Microsoft takes pains to obscure role in 0-days that caused email breach
arstechnica.com
arstechnica.com
And none of it has any impact, nobody seems to care.
The comments in this thread are crazy to me. Yes, dealing with targeted attacks by nation states is hard, and occasionally you'll fail. But that's part of the reason to pay Microsoft rather than try to host your own. In that situation the absolute minimum expectation is for MS to follow basic best practices. Nothing about this story suggests they've been doing that, it's just one wtf after another.
And their communication on this has been so bad an unclear that it has to have been intentionally obfuscatory.
Azure if you're a .NET shop and want good integration with Visual Studio
AWS for everyone else
Examples:
- SQL Server Analysis Services (SSAS) has no Azure PaaS, but there is an AWS PaaS for it.
- RDS for SQL in AWS allows setting a time zone, Azure SQL Database is UTC only, breaking the majority of existing databases when migrated. (They confuse what "developers should do" with what "developers actually do".)
- Azure's PaaS for Active Directory (Azure AD Domain Services) can only be linked to an Azure AD tenant, it can't be used as a standalone authoritative domain. AWS allows this scenario.
Essentially, every Microsoft product you can think of is easier/cheaper/better on AWS instead of Azure.
If Microsoft's CEO was still Bill Gates, heads would have rolled a long time ago.
Where AWS really showed its unsuitability to host applications on the Microsoft stack was that AWS doesn't have a PaaS way to host .NET Framework web applications; IaaS is the only option.
So both .NET Framework web application nor Microsoft SQL Server database were noticeably harder on AWS than Azure for us. Standing up one IaaS server to host SSRS in Azure was a lot less work than accounting for all the gaps on the AWS side would have been.
We’ve had issues where large databases would take forever to cut over to the PaaS database and cause long outages during migrations.
It’s these random feature gaps that make these platforms difficult to deal with.
For the initial migration to PaaS, whether Azure or AWS RDS, it’s faster and easier to use replication instead of BACPACs.
For moves within the Azure SQL environment, they have database copy functionality that can be utilized. (Which RDS doesn’t have, and I would have sorely missed if we hadn’t pulled the plug on AWA.)
Setup linked-servers from your local server (via Server Objects / Linked servers), once you've done that you can just do "INSERT INTO bigtable(..) SELECT .. FROM [remotename].dbo.bigtable;" , it'll tax the transaction log but it's a magnitude faster than bacpac's,etc. Sadly Azure SQL doesn't support linked servers so one of the servers has to be outside.
There's an annoying difference between 'Azure SQL Database' and 'Azure SQL Managed Instance'. I recall the Managed Instance does support timezones and SSAS, while the ordinary offering also misses other useful stuff like Resource Governors.
This may also explain why in Azure, more cores run a Linux kernel than Microsoft Windows.
Teams, Sharepoint, PowerBI, the ad platform that is Windows, Azure
all terrible
(not to mention the ruthless business practices)
Yes. Especially on HN.
Microsoft used its video game systems and Linux flirtations as Trojan horses to convince a generation of tech-centric people that the bad old Microsoft of yore is just something that old people worry about and that today MS is all rainbows and unicorns.
HN is full of people willing to fall in their swords for MS because they weren't around for its last round of despicable behavior, and bringing it up just means you're out of touch.
> "HN is full of people willing to fall in their swords for MS because they weren't around for its last round of despicable behavior"
When was this last round? Is HN full of 20 year olds? Microsoft is really popular with the youth of today? That's nearly halfway back to when Microsoft was founded.
Not even Apple nor Android. ;)
Microsoft drove out the attackers on June 16.
But only after a customer tipped off company researchers of the intrusion.
Is anyone at Microsoft paying attention?
Other than the legion of PR flacks furiously obfuscating every fuckup?
Windows OS is basically just a wrapper for data mining for Microsoft’s very large, but ignored, adtech businesses (plural).
1. Purposely commercial usage, not merely "sharing a link" to some content on the web.
Governments do a bad job of funding news production, newspapers didn’t take the internet seriously and made a massive mess out of it, and the tech companies just sucked out the remaining value and killed news.
The fact is the big tech companies make next to nothing on news. It’s rational to just stop doing it if the value goes negative.
If government wants to levy a real tax and use that money to fund and support news, fine - but these laws are based on a mistaken premise that somebody is making buckets of money in news. Nobody is.
Perhaps these so-called "tech" companies need the traffic generated by people reading and sharing news stories. It makes no sense for "Google News" to exist if it makes next to nothing. It would be "irrational".
Google and Facebook keep track of every user navigation to a news story. The links are not direct. Of course this is for purely non-commercial purposes. Data collected is not used for commercial purposes. Yeah right.
https://www.newsmediaalliance.org/wp-content/uploads/2019/06...
If it isn't valuable to Google to intermediate peoples' access to online news, then why doesn't Google stop doing it.
IMO, the issue is not that content producers such as news organsations are asking too much, it's that they are asking at all. The so-called "tech" company "business model" only works if the company does not have to pay anyone for content. If every producer whose content is being used by these companies to support and generate revenue from advertising services suddenly starts demanding payment, no matter how small, these "Big Tech" companies and their Golden Goose are cooked.
When your entire multinational runs on M365, SharePoint, OneDrive, exchange online, teams, Azure AD, you really don't want to know about its flaws because changing to another provider costs millions.
And what other provider? There's only Google and they have only a tiny share of the enterprise market. Everyone is in the same boat.
Ps speaking about productivity SaaS platforms here, not generic cloud.
There's still FTP, NFS, SMB, etc...
Hell, there's still Lotus 1-2-3
If you can't get away from Microsoft, it's because you aren't trying. That is what they've counted on, and that's why they've invested as much in terms of trying to have their products taught in schools as early and widely as possible, and why I now refuse to support or teach kids on Office alone when I can teach them on LibreOffice + Office + Google docs instead.
Literacy folks, it's the key to the shackles that vendors have been doing their damnedest to slap on you over the years.
I doubt you’ll find any company with an IT department with enough resources to roll their own Office 365.
That's probably because you probably weren't around in the 80s/90s. Netware was a network server tech from before Windows was a thing. All discontinued now so hanging your enterprise off this tech would be a ridiculously bad idea. Seriously, we try to get rid of tech debt, not add it :')
GroupWise still gets some token updates but really. I'm super super happy we moved off Lotus Notes which was in the end a vile piece of unstable stinking java. When it started it was pretty good, sure, but the attempts to keep up with the times made it unstable.
So no worries, they are not serious replacements for today's productivity apps. They were from a time when life and business happened at much lower speeds. When people could wait a few days for a letter to be mailed in.
Try putting a picture in Lotus 1-2-3, connecting to a remote data source, doing a pivot table etc :P Not to mention doing any kind of realtime collaborative work.
> There's still FTP, NFS, SMB, etc...
> Hell, there's still Lotus 1-2-3
You're not serious I hope? While these apps have some basic functionality, they would not work in the modern world. Even collaborating has become so much better (remember all the emails in the mid 2000s "CAN WHOEVER HAS OPENED REPORT.XLS PLEASE CLOSE IT SO I CAN EDIT" :). And that was already a huge improvement on the Lotus 1-2-3 days. Now we can seamlessly collaborate on the same document.
Sometimes I'm genuinely surprised we got so much work done then. Things are so much more efficient now.
Exactly this is going on for at least the last 30 years.
Nowadays they just seem to have better PR / marketing so the usual daily scandal has exactly zero impact on them.
But form the perspective what they're doing, and how they're doing it, nothing ever changed. Microsoft is Microsoft.
---
I've read at some point some revealed internal memos or emails from Microsoft, I guess from a court case as the PDF was full of scans of printed out stuff. It was about their internal strategy regarding competition (and actually their "partners" who they count to their competition more or less, only that they see them as a kind of "useful idiots"). Frankly I can't find the PDF right now but it would be really helpful here! It was likely something famous as I wouldn't have downloaded it back than. Who has the right link?
It is generally frowned upon or illegal to sell defective products. In many other industrys the discovery of multiple, repeated defects in a product allows the customer to get a full refund with protection from retaliation. Only in software do we call defects a oopsie and throw our hands up in the air as if nothing could be done and let companys off the hook.
Normalizing this process by handling trillion dollar companys with kids gloves is ridiculous. They are selling defective products and should be treated like it.
I've always distinguished a defect as a fault that was known prior to shipping (and hopefully documented) and a bug is a fault discovered after shipping. Draw your own analogies for SaaS, I guess.
But given another popular distinction between defect and bug is more around design vs unexpected failures, it may be hubris to overload either of those terms with all the extra meaning that's already captured by '0 day'.
As TFA notes, it'd be preferable if Microsoft didn't weasel away from commonly used and well understood words like vulnerability & exploit, or if they didn't eschew industry standard CVE reporting.
A airbag that, unknowingly at the time of manufacture, explodes after exposure to high heat or humidity has a defect. The product, now knowing that it contains a material defect, is defective.
The use of bug, 0-day, vulnerability, exploit, etc. when making PR statements about security defects in software is a deliberate effort to downplay the severity of their failures. They deliberately avoid the use of the word “defect” because in many industrys that has literal legal consequences. At many companys, putting the word defect in a email has the general counsel descend, that is how serious it is. In contrast, calling a flaw that prevents the stated usage of your product a “bug” lets you sidestep all of that by mischaracterizing it as a legally meaningless “oopsie”.
These flaws are defects. They clearly cause the products to not achieve their stated goal and the failures cause demonstrable harm. Calling them anything less is just handling these trillion dollar companys with kid gloves which is how we got into this systemically incompetent security mess.
They need to be held to the same standards we hold other companys to and fix their damn products or get out of the businesses that they are too incapable to do acceptably.
What is the stated goal of software packages whose EULA often includes a disclaimer, "NO WARRANTY OF FITNESS FOR ANY PURPOSE"?
If you are selling to a general consumer via a one-sided contract then there are implicit guarantees of fitness for the plainly advertised purpose that can almost never be waived at least in the US. Note that this does not usually apply to gifts so non-commercial OSS is likely unaffected.
If you are selling to a business customer then they are accepting those terms. If they wish to then go on and use that product in their delivery to a general consumer then they are accepting the liability of verifying or making it fit for their purpose. If they wish to provide other guarantees then they are also responsible for those.
But even so, you seem to be claiming that the product doesn't match "stated specifications, guarantees, or use" (I find 'use' a bit vague, but nonetheless.)
Can you point at the stated specifications, guarantees of AAD / Entra that are contraindicated by this exploit having occurred?
If written guarantees have in fact not been met - that could be really interesting.
> These flaws are defects.
You use the word flaw a few times - as something similar to a fault, here as a synonym of, or a precursor state to, a defect. If we're being persnickety about language ...
Are you arguing that the intended functionality of Exchange is leaking emails? No.
Are you arguing that customers find their emails being leaked a desirable or neutral option? No.
Are you arguing customers will accept a product that they know will leak their emails? No.
So, a flaw that leaks emails makes the product unacceptable to the customer. The only possible defense for Microsoft here is that they accepted no liability or disclaimed all liability for leaking emails.
It is certainly possible that Microsoft did that in their contracts. I applaud the skills of their salespeople and lawyers if they tricked the customer into accepting products inadequate for their needs. That does not stop me from calling it out as duplicitous, immoral behavior that should be stamped out.
Part of this being pointing out how they have changed the words to make their statements seem less bad. The use of correct, industry-standard words makes it harder to misdirect customer intuition.
Sure, in a strictly literal, legal sense, it is quite possible that they are not selling a defective product because they lied to the customer and tricked them into purchasing a substandard product. However, in the colloquial sense, they are absolutely selling a defective product as the consumer is not getting the plain meaning of what they were advertised (even though it is not contractually binding).
I do not know about you, but I really think we should push for the consumer-friendly model over the lawyer-friendly one.
I doubt many others would phase it like the product (is actively) leaking the emails
> Sure, in a strictly literal, legal sense, it is quite possible that they are not selling a defective product because they lied to the customer and tricked them into purchasing a substandard product.
So you said a guarantee was broken earlier, and I asked you to demonstrate that or point to where they've committed to guaranteeing a certain quality of service.
Now you have adopted a position of saying they're technically not doing anything wrong, but morally they are, which when talking about Microsoft or Amazon or Google or Apple or (etc) is a bit of a slippery slope and/or isn't really news.
I see you also slipped in a 'they lied to their customers' (and 'tricked them') but if you read any EULA you'll see it's all best-effort, sold as is, no warranty for any purpose, etc etc, and this has always been the case.
Should it be the case? I don't have a good answer there. If you want penalty clauses, I'm sure you can find vendors that will oblige, but a) you'll quickly have an adversarial relationship with your supplier, after b) you spend stupid numbers of monies negotiating such a contract, and c) you'll still suffer exploits and outages.
The EU is currently working on making that happen. The current draft looks like it could be improved, but overall this looks pretty reasonable.
The nice thing about EU doing the heavy lifting on some of these tendentious subjects is that the rest of us often get to (eventually) enjoy the benefits, just because it's easier for them to not have to maintain two 'things' (product lines, releases, etc).
Triggering security bugs or zero days are typically things that require highly unusual and targeted usage which are extremely unlikely to occur otherwise.
So I would draw a distinction between failure of a product in normal usage and failure of a product when an active adversary is trying to cause it.
> 'pilot's licence'
Obviously it's not irony, but neither is it an abuse.
There are some regional variations in convention though. In my part of the world we differentiate the noun (licence) from the verb (license), and we also [can] use single quotes.
[0] https://www.bleepingcomputer.com/news/microsoft/microsoft-st...
> "No key-related actor activity has been observed since Microsoft invalidated the actor-acquired MSA signing key," Microsoft said.
>The actor used an acquired MSA key to forge tokens to access OWA and Outlook.com. MSA (consumer) keys and Azure AD (enterprise) keys are issued and managed from separate systems and should only be valid for their respective systems. The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail.
https://msrc.microsoft.com/blog/2023/07/microsoft-mitigates-...
* The bug here being too wide a scope, or more likely, the scope not being checked at all. Not the first time this class of bug has happened with a Microsoft product on Azure:
It's also possible that they have to word things carefully because international diplomacy happens in a language that looks like english, but is not. (In the same way the legal documents are not quite english.)
For instance, "China exploited zero days in our cloud services and targeted US gov't communications. We are addressing the situation." could mean "China has committed an act of war against the US, and we are responding in kind on behalf of the US government."
The last time I checked, Microsoft did all sorts of shady clandestine stuff for the US military and intelligence communities (they even supported the US CLOUD Act). Also, they manufacture stuff in China. I'm sure they have to be very careful with this sort of press release.
Chinese Hackers Targeted Commerce Secretary and Other U.S. Officials https://www.nytimes.com/2023/07/12/us/politics/china-state-d...
Some people still don't underestand what "cloud" means from a data perspective. (Look, we encrypt your data. With our key :)) )
When do we have alternative hw, os and apps stack ? You know, equal in eyes of govs and users of all kinds. Yes, Excel alternative and rest.
END SWITCH OFF THAT IDIOCY CALLED Exchange !! /caps must stay
Edit:
Wait, do thay wait with announcing this gov-level discredit until FCC allow them to buy Blizzard ?