Right. The network should actually be configured to prevent access.
This is why google assumes that the network layer adds no security.
December 28, 2019 – The databases were indexed by search engine BinaryEdge... "
... at least two days then.Microsoft should not have collected anything beyond an email and a password. Payment information should only be held temporarily.
Personal information is a toxic asset. It baffles me why companies willingly hoard it.
Dell always denied it, but it was pretty funny. They had service tags and everything - anyone else get that?
Lets be honest no one can keep this data without eventually being hacked, so maybe they shouldn't have it after that transaction.
https://www.elastic.co/blog/security-for-elasticsearch-is-no...
It’s not default insecure like Mongo was - this was far far worse. You couldn’t even prototype in a secure way even if you wanted to, without a massive contract. One of the most frustrating things in software - IMO they deserved to have AWS commoditize their stack.
Of course it's unethical to use said product to store real user data too, but the road goes both ways.
If you get to the point where it’s what’s protecting your data, you’re already fundamentally screwed.
Hell, even if it is airgapped, it can still be compromised by viruses on USB sticks and such.
You should never be leaving sensitive systems wide open, period, regardless of how secure you might think that network is. Thousands of data breaches have been caused because networks didn't end up being as secure or as separated as hoped for.
However, Amazon has thankfully released a free and open source security module for Elasticsearch as part of their Open Distro project. It is based on another project called Search Guard. See: https://opendistro.github.io/
Specifically can you go into more details about what worries you with containers. Is it insecure images with out of date software, or risky applications inside the containers? Something else?
It reminds me of companies I've worked with before that accidentally had a production site pointed to a dev database. Why the hell is that even physically possible with your network setup?
Anything can reach anything, provided you know the naming schema... and there's no easy way to fix it on anything that is not AWS/Azure/GCP, not without losing all the benefits of a self hosted k8s cluster in the first place.
Openstack at least provides ways to isolate machines, but that's VM-level only and truly an ultimate PITA to set up.
Developers are not operators and operators are not developers. The whole idea that we can do away with this specialization and and relegate operations to the people that create software because it is now possible to script infrastructure and to install complex packages with a few mouseclicks does not make it true. Operations and the complexity that goes with it is a job in its own right, no competent operator would have left this situation as it came out of the box.
https://www.elastic.co/guide/en/elasticsearch/reference/curr...
As many other answers to your query have stated, this is caused by a broken understanding of the devops methodology among organizational management forcing developers who are not competent in systems administration to be responsible for these systems.
No, I don't expect perfection. However, I do expect very careful implementation of access management for very large databases containing lots of PII and other sensitive customer information. Things like huge databases being accessible without credentials shouldn't require perfection on the part of some human. That sort of stuff should be continuously audited in an automated fashion.
But the software industry is quite bad, as a whole, so even the relatively competent actors make surprising, high-impact mistakes.
Maybe it's because the stakes are relatively low (c.f., bridge collapsing vs. PII leak) and the competition relatively fierce? Maybe software engineering is still very young and moving quickly?
In any case, I think it's totally reasonable to hold the opinion that MSFT is doing things pretty well relative to the rest of the industry and also that the industry as a whole is doing a pretty poor job.
IDK, for me the story has to be one of the following:
1. MSFT made a huge and inexcusable mistake, so maybe there's something systemically wrong with MSFT; or,
2. MSFT is very competent, and even very competent people are making very big mistakes, so maybe there's something systemically wrong with the entire industry.
When your mistake makes a building fall over...well, there's a reason why that almost never happens.
the forest I might be missing through the trees is that maybe there is an industry agreed upon standard within the Tech industry. My understanding is almost all of these breaches happen because comically silly mistakes (pw = password), not super high sophisticated attacks.
At the same time, the tech world is bigger than it used to be, the stakes are higher, and more is on the line than ever before. Mistakes are more costly (though in this particular case I don't think you could prove any real damages).
And worst of all, the political world remains incredibly tech-illiterate. So, those in charge of guiding us in this realm are ill-equipped to do so.
I don't have a good answer for this. In an ideal world I'd like businesses to take this sort of thing more seriously, but in reality I don't see any reason that they should.