Microsoft comes under blistering criticism for “grossly irresponsible” security
arstechnica.com
arstechnica.com
These vulns are cross tenancy violations, which, again, is insane. That's as bad as it gets for the cloud.
> This incident demonstrates the evolving challenges of cybersecurity in the face of sophisticated attacks.
The insane thing is that some of these vulns are as easy to discover as just running nmap. I'm sort of shocked that people haven't run into them accidentally. Hardly sophisticated.
I'm not trusting Azure with shit.
Why? Why does company size have anything at all to do with the security of their product?
Microsoft has been making shoddy, horribly insecure products for decades now. Do you need me to list all the email viruses and other such things that were running rampant in the 90s and 2000s?
What's truly insane is that people keep expecting Microsoft to do better, and then being disappointed when they don't. The common saying is "the definition of insanity is doing the same thing and expecting a different result", and that's exactly what most people do in regards to Microsoft and product quality or security.
Because they have a massive security team. Size has a lot to do with security.
> What's truly insane is that people keep expecting Microsoft to do better, and then being disappointed when they don't.
Microsoft has done a ton of impressive security work when it comes to Windows, they've really stepped up their game. They've invested quite heavily.
Unfortunately the Microsoft approach to software engineering is to set a bunch of monkeys loose on a room full of keyboards, rather than to spend their considerable resources vying for top talent.
(Obviously they do have some good engineers, no offense if you're one of them, it's simply that from my sample size of 5, 80% were just warm bodies with email access.)
As long as all they have to do is say "Whoops! We're sorry" when a breach happens, we should expect breaches to be the norm for all big companies.
Off-topic: this is exactly the same reason that Google offers up ads for scams and ads containing or linking to malware on their own advertising network.
The only way to get to the size of these companies is to scale what can be scaled, and damn the rest until the pigeons come home to roost. Which, if they play their political-donation cards right, won't happen. And if it does, jeez they've made bank in the meantime, and will Goodhart the shit out of whatever watered-down legislational changes may make their way through.
Because they have the money to hire people who know what they're doing, though it seems they are having difficulty selecting the right candidates.
Yes, Google gets criticized for not having any customer service. So... what? Has this affected Google's profitability one iota? No.
Same with MS.
This is a nitpick, but it's often completely reasonable to expect a different result by doing the same thing. Nothing against what you wrote, I just hate this saying so much. It's usually wrong to assume things are context-free. Most of life is defined by routine. Erosion carved out the surface of the earth, breathing and eating keeps you alive, etc.
At some point the definition of "same" comes under scrutiny and you will find that it's impossible to truly do the exact same thing more than once, and yet even if it was possible you might still get a different result because other things you had no control over changed. Entropy makes it all just so.
Of course, this then leads to an argument over how the conditions differ in the example where the saying is used, like with MS here.
It was so boneheadedly stupid, it was like a sysadmin making all user directories readable by all users. Not sure how that would not be tested. And made me worry about what other vulnerabilities lurk in Azure.
[0] https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-v...
Nothing seems to have been designed to naturally fit together, everything feels like its glued on
This is a trademark of Windows since the beginning.
To be fair, Microsoft has historically certified to conform to EAL4 which requires AVA_VAN.3 which is the ability to protect against "Enhanced basic" attackers and includes a actual penetration test. However, despite decades of attempts, they have never once successfully certified any product against AVA_VAN.4 which is the ability to protect against "Moderate" attackers. They have literally never once been able to protect against "Moderate" attackers. And they have the certifications to prove that they absolutely, positively, can not.
It is the height of idiocy that anybody listens to or trusts anything that Microsoft says at all about security. The have literally certified that the height of their ability is abject incompetence and the total inability to protect against "moderately" skilled attackers. Until they can definitely prove and certify otherwise, their claims of security should be completely ignored as the useless trash that it is.
[1] https://learn.microsoft.com/en-us/windows/security/
[2] https://learn.microsoft.com/en-us/windows/security/security-...
[3] https://www.commoncriteriaportal.org/pps/
[4] https://www.commoncriteriaportal.org/files/ppfiles/PP_OS_V4....
[5] https://www.commoncriteriaportal.org/files/ppfiles/PP_OS_V4.... Page 53
[6] https://www.commoncriteriaportal.org/files/epfiles/2022-21-I... Page 14
Advanced would be the CIA, Mossad, FSB, and the like.
Of note are the Security Assurance Requirements (SAR) seen here [2] which discuss the certification process.
The Security Functional Requirements (SFR) seen here [3] are more focused on what you are certifying and the sorts of problems you are certifying to solve.
As seen in the SAR document [4], AVA_VAN.1 is "basic" with a public vulnerability search. AVA_VAN.2 is the same, but they do a independent pentest. AVA_VAN.3 is "enhanced basic", AVA_VAN.4 is "moderate", AVA_VAN.5 is "high". The EAL levels are listed here [5] and echo the same things I stated about their corresponding AVA_VAN assurance requirements. Historically, EAL4 (the highest level ever achieved by Microsoft for any product in any configuration) said something like: "protects against casual and inadvertent" attackers, so that should probably help you calibrate what "enhanced-basic" means.
As for what constitutes "high". You can see a OS certified against the SKPP [6] here [7] at EAL6+. A EAL6+ certification requires AVA_VAN.5 or equivalent. For the SKPP they use a equivalent, AVA_VLA_EXP.4, which requires the NSA to certify that it protects against the NSA (with full source code) as a proxy for a "high attack potential" actor.
Yes, that is a certification by the NSA certifying that the NSA can not hack the OS even with full source. This is the OS used on the F-35 and the certification was done to determine if it was acceptable to bet the entire US Air Force on the OS, so the NSA was not playing pretend in this case. That is what constitutes a "high attack potential" actor.
So the gap here is: "protects against casual and inadvertent attacks" vs. the literal NSA.
The funniest part is that literally everybody says they are being attacked by "nation-state" actors. If they really are being attacked by "nation-state" actors, then they should be using systems that have been proven and certified to protect against them, not systems proven and certified to protect against your roommate in college.
[1] https://www.commoncriteriaportal.org/cc/
[2] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR...
[3] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR...
[4] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 184
[5] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 33
[6] https://www.niap-ccevs.org/MMO/PP/pp_skpp_hr_v1.03.pdf
[7] https://www.commoncriteriaportal.org/files/epfiles/st_vid101...
They rejected it on the basis that they do not investigate any vulnerabilities that require man-in-the-middle to exploit.
Seriously!?
You can literally kerberoast Azure AD by default, and that's a known to be used in the wild attack vector since 2014. In a cloud service. Today.
Spammers literally rent Azure VMs because they know that the IP range of azure is not processed by Outlooks/Exchanges email filters.
So often researchers did the right thing and disclosed everything correctly just to get Microsoft to say "oh yeah here is another RCE, but we don't give a damn. Oh, and there is no patch either."
It's just so ridiculous.
There's even unfixed RCEs of VBA from the Office 2013 days which still work, because the mentality of never touch a running software creeped into how Office is built (which is: have a literal copy of all outdated Office versions for the sake of compatibility).
And then people wonder why "Hackers" always say that Microsoft is insecure and why ISO27001 is now a google dork to find easy to hack victims.
Can anyone provide references for these proving their current existence?
I think this is because of their business model, which is to respond quickly to the market with features, not stability, security or polish.
That said, their intrusive data collection is a nightmare.
the product only has to be just good enough to get some pointy haired boss to approve the purchase
(and he never has to use the software)
But it is a big place. And not everyone gets the memo.
Also it's worth differentiating between Azure and the rest of the Microsoft silos. The Xbox isn't being cracked on the regular. The microvirt for applications and browsers in desktop Windows seems very well thought out. It seems as though the Azure team are pretty awful, though.
It's hard to even describe how historically bad they've been; they normalized and encouraged unsigned binaries, essentially viruses and worms, and were NEVER punished.
1. Debian - SecureApt - https://wiki.debian.org/SecureApt
2. Arch - pacman/Package signing - https://wiki.archlinux.org/title/Pacman/Package_signing
3. Fedora - RPM - Checking Package Signatures - https://docs.fedoraproject.org/en-US/fedora/latest/system-ad...
Everything coming from Windows Update is also signed by a public CA.
None of those projects have come close to Microsoft in terms of creating a product, for pay, that average people reasonably rely on.
Again, using a legal definition of reasonably; a widely used and paid for product can be held to something like a "merchantability" standard - especially if Microsoft has ever claimed their product to be safe and secure, which I'm fairly certain they have.
Azure...is a whole other thing. Every single service I look at feels like it's been developed two or three times, and renamed at least once...with varying degrees of backwards compatibility/interoperability/deprecation. The security interactions must be a nightmare to properly test for MS. On top of this it feels like there's multiple strategies being enacted simultaneously which makes it hard as an admin user to know you're doing the right thing in general.
Other cloud providers undoubtedly have some of the same issues with complexity/change but AzureAD (now renamed to Entra ID for whatever reason) is being used to manage core things like user accounts and mailboxes for organisations of all shapes and sizes (often without internal security teams).
There's also an unpleasant feeling that security is an upsell opportunity. It's a bad look.
Elon Musk was one of them (at what became Paypal)
Honest question, why was the decision wrong? It does not matter to me eather way, I’m just an engineer that was brought in to consult on some aspects of the contract.
There’s an entire subculture of the IT world that spells it “Micro$oft” and refuses to acknowledge its very existence, or a valid option.
I once saw a post about how some Linux tool had support for “every major LDAP directory system” and did not list Active Directory! It’s like… dude… something like 99% of deployed LDAP systems is AD. The rest is a rounding error.
(I think it is directly related to the lack of stranglehold which MS had over much of daily computing in 1990s. Apple, Linux, and mobile platforms forced it to compete and innovate more seriously, winning back quite some respect.)
The only Windows systems I've seen in over 15 years were to run Active Directory over 10 year ago (and not since), my personal gaming desktop (which no longer runs Windows) and GitHub runners for cross compilation.
There's plenty of Microsoft out there, but there's an entire, thriving universe where Microsoft is completely irrelevant.
Imagine if someone listed "modern UNIX-like operating systems" and the list went something like: NetBSD, OpenBSD, AIX, OpenSolaris, and then went through dozens like that into ever more obscure things nobody has ever heard of, but skipped Linux like it didn't even exist. Just some Finnish guy's hobby project, not really worth discussing, right?
It gets to the point where it's absurd.
As a real example, someone made a printable SVG/PDF poster of "big data" and "data science" companies and technologies. They were listing dinky little startups that had a total value smaller than the annual cost of an individual Azure storage blob container that I deleted to save money. That was an "oops" by someone that the customer didn't even notice.
> It gets to the point where it's absurd.
All of the examples you provide don't paint some cohesive picture, they come across as random, haphazard strokes with no form or meaning. Your original comment attempted to answer a question by ridiculing an entire demographic of people who care much more about human rights than you realize.
That doesn't mean I'll just ignore their existence or forget to list them as places in the world.
It's a uniquely Linux-fanboy thing to just pretend Microsoft doesn't exist, or that it's not even worth including in a list.
"Superpowers: Russia, China, and India."
"Hello!? United States!"
"The united what?"
Overall, this take feels immature and insensitive to the ideals that drive Linux users.
I can't comment on the LDAP thing on a technical level, but if the focus is on libre software, why is it apropos to list proprietary things that it's compatible with? Software that boasts this compatibility doesn't always keep it, or sometimes loses it due to deliberate action from the proprietary party. I don't think I'd list Active Directory either. It's not something one can vouch for unless they're literally Microsoft.
> Leaning on a proprietary solution also means you're downstream of any decision the makers of the tool make, including choosing to nuke your (and/or your business's) use case.
My understanding is that OP is advocating free/libre software protects a business from changes in software that could affect the business' use case.
This risk is present in both proprietary and free/libre software. Maintainers may remove features that some users find critical. If a feature is removed and your business requires the feature, you now need to maintain a fork of the software or contribute development time upstream.
Depending on the project, it may move slow enough for the dependency to be slow to update and it be fine. Depends on what you're doing.
At least in the case you mentioned, I can revert to an older version and freeze it there until my business can sort out the way forward.
Ideally, one chooses dependencies that are easy to replace and reasonable to maintain for a bit, if needed. Or if you're lucky, no dependencies at all!
How is that possible? I'm guessing you mean the best terms for Windows machines and Windows-based services. As soon as you exit the Microsoft realm, the prices plummet...
As someone who has used Azure, AWS, and GCP since their inception but mainly Azure for very unfortunate career choices -- I can assure you Azure has the most problems of any sort you can imagine.
Your MS rep (if you're big enough to have contact with one) will most assuredly be using their checkbook for you guys or your client. I'm not being melodramatic. This isn't even an original opinion or experience (go ahead, look around HN). And it certainly isn't some cultural "M$" backlash as another poster put it.
If this post seems editorial it's because after nearly a decade of this nonsense I'm just simply exasperated, and it greatly confuses me when people who are within the MS ecosystem don't know how bad they have it with Azure. It's basically unacceptable that MS gets away with it.
From AKS to WAF to Cosmos DB take your pick. You will run into issues and you will run into them continually.
Personally with my experience, Azure is not something I could ethically ever recommend to anyone.
One of fun things we had with our MS experience was writing code that should work according to docs, returned nonsensical errors (not documented, generic kind of error) from their API, only for that to magically start working next day...
Even the basic stuff appears to be shoddy in places, for example I received notification about meeting that I was added to 5 days ago about 3h before the meeting.... when the meeting author edited the meeting to add next person.
Also trying to find what made e-mail land into spam in cloud exchange is near-impossibility... and whitelisting them in global rules just doesn't fucking work for no good reason. It's utter mess.
Just off the top of my head, we had a ms forms, a couple actually, that as soon as they hit 50k entries, broke in weird ways. Not accepting new entrys, dropping entries, etc..
That's just one example I immediately recall where I could code up a better solution in a short amount of time, that just shouldn't be a thing with a large cloud/service provider like Ms.
A common bureaucratic failure mode when evaluating competitors is to make a bunch of categories:
Performance: 4/5 Ease of use: 4/5 Cost: 3/5 Security: 0/5
and then average them. When for these categories, you probably should compare the minimum rather than average.
I can't remember any outages in the few years I worked there though.
We've tried the latter, twice, they got bought and support quality tanked both times. We don't want to manage hardware yet, so...
Also, customers want MSSQL, and managed MSSQL is nice since it's trivial to scale up and down with the needs of the customer.
Started using their other services like Service Bus, Blob Storage and Application Insights. We're using .Net so integration is quite simple.
It wasn't my call, but there weren't that many great alternatives from what I can see.
In the case of GCP this is untrue.
> We're using .Net so integration is quite simple.
This is the reason for most deployments. They are MS shops so the go with the MS Cloud.
You're probably right, but anything that isn't core to their ad business seems highly risky to rely on long-term.
I certainly wouldn't risk recommending them.
Why would they want that when PostgreSQL exists? That's like saying customers "want" Oracle databases despite the existence of this post:
Postgres has its strengths, but so does MSSQL.
They already run it due to other software than ours, so their IT is already familiar and has permissions, auditing etc in place.
1. Its cheaper
2. They're already a C# shop so it just "feels right"
Thats about it, really. That appears to be the sum of the thought that went into it. And that also explains why they had to bring myself (and others) in as very expensive consultants to un-fuck various systems...
So long as Microsoft has something interesting to offer consumers and business, security will be the last thing people care about.
Microsoft has had absolutely terrible security since I've had a computer and it's been heavily criticized the whole time. None of this has stopped their meteoric rise to extreme profitability.
GitHub was similar, they published their freaking private keys accidently, which should raise some major red flags, we're all just going about our business with GitHub.
I was down voted hard and fast for my original comment but I'd like to see someone actually disprove my point. I've been in this game way too long to know that almost no security issue matters in the eyes of consumers so long as the company offers decent products and has a great marketing team.
I'm ideologically opposed to this lack of inaction and I think you're right, you'd need some type of financial disincentive to change people...
Social media itself is a type of privacy breech and people actually openly engage with it.
I don't say this to imply that everyone is equally bad, but to question if is obviously as illogical as you seem to think it is to stick with a company that's had a major security debacle. What certification can you get from another CI vendor about their security procedures that CircleCI wouldn't have given you 2 years ago, or your internal Jenkins team wouldn't have offered?
GitLab currently (since August 2021) suffers from the same "SSPR Abuse" vulnerability that Obsidian exposed on Azure AD yesterday.
They were nonplussed by my proof of concept and declined to move forward with the bug bounty as offered on Hackerone.
Sure, we've learned that Azure is less secure than we may have thought last week, but is AWS or GCP better? Or have they just not been uncovered for their issues yet? Or maybe they had their big security issue last year. Once everyone's had a big problem, what do you do? Make up some scoring system and keep re-migrating your company to whoever currently has the lowest "security mistakes" score?
And when a bear attacks you and your buddy, you don't need to outrun the bear, you just need to outrun your buddy.
On second thought, I'm not sure any of this philosophically applies to Cybersecurity, given the low cost of entry, stealth and anonymity, and the ability to mount massively parallel, unattended attacks.
Yes, they are.
can you imagine what would happen if the GRU got into the Teams backend with several year's history?
now consider that the only thing protecting that data is Microsoft software and their internal processes
(I care)
It isn't like Azure is just ignored in the industry, time and time again I see it billed as the "non amazon aws" for companies that don't want to support AWS due to Amazon.
I feel like I hear more about GCloud issues than I do Azure issues which is concerning given how little GCloud is used even compared to Azure.
https://www.cnbc.com/2022/12/21/google-leaked-doc-microsoft-...
[1] https://cloud.google.com/blog/products/infrastructure/google...
https://news.ycombinator.com/item?id=36770235
> "Microsoft’s engineers should never have deployed systems that violated such basic cybersecurity principles"
I hope someone quotes this line back when they inevitably introduce a 'we want a backdoor to encryption' legislation.
Although, even worse, the private key could likely have been used to actually forge communications from those parties.
About this time there was a "security stand-down" going down at MSFT in part because several federal customers LITERALLY had to solicit an ACT OF CONGRESS in order to continue to use Win2K (or an early version of XP) with all it's known security flaws. Do not ask me about the version of Win2K in nuclear submarines. (Really. Don't ask me. That was someone else's project. I really don't know anything about it other than the rumors that were swirling around BlackHat.)
So here I am, coming in as some guy who's hip to secure software development and tools and how to convince devs to do the right thing re: security even though they're under a deadline. My third interview of the day was this guy who supposedly wrote Excel and was the "third highest ranking coder in all of MSFT" (not Simonyi, I would have recognized him.) And his first question was "So... how's your QA skills?" This isn't what I'm thinking I'm interviewing for, so I say "Pardon?" and he replies...
"This security thing is bullshit. Bill's going to eventually realize it's bullshit and in a couple months we'll go back to writing software the same way we used to. So I'm going to have to find a job for you and I'm thinking QA; that's the same thing as security."
I did not get that job.
I believe Michael Howard or Dave Leblanc got it. They went on to write a pretty decent book about secure product development and if you're a microsoft shop and have heard of the Secure Development Lifecycle, it's largely because of Michael and Dave.
(Don't worry, I was fine. I went on to work at Handspring and PalmSource and a bunch of enterprisey dev shops that were hip to the idea of developing secure code. And my life was probably filled with fewer headaches than anyone at MSFT.)
But... I remembered that interaction. Microsoft keeps saying "oh yeah! we're big on security!" And in many ways they are. MSVC (or DevStudio or .NET whizbang or whatever they call it now) have several very cool fuzzing and analysis tools. I've heard the Azure group is better about security than they were, though that's rather a low bar. I feel for them since they have a metric boat-load of legacy code and a development methodology that sort of guarantees failure.
They are also the strangest and most conceited group of developers I've met (with the possible exception of Amazon or Facebook or Netflix.) Come to think of it... what the heck is it about these FAANG companies? I bet I'm just meeting the duds. There have GOT to be decent developers in there somewhere.
They're all HUGE dev organizations and I appreciate how difficult it is to get that many developers pointing in the same direction at the same time. But at the end of the day, MSFT has a culture that really doesn't care about security. Or at least that's my take on it. I'm sure there are plenty of places in Redmond where people care about writing code that isn't buggy or vulnerable. But it's 20 years later and it still hasn't spread far enough.
So it goes.
my UK "Amazon" card was really a NewDay card and the US one seems to be provided by Synchrony Bank
should really be called "Amazon Basics" credit card
They don't issue credit cards, to my knowledge anyway. Given different around the world, banking laws I doubt they ever will, easier to let a bank deal with that.
Mostly: hiring people for perceived "talent" over actual engineering skills (especially engineering soft skills.)
Imagine interviewers highlighting someone's CV because they've won Putnam math competitions, while round-filing some other CVs because "they write Haskell/Erlang/Rust/etc on some hobby project, and so they might try to push for it at work and then burn out when they find out we won't do it here."
Now imagine the people hired by a process like that, going on to hire other people, and so on.
> I bet I'm just meeting the duds.
That too. In a big org, nobody with "real shit to do" is going to spend time interviewing. They're going to push that off on someone whose time can be wasted. Which means company culture gets decided by a bunch of people whose time isn't worth anything...
Listening to the cybersecurity person interviewed here play down the significance, one is left to possibly believe cybersecurity folks rely on Microsoft to keep them employed.
According to this podcast, the only reason the government discovered this breach is because they were paying Microsoft for the "privilege" to see who was accessing their email. Most customers were not paying thus would never have discovered similar unwanted access.
If charging for this transparency is a "business model", as the podcast suggests, and there were only a relatively small number of "customers", it really makes one wonder. How much money were they making from this "business model".
Too long.
If Azure is as bad as this article makes them sound, does that mean most major security certifications are also as pointless they look from the outside? Like the pointless ISO 9001 certification - which only states "we have a process; here's the process; we follow the process; we don't deviate from the process"?
https://www.pressenterprise.com/2015/06/10/cartoons-broken-w...
This is vaguely like Kubernetes but worse.
So for example they can’t do zone affinity for traffic routing, so all of their zone-redundant traffic ping-pongs between data centres like crazy.
If you use just a couple of layers of their services like private endpoints and app gateway, you can expect to see 15ms response times.
I can't talk about what I saw while working there, but let's just say that I have a nervous tic when someone tells we have a team for security so you need not worry, and when can you have it done by
It's not malicious, but the effect is sort of like wearing a blindfold and one hand juggling, throwing things in the air, and presuming that a right hand (a) exists and (b) is not currently holding several other balls.
Everyone was super lovely and awesome and smart, but there is (for whatever reason) an attitude that is one of those things that is handled/reviewed by a special team, like accessibility, or HR, or product design, or backups.
The thing is, we did have a great security team, it's just that expecting them to have local knowledge of every single line of code is obviously unfair to them, and the idea that you can "do security" on any product just by applying a fixed set of rules somewhere way down the pipeline is to grossly misunderstand how vulns happen and work.
Every single IC can and must be on the lookout for vulns. They're vulns. They are literally made out of eyeballs pointed elsewhere.
Security is like hygiene: everyone has to wash their own hands after they go, it makes no sense to think that everyone can save time by having a Department of Hand Sanitization.
What the hell happened? Is annual security training still a thing?
Note: My time at this company overlapped heavily with Covid WFH, so things may have been looser/weirder than normal.
And regarding threat modelling: I literally have no idea; I was just an IC. All I know is, there were several occasions where delivery cadence was selected for, and in my opinion, on at least some of those occasions, security should have been selected for instead.
One charitable explanation is that they'd just threat-modelled my part of the product and decided there weren't any threats there, so there was no need to ease up on the gas pedal. But some threats are subtle, and where you least expect them.
That still happens.
>Is annual security training still a thing?
Yes it is.