Everything authenticated by Microsoft is tainted
graz.social
graz.social
- On June 26, OWA stopped accepting tokens issued from GetAccessTokensForResource for renewal, which mitigated the token renewal being abused.
- On June 27, Microsoft blocked the usage of tokens signed with the acquired MSA key in OWA preventing further threat actor enterprise mail activity.
- On June 29, Microsoft completed replacement of the key to prevent the threat actor from using it to forge tokens. Microsoft revoked all MSA signing which were valid at the time of the incident, including the actor-acquired MSA key. The new MSA signing keys are issued in substantially updated systems which benefit from hardening not present at issuance of the actor-acquired MSA key:
- Microsoft has increased the isolation of these systems from corporate environments, applications, and users.Microsoft has refined monitoring of all systems related to key activity, and increased automated alerting related to this monitoring.
- Microsoft has moved the MSA signing keys to the key store used for our enterprise systems.
- On July 3, Microsoft blocked usage of the key for all impacted consumer customers to prevent use of previously-issued tokens.I’m not a security expert. What are the holes in this strategy?
Absent either customers paying for it, or regulations requiring it, Microsoft certainly won't sink money out of the goodness of their heart. I don't believe there are a lot of regulations for this — and how many customers do you think would pay for something like this? Realistically? :-(
If you have immutable, permanent audit logs, you can go through all actions authenticated with something directly or indirectly signed by the leaked key. However, building such an audit log in a way that someone with maximum permissions still can't tamper with it is not easy — and not cheap. (And, worst case, the audit log may not have the necessary detail; e.g. just listing an authenticated identity, but not the way authentication was established — thus not allowing easy identification of possibly compromised access.)
As such, the hole in the strategy is that it doesn't account for other persistent backdoors that may have been added while access using this leaked key was possible. It only prevents further exploitation of the issue. But depending on the sophistication level of the attackers — which seems extremely high considering how the key was apparently stolen — it's nigh impossible to figure out how many secondary avenues of access they have established.
* We already have confirmation that the US government has been tapping internet infrastructure, accessing back doors in BigTech backends, and compromising industry-wide encryption and RNG standards.
So there is no way to prove that SOMEONE at the NSA doesn't have the ability to access all of the information on the internet.
And, since the NSA is just more humans, that means there's no way to prove that someone else hasn't sold that ability or specific subsets of the data to malicious actors.
Post Snowden revelations, you have to do risk analysis. Is some US or Five Eyes Government Agency able to access all your personal information or business competitive secrets? Probably Yes. Can one of your competitors? Probably Not. Can a malicious neighbor or drug cartel that would then use it to extort you for money? Probably not.
So even in this hypothetical example where everything authenticated by Microsoft is tainted, it's not clear if it actually changes this equation significantly.
Microsoft has some of the worst security vulnerabilities and practices I have ever seen. I can’t for the life of me figure out how executives at big Fortune 500 move their workloads to Azure.
The only selling point Microsoft has for Azure in some domains is that Amazon is their competitor. I wish Amazon just let AWS be it’s own thing.
I also hope that Microsoft step up their security game but at this point it’s kind of a lost cause.
Almost every organisation already has a huge-ass contract with Microsoft for Windows, AD, Office, Teams, Exchange and whatnot, deeply integrated with their core IT. So if the organisation doesn't already have AWS set up as a supplier, it's usually easier to push for an existing supplier instead.
I have experience with hosting my own on dedicated servers. It's mostly been fine.
It's all smoke and mirrors but it works.
It does work and it is very compelling, at least on the tin. The problem is convincing powers that be that it doesn't do what it says is borderline impossible. The most they've built is equal parts astounding and terrifying.
In a sort of funny twist I feel like this is an area Google could really excel in if they got their shit together. Signing up for Workspace and GCP and everything else makes you feel like they don't want you to use their products.
TFA seems strangely relevant as there seems to be some cultural values reflected in both Microsoft's security posture and reputation, and the ability to bundle and market disparate and downright broken (at least in some cases) products effectively.
The problem is that Microsoft still hasn't said that officially and directly out loud despite the writing on the wall. They continue to sell DevOps to new teams and point to its "active roadmap" (despite it being mostly unambitious and increasingly "copy X from GitHub"). So a lot of companies still have just enough doubt in the message that DevOps is legacy/dead that they keep inside it and don't migrate to GitHub, because Microsoft keeps giving them that doubt. I'm not sure if it is superstition on Microsoft's part to not kill DevOps (it is an ancient team with quite a legacy; it's maybe Microsoft's albatross), some sort of "magic" migration strategy they want to keep secret until complete, or just that Microsoft loves telling customers what they want to hear and enough companies want to hear "DevOps is alive and in good health" for a number of sunk cost or emotional support reasons.
Once Microsoft learned that ADO was not, indeed, dead, they began to reformulate the path forward for ADO and have actually released a fair amount of preview and release features since the pivot back.
Enterprises like ADO and even when ADO was “legacy”, MSFT continued to see an uptick in adoption. ADO has better integration with Azure, at least for the web app space I play in.
Microsoft will show up with 10 sales engineer, while others might just be a contractor or a zoom call.
They present themself as the authority for non-technical business and is winning a lot on that.
They're good at capturing market share, no doubt about it.
Blame CTOs and system admins who are either married to the stack because it's the most familiar OR they were forced onto it by a CTO because, "no one ever got fired for picking a Gartner upper right quadrant option."
I used to run a Windows 2000 Pro web server, after lack of security I switched to Linux.
Microsoft may be popular, but they have big holes in their security. Always has been.
As long as the underlying OS is secure enough that attackers can't get in via something like a buffer overflow in the TCP code, website security is almost entirely a matter of web server application security.
A well written web server application on Classic Mac OS then could be more secure than a less well written web server application on a more secure operating system such as NT.
What happened was that someone entered a 0 on a data entry form in a field that was not supposed to be 0. That form was submitted to an application on a server, which used it as a divisor and got a divide by zero exception.
That application did not handle divide by zero exceptions and so was terminated by the OS.
With the server application no longer running terminals around the ship that relied on that application were no longer useful.
Like "antivirus".
Not exactly useful for a web server beyond development.
FWIW, I had an Apache box running on Slack which got fork bombed around the same timeframe.
Security was largely up to the competence of the individual. I was learning Linux :-)
Win 2K Pro is limited to 10 connections. In 2002 I worked for a surgical tool company with sterilizing software for 300 clients and they tried to do it on Win 2K Pro, so I switched them to Server with SQL Server 2000 instead of Excel.
It doesn't matter that China/Whichever state actor is snooping on all your user's data. Either no-one finds out and you're good. Or the blast radius is _so_ wide, that all blame falls on Microsoft
This issue.
Services get compromised often, cloud or customer managed. Microsoft has a mature, professional and effective security team. They got compromised, due to implementation flaws and one or more (my conjecture) corrupted insiders. Most organizations would have no idea wtf happened and would not be able to identify what has been revealed to the public.
Hindsight is 20/20.
I'm not surprised, it's Microsoft after all. They lied about their data security to win bids in health market, only to let everybody down after a year when they finally understood the cost to secure that particular data were too high for them.
Can you explain this more? What's wrong with AWS compared to Azure?
I no longer work there, but they chose GCP because AWS wasn't even in the running because of this.
Because they’re not financially liable for the mistakes of Microsoft. They go to these services because they sign contracts offloading that risk to another company. If Microsoft leaks your entire datastore because of poor security on their end, you sue them for damages because ensuring the protection of your digital property is part of the reason these companies are enticing to use in the first place. They use Microsoft because everyone uses Office 365 because it integrates well with Active Directory which they’ve used for their corporate directory for 20+ years.
> They were able to implant #backdoors, self-made keys, ... all over the place.
I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did.
> If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get rid of the intruders. Everything authenticated by Microsoft is tainted. Even #Windows auth.
Microsoft's response also seems to clearly state that they have rotated the keys, moved them to a more secure storage, etc. They don't say they've removed the attackers, I guess, but they certainly don't indicate that the attack is ongoing. Certainly they don't indicate that all auth is forever broken.
I feel like the conclusions being drawn are extreme.
https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...
> I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did.
When you consider the potential implications, and possible scenarios, from a security perspective you have to assume that they're not just "possible" but a reality.
If you find a zero day exploit, you don't just ignore patching it because "well nobody else probably has it".
Not saying that MS’s response was great, but I agree with GP that the whole thing is hyberbolic.
Uhh, what? Of course you do. Why give the benefit of the doubt to hackers who hacked you with malicious intentions? That's the type of security nonsense that I'd expect from... Well, Microsoft lol
Obviously I won't run it on my personal computer, but i'm not renting my pc to anyone.
That's pretty much the only option if you safeguard valuable data for your customers. Yes, it's expensive to get breached, so take precautions to make it a rare event and contain it as much as possible when it happens.
I don't think the article is unreasonable. This is cloud infrastructure sold to companies with defense industry contracts where breaches are taken seriously.
This is not theoretical. When the openssl fiasco hit, I worked in a place under financial regulation. Not even the defense sector, which is under much stricter rules. We had to go through all logs to ascertain customer data was intact, and since leaking private keys did not leave a trace in the logs we then wiped clean all systems these keys secured.
This was a massive undertaking to coordinate and minimize downtime for customers but it was deemed necessary to comply with security regulations. To hear that a big juggernaut such as Microsoft doesn't even do this without facing much consequences is mind boggling. I can not understand how that would ever pass an audit.
I have literally done incident response I am well aware of what the investigation process is like.
"The box" in this case is their entire org.
No you don't. You definitely don't want to assume otherwise and you spend the time derisking and investigating, but if you have zero evidence to support the situation you don't just consider it the case anyways.
You linked Microsoft's investigation report on the exploit.
The attackers first managed to get access to Microsoft's development network, noticed a crashdump, understood the possible significance of that, dug through it, found a private key, then acquired enough insight into Microsofts authentication systems to understand how this key could be used beyond its intended purpose and then executed on that.
And you don't believe they left persistent backdoors in some high-profile targets?
The conclusions being drawn are … entirely appropriate. Your argument maaaaaybe makes some sense applied to general public random cloud customers. Backdooring indiscriminately just increases the risk of discovery. But large companies and government users? You have to assume compromise, anything else is incredulously naïve.
cf.:
https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...
> Storm-0558 operates with a high degree of technical tradecraft and operational security. The actors are keenly aware of the target’s environment, logging policies, authentication requirements, policies, and procedures. Storm-0558’s tooling and reconnaissance activity suggests the actor is technically adept, well resourced, and has an in-depth understanding of many authentication techniques and applications.
(… especially when you're not even bringing up the fact that the compromised key was mainly usable to access e-mail)
I don't know what your point is.
If an attacker had full root across the org for an undetermined (but not short) period, I'm unsure what other approach you think you could take? You can't just run MalwareBytes and call it a day.
This comes down to a risk assessment. No company has a breach and just shuts everything down, that is insane. When we perform IR we build a detailed timeline, we collect the scope of potential access, and we form a remediation plan. We don't just go "well hey, anything can happen right? shut it all down".
So the question is how you handle such a situation.
That’s just embarrassing.
I’m under no delusions that an intelligence agency with ‘home team advantage’ wouldn’t already have the keys to the kingdom. If they are in the apparent habit of leaving the keys sitting around in random Cafes, the odds that other non-home team intelligence agencies have a copy increases dramatically too. Or even random miscreants.
As to if that matters? Eh.
$ dpkg -l ca-certificates
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name Version Architecture Description
+++-===============-============-============-=================================
ii ca-certificates 20230311 all Common CA certificates
$ trust list | grep Microsoft
label: Microsoft ECC Root Certificate Authority 2017
label: Microsoft RSA Root Certificate Authority 2017
On RHEL 9: $ rpm -q ca-certificates
ca-certificates-2023.2.60_v7.0.306-90.1.el9_2.noarch
$ trust list | grep Microsoft
label: Microsoft ECC Product Root Certificate Authority 2018
label: Microsoft ECC Root Certificate Authority 2017
label: Microsoft ECC TS Root Certificate Authority 2018
label: Microsoft Identity Verification Root Certificate Authority 2020
label: Microsoft RSA Root Certificate Authority 2017
label: Microsoft Root Authority
label: Microsoft Root Certificate Authority
label: Microsoft Root Certificate Authority 2010
label: Microsoft Root Certificate Authority 2011
label: Symantec Enterprise Mobile Root for Microsoft
Interesting that RHEL has many more certificates, when both packages take whatever's bundled into NSS.According to 'rpm -q --changelog ca-certificates' RHEL take their certs from "CKBI 2.60_v7.0.306 from NSS 3.91" and according to /usr/share/doc/ca-certificates/changelog.Debian.gz, Debian take theirs from "Mozilla certificate authority bundle" 2.60.
> Imagine what the CA/Browser Forum would do if they discovered that a PKIX CA had lost control of its signing keys, didn't revoke them and in fact carried on using them for 2 years without telling anyone...
Are these certificates affected? Or perhaps the CA/Browser Forum aren't aware of the scope.
Which has these among a long list (retaining the reverse order from link above). NB I have just copied and pasted for convenience; neither removed text which refers to links nor added the actual links. You can click through yourself if you want to follow the links.
8<---
023-08: Again Microsoft, again Azure: "unauthorized access to cross-tenant applications and sensitive data (including but not limited to authentication secrets)". If you aren't tech-savvy: this is very bad. (Source)
A reoccuring pattern emerges more and more: Microsoft didn't fix the issue in months and as of 2023-08-03 it is still an open vulnerability in Azure, risking the data of all Azure customers. related:
Microsoft comes under blistering criticism for “grossly irresponsible” security | Ars Technica
BrianKrebs: "The CEO of Tenable just ripped Microsoft a new on…" - Infosec Exchange
2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry, Source, German source)
With the default logs, customers could not even detect intruders as you would need to pay extra to get access to those log files.
Microsoft did not communicate which services were affected and which not. Any Microsoft cloud service was potentially compromised.
Most probably, the usual "any compromised system needs to be thrown away and re-created from scratch will not be applied here. As a consequence, you can't trust any data from Microsoft services any more.
Security experts like Mike Kuketz think that most probably we need to consider all Microsoft systems that are using their cloud authentication including all Windows hosts are compromised.
According to this German source, Microsoft is still refusing to tell what happened and which systems are affected to what extend.
2023-08-18: German comment: Many similar comments like that underline that Microsoft disqualifies as a trustworthy partner.
2023-09-06: first public explanation by MS: Microsoft: Results of Major Technical Investigations for Storm-0558 Key Acquisition Press reactions: heise (German), fefe (German)
> 2023-09-29: My Mastodon message about the latest news was posted on Hacker News and its discussion reached number one worldwide.
The circle is complete.
2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry [1], Source[2], German source)
Also the following:
https://infosec.exchange/@briankrebs/110820474957163710
Quite damning if true.
[1]: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... [2]: https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...
This is not to downplay how bad Microsoft's security lapses were, and how bad their announcements were. The most horrifying part to me, besides the need for "premium" logs to detect a breach which I'd been complaining about before this, was how PR seemed to blame the Exchange Online team for misusing the authentication libraries, but later they updated the libraries and said the token validation issue was "corrected using the updated libraries". That feels like internal blame shifting out in public.
[1] https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...
In the very same link he posts: https://www.microsoft.com/en-us/security/blog/2023/07/14/ana... "Post-compromise activity
Our telemetry and investigations indicate that post-compromise activity was limited to email access and exfiltration for targeted users."
So it's not "all Microsoft".
It's the usual exaggerated headline, but this time it draws attention on a person's post on Mastodon.
This platform is really no different from Twitter.
[1] https://www.researchgate.net/figure/Yearly-cost-difference-o...
Or is this the discussion of having a team of SysOps vs a team of Cloud Engineers?
My current employer handles things where internal service at the org are on-prem while customer facing services are cloud. Even the cloud stuff backs up to an on-prem storage system (though it also gets backed up to an off-site S3 provider).
You could operate an on premise bakery but most companies just order donuts.
https://techcrunch.com/2019/06/21/three-years-after-moving-o...
There are multiple analysis of that breach available. Pick one.
Here’s a starter.
Now I have apps where I need 15 minutes of maintenance a year, install and configuration takes 5 minutes.
Some cloud providers have amazing stuff, but I feel they all start to bloat and I don't have use cases that need whole clusters.
What we see, instead, is what happens to poorly democratized and incentivized systems.
There is a best of both worlds in there and I think we've gotten where we are now because of cloud providers marketing themselves suitable for everyone.
When everything was local and private, the attacker could only access a specific device or network, even if the security was often very weak. Now a single attack on a centralized entity has such a big payoff, that it makes if viable to allocate much bigger resources by attackers.
Also even for softwares deployed on on-prem hardware, big orgs will still need single sign on, which will still be open to these kind of attacks.
Maybe “on prem” but largely managed by someone else, which is already a thing.
[edit] to editorialize, I also think ~everyone is going to get this very wrong. I think doing this stuff such that you don’t grind productivity to a halt but also don’t have mile-wide vulnerabilities is goddamn near an Apollo Program level of difficult, and basically nobody is treating it that way (and a lot of them would probably sooner abandon their grand mass-data-total-control plans if they had to treat it that way—which is exactly what I think most of them should do, but execs just love the idea of perfect legibility of data and processes end to end on their phone or whatever, even if it’s in-fact just a money-wasting and risk-generating fantasy for most companies)
The company i work for just recently integrated all of our internal apps and services authentication through azure .. That feels like it was a mistake now.. or am I just over paranoid??
„Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society.
Wouldn’t it be more reasonable to teach:
1. You have no privacy, it is impossible to ensure or guarantee privacy, and there’s no incentive at all for anyone to ensure privacy. (Scott McNeally of Sun said that already in the late 1990s)
2. There is no security and every kind of security has been, was designed to, or will be compromised.
3. All your digital information is already public or will become public at some point. (btw: Every top-tier consultancy operates under that assumption)
There were already addons like that that created garbage traffic a while ago. Just wasnt practical without language networks.
For any bit of information, they may not apply, but if you assume they’re true you’ll:
1) not record information that is truly damaging in a damaging way (which is really good practice in general if you’ve got something to lose!)
2) have practical operational practices which do not rely on these being false - which is a really good idea if that actually matters (you have actual enemies somewhere).
3) you’ll focus on safety and building value in areas which are not mere information at rest, which is a good modern practice.
Osama Bin Laden already knew all this, which is why it took so long to find him. A decade or so. I guarantee you the CIA has been learning this with all their leaks. The FBI learned this this after COINTELPRO.
What is not written down can’t show up as a grainy photocopy in the New York Times, or a viral video from Wikileaks, or whatever.
What you’re talking about is a hammer to use to punish someone after a leak. But by then it’s far too late for anything actually valuable.
Necessary and important for ‘day to day’ stuff like bank account balances I guess, as long as you assume that they’ll be violated with little practical recourse if you have anything actually valuable in it.
Streisand effect, etc.
As far as companies are concerned, personal information should be considered hazardous material, and avoided at all costs.
But thinking it will actually protect you if you have an actual valuable secret is willful naïveté.
That isn’t defeatism, that’s a realistic appraisal of the situation.
If what you described was actually possible, we wouldn’t all be still able to browse all the top secret files leaked from Wikileaks for instance.
If you do have to write it down (for practical reasons), it’s best to assume it will be leaked eventually and write it down with that in mind.
Even better, is in your operational assumptions, assume it will then be leaked shortly afterwards and build in ways to work around that.
So for instance - key material should have easy ways to be revoked, rotated, etc.
Operational rules should be easy to update/push new versions, etc.
Authentication shouldn’t rely on parroting a well known value (SSN, a plaintext shared secret, a biometric, etc.), and should be easily changeable/rotatable.
Most of these we’ve been steadily baking into our day to day lives anyway.
What you’re talking about is necessary, but insufficient for anyone who has a secret they actually need to keep. At least in the modern world. None of those penalties are ever likely to actually occur either, because no one wants to pay them. And they know they will end up paying them at some point, because anything else is just not how the world works.
For classified top secret information all those rules apply in some form, yet we’ve had numerous high profile leaks of TS information for years. The intelligence apparatus has done everything they can to destroy said leakers, but with limited success - and those secrets are still out there.
And that is without financial incentive!
That’s all. Most folks won’t have those kinds of secrets thankfully! And when they do, they usually just don’t tell anyone.
I have to believe it's possible, but I have never seen any reasonable proposal for government regulation of infosec. Even disclosure requirements become bullshit and only harm everyone faster than they can get published.
Disagree. You don't need 10 years in IT to understand the meaning of: "M$ allowed customers to use their house-keys to open everyone's office safe, lied about it for 2 years, and still doesn't have a plan for fixing it".
McNeally was simply wrong, but despair is easier than fixing things, so a lot of people went with despair. The popularity of cloud and SaaS is the result. But this isn't a foretold destiny; just don't "trust" people you don't actually trust.
All of the points are not true I think:
1. People can still have guaranteed privacy (e.g. going into the woods with no devices). As with many laws an incentive to ensure privacy of others could be punishment in case of failure.
2. There is no absolute security, but there is security against certain threat models.
3. Why would data I keep on a device that is not connected to any network ever get public?
Well we expect people and corporations to fix a problem when confronted with it. That is what we expect.
> „Normal“ people will not read this, nor be able to understand, nor gauge or grasp the impact. It’s become way to complex. We can’t simply stop using mentioned services anymore as a society.
Have to give you a pass on "normal" people. I don't know any. I see no reason why we cannot go without the (by the way) unmentioned services or why we cannot change them to be more privacy conscious.
>Wouldn’t it be more reasonable to teach:
No it would be more reasonable to teach that privacy is vitally important to have a functioning society and economy. Anyone claiming different think they can exploit the information disparity between you and them to make money in the short term.
>1. You have no privacy, it is impossible to ensure or guarantee privacy, and there’s no incentive at all for anyone to ensure privacy. (Scott McNeally of Sun said that already in the late 1990s).
Well I respect Scott, but this is not his great moment. Let's change this to be still completely true: You have no property, it is impossible to ensure or guarantee property and there's no incentive at all for anyone to ensure property. Well we did find a way to actually do ensure property. It is called the law (and a government to enforce it). Just an idea to use this tried and tested concept on privacy as well.
>2. There is no security and every kind of security has been, was designed to, or will be compromised.
First this has always been true. Every lock can be picked. Fortunately not everyone can pick a lock. That is the reason why most of us still lock the door.
>3. All your digital information is already public or will become public at some point. (btw: Every top-tier consultancy operates under that assumption)
You mean those top-tier consutancy firms mentiond in this book: "The Big Con" by Muzzucato and Collington, Penguin, 2023? I can see that they sell the assumption, but they are not operating by it. If that were true McKinsey for example would have known their advice to Purdue Pharma would become public and they would lose big on it.
In short people who claim privacy is not important mean: _your privacy_ is not important and they are overly confident they can keep ahead of the information disparity to keep themselves private. See how hard, ironically, Google is working to keep all their information private in a public anti-trust trail.
My elderly aunt keeps her secrets on a notepad in her desk. I suppose a spy or a housecleaner (if she had one) could know her secrets but it won't be "hacked".
The whole "you have no privacy or no security" is false and only impacts the terminally online.
Do what the intelligence agencies do. Stop letting other people store your secrets. Put them in a nice heavy locking box. Guard them with a firearm.
Having a firearm only works as protection if (A) you are present and armed 24/7 to protect your safe, (B) you are actually willing to shoot and (C) capable of doing so better than your assailant.
In a business context, if the company is large enough, it might well be worth hiring day-and-night security guards and heavy steel safes. But for the average PC user, the security can be improved much more effectively with simple improvements like creating passwords with 'diceware' or using separate accounts for financial tasks.
The value of your personal info individually is $1? Maybe $4?
If you can hit someone who has 100k records, hey that's a solid payday.
But no thief is gonna go break into a safe, risk being shot by an angry homeowner, or kick off targeted attacks over.. $4. Even your flatscreen tv is worth more and is MUCH easier to steal.
Almost all adversaries don't care about a specific target. They want an easy target. A safe + upset well armed owner is not an easy target.
#1. You have no privacy ONLINE. Providers have perverse incentives to sell you out down the river. Therefore, you DEFEND yourself by keeping a shallow online presence. If you are a casual user, you keep as little information online, specially in social media, as possible. If you need an online presence, you ASSESS the risks and pay time and money to MITIGATE those risks. If you don't see a Return-Of-Investment on those mitigation efforts, chances are you have been CONNED into thinking you need an online presence, but you probably DONT.
#2. There is no ABSOLUTE security. All possible defense measure CAN be circumvented, not not necessarily WILL be circumvented. You ASSESS as many risks as you can imagine, and MITIGATE only those where you expect a positive ROI. The ones you don't mitigate, you ASSUME. The ones you cannot afford to assume, you DO NOT TAKE by refusing to use the system.
#2.a Corollary to #2. If you take ZERO risk management, you still have a BASELINE level of security based on the risk-reward analysis by the criminogenic/sociopath portion of the population; they will not attempt an invasion if they do not expect to get away with it, or to gain something out of it. The more cynical people in the know claim there's no security, the more this baseline approaches zero and the more vulnerable the general population is.
#2.b Even if you are not part of the general population, the lower the BASELINE, the more time and money you PERSONALLY have to invest in risk management to achieve a bearable level of safety. Cynicism is costing US time and money, pal; don't pee/shit on the village's wheel just because it looks edgy!!!
#3. All your CURRENT digital information is already public or will become public AT SOME POINT. You can do better and pick the technologies that will push that point FURTHER into the FUTURE. And for not yet digitalized information, you may make conscious decisions whether the convenience is worth the risk.
This is a giant claim.
It does seem theoretically possible that a stolen signing key could have been used as part of a bigger attack to access critical services like Windows Update or the Azure control plane, but it does feel like someone would have noticed that kind of systemic compromise.
Also, unlike what (I think) is being claimed here, Microsoft did fix the issue after learning about it: https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...
And those people had already hacked an engineer's account. Because the chances of stumbling upon this key when only hacking one engineering account are very low, it's reasonable to assume many MS engineering accounts had already been hacked.
Basically, your MS account is not safe.
This isnt being focused on enough here. MS is set up in such a way that there are individual members of staff, with individual devices, that just need to be compromised for all their infrastructure is compromised.
This fact alone means that's its near certainly presently compromised. states have the resources to place an engineer at MS, let alone compromise one of their devices.
This, critically, is not necessary. There is nothing technologically necessary about one person, or one device, having the keys to the kingdom. It's security malpractice.
The key that was compromised from one MS engineer was used in conjunction with a specific bug - crash dumps were including secret keys, accessible on a debug environment -, this is not how the system is intended to work at all and they implemented measures to fix it. So this is another hyperbole from the original post.
That's the access patterns of a single application for a single user. They know absolutely nothing about what's happened to their infrastructure.
1. You have a $200 million piece of defense-critical equipment. 2. You know that there was a 5-minute period where a potential member of a foreign intelligence service was alone and unattended in the same room as this piece of equipment.
What do you do with the equipment? You can:
a) Put the equipment into service b) Disassemble the equipment on both a hardware and software level and try to detect if anything was altered c) Destroy the equipment
If you choose anything other than c) you have probably never been, nor should you ever be, in charge of securing critical assets that can be targeted by a nation-state. This incident seems to indicate that the leadership at Microsoft would choose a).
Also, bear in mind that these are the people that you just sent all your ChatGPT data to.
Anyways, I've worked at companies that are absolutely targeted by nation states.
The idea that an attacker went to this length to get the key and then did nothing with it is absurd.
The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.
for some, this sounds like a nonsensical choice. for others, a defining moment of leadership.
>How a baker survived the Titanic sinking by getting really drunk
Bottoms up!
The Machine Stops by E.M Foster
https://web.cs.ucdavis.edu/~rogaway/classes/188/materials/th...
I'm not saying cloud computing is the solution to every problem, and nor should it be, but calling it a sinking ship is simply absurd.
Frankly, I grow so tired of people thinking everything is a boolean choice. The real problem with the cloud is people who see things as binary statements: "cloud is cheaper", "cloud is more expensive", "self hosting is easier", "cloud is easier", "cloud is more secure", "on-prem is more secure", etc. All of those statements are true just as all of those statements are false. The reality is far more nuanced and it depends entirely on the constraints of your business at that point in time. Such as what engineers / skill sets do you have on your team? Capital to buy hardware, your physical location, the product you're trying to build... etc.
But the problem with nuanced arguments is they're subjective to the immediate problem you're trying to solve. So you cannot debate them with other people as those other people are trying to solve different problems with different teams and different tools. And thus we end up with people posting bullshit blanket statements like "the cloud is a sinking ship" or the linked article that boasts that the cloud is less secure.
Cloud is centralizing. Centralizing, instead of distributing, is bad.
Centralization broadens and expands the attack surface and creates a honey pot for attackers.
This isn’t hyperbole nor is it alarmist. This is reality playing out before us in real time.
Fragmentation creates different problems than centralization, but it isn't a magical bullet either. Depending on your resources, you are far, far better off trusting even Microsoft than trying to come up with your own security implementation.
There is no consensus.
But, that's with every industry, every field, every platform.
Some warn, others ignore.
Wanna bet who's right?
I've been doing this stuff for longer than a lot of people on here have been alive and the biggest risk is always your weakest link. The weakest link in most companies isn't the cloud, it's the engineers deploying to the cloud. That weak link exists regardless of whether those engineers deploy to a centralised place or on-prem.
Is there an additional risk having something centralised? Sure. But in the vast majority of use cases, that risk is going to be marginal (and for those types of businesses where it is an unacceptable risk, they are largely not using public clouds for exactly this reason).
And we are back to my point about these conversations being nuanced. A security team, if they do their job correctly, doesn't just make blanket statements like "centralised systems are insecure" -- instead they identify the risks and develop an IT strategy based around which risks a business is willing to accept and which are not.
Some warn, others ignore. Is true. It's true for every industry, every walk of life, in every country, on the entire planet.
Experts, though, when have they agreed on anything, in any field?
One must ascertain for themselves which authoritative sources can be relied upon. The experts that warn of centralization are authoritative and masters in their fields.
Centralization in any other area of life tends to be bad for citizens, so I ask you this: Why would centralization lead to MORE security, or MORE benefit to the users and citizens of the world?
I'll wait...
That’s not what they said
> Centralization in any other area of life tends to be bad for citizens, so I ask you this: Why would centralization lead to MORE security, or MORE benefit to the users and citizens of the world?
I had already addressed the point about centralisation and risk. This additional question you’re raising is, at best, a straw man argument.
If you go back and read, and I mean properly read, pause and think about the comments being made, you’d realise that we aren’t saying risk doesn’t exist. We are saying the reality of that risk depends on numerous factors specific to each business, project, and even team. Thus you cannot distil “the cloud” down to a single truism such as what you keep trying to do.
Bloated security theater being profitable also doesnt help. One example is smartphones as TAN generators for online banking replacing TAN lists. While you can now charge customers per SMS, the second factor got quite a bit more easy to attack.
I don't see the argument here. CISA posts issues they find, are they intended to be comprehensive?
This is in addition to a lot of government agencies sitting on, and investing into the knowledge about vulnerabilities. Some of the more public ones getting fixed doesnt change the overall vulnerability of the system. There is a clear incentive mismatch. One cant pretend that those vulnerabilities are "safe" due to only spooks knowing of them. If you can find them, so can others. Especially if you are actively exploiting them.
I would argue that this shows both an unwillingness to accept improvements in security as well as actively degrading the current state. And this is before talking about governments actively adding vulnerabilities, which now even possible by law in some jurisdictions.
It’s irresponsible to make broad claims like this, that everything in Microsoft’s cloud has to be replaced to mitigate the breach. That doesn’t pass the sniff test.
I get that Microsoft has a vested interest in mitigating the PR aspect of it, but I doubt they’ve just done nothing to correct the issue.
This essentially makes all key western companies and public orgs, hosted on azure, probable targets. It's highly unlikely that they only stole state dept. emails, when they had access to banks, finical orgs, etc.
Indeed, their very ability to steal emails from the US state dept! makes it likely a breach at other less protected vital biz/orgs occured.
The whole of the azure cloud, and esp. the whole of managed MS apps at major institutions was compromised for at least a year. This is apocalyptic.
https://arstechnica.com/security/2023/08/microsoft-cloud-sec...
In the end, it turns out it was not accepting expired certs -- there was another auth method superseding the certs -- but the behaviour I saw in this case was not unusual to encounter.
Microsoft has many excellent engineers, even in security. But decades of culture rot take longer than a few years to fix, and a lot of old-timer Microsofties have this "not my problem" viewpoint that can lead to major security risks. No doubt, the way Microsoft has handled this year's layoffs -- staggered, leaving people in the lurch and in serious stress for months on end -- has wiped out much of the progress they've made under Satya.
tl;dr I'm not surprised by (a) Microsoft having breaches and (b) Microsoft not dealing with security issues in a timely manner.
Me, I have never used it and hope I never will have to use it. Luckily on the hardware I have, it can be fully disabled.
The company can recognize that "there is no choice" is not a valid option. There are many choices if the company actually cared to invest into choices. That requires learning and actually vetting your vendors though. That's hard work. Good luck getting people to do hard work.
I'd be curious to know what kind of problems could be only solved through a cloud-only solution. It's a honest question; I'm not old enough to remember actually using mainframes but in my days companies had their own IT staff, gear and storage. I understand that hiring a IT team of 3 could not be viable for a small 10 people startup, but I'm sure there are solutions in between before being forced to entirely surrender everything to someone else's data center.
Building an in house solution to do this is extremely costly in every way imaginable, from the extreme expertise needed, to the ability to do it at a very large scale.
There are a number of vendors out there who provide great software to do things like scan source code, scan dependencies, or scan a live environment for vulnerabilities. The best of those vendors have cloud-only solutions.
You're stuck either accepting the risk that, at the very least, vulnerabilities about your software would be potentially exposed for the world to see, or installing an inferior product on-premise. That potential risk is even greater if your customers depend on you to store things like private and/or financial data.
So, color me unimpressed.
That said, good luck implementing and managing that in a large organization.
https://stackoverflow.com/questions/77186232/how-to-use-gith...
I remember when the Network Computer was going to put Microsoft out of business. It was Sun providing the NC and JavaOS, Netscape providing the Web Browser and anyone who wanted to license the NC to make their own. Internet was too slow then as everything was stored on the Internet, which because the Cloud model. Microsoft bundled IE with Windows to destroy Netscape and made Dotnet destroy Java.
This is embarrassing for Microsoft. All their cloud services have been hacked. Data has been leaked. Could lead to lawsuits.
And now the search feature doesn’t work anymore.
If it wasn’t for the game support being important for work I’d happily leave and avoid every aspect of their ecosystem. What other reasons do people have for sticking with Microsoft apart from software compatibility?
Regarding mandatory updates, try Reboot Blocker.
https://blog.cloudflare.com/cloudflare-now-powering-microsof...
https://rakkhi.substack.com/p/microsoft-hack-zero-trust-arch...
That they've chosen to integrate it with all their legacy stack (which is one of the most complicated ones in existence) is understandable and what 99% of companies would have done but... it's a horrible experience using it. Maybe people with only Microsoft experience don't feel the pain anymore.
That's exactly the problem - what ARE companies going to do? Migrate OFF windoze? Migrate out of Azure? To Linux?
Certainly not, Microsoft-y admin only know Microsoft, they usually can't do much else, it's all they know. They certainly won't bite the hand the feeds them. That means the organizations are stuck, which is exactly what Microsoft wanted all those years ago with a monopoly, and got it.
Customers too stuck in their own ways to do anything but be a slave to Microsoft and their constant insecurity deserve what they get sadly.
Catastrophically-bad-by-design authentication is a Microsoft staple.
The short answer is...yes.
Of course it isn't easy. Of course it would take time. But it's certainly not impossible. It's certainly been done.
I'm not defending MS but the idea that they're some sort of siren and companies can't help themeselves...well, please get me a list of those companies so we short the shocks if they're that incompetent.
When the US govt got hacked they actually did something about it government-wide. Started new security standards. For themselves and their vendors like M$
A quick scan of a summary of the SolarWinds story suggests that's not the case, but it's possible that the article I read glossed over too much.
No, but the other way around happened. It may be even this hack on the article, it's not very clear.
The Solar Winds thing is probably much larger than what we have been allowed to know. I do expect more of it to come out, for decades because the victims just have no way to know they have a problem.
Migrating will be relatively cheap. No wonder they’re hobbling the tools (/tinfoil), they see the threat.
Earlier this year we had a linux task that was above the normal complexity my team deals with. So a few people threw it at chatgpt and were amazed at how good the results were. In reality, it was full of outright factual inaccuracies and non-breaking bad decisions. But their skill ceiling prevented them from seeing how bad the output was.
I didn't want to be a wet blanket, so I let them have their fun and quietly guided the jr working on the resolution through an appropriate implementation.
I doubt they'll be much help doing anything that is better than whatever standard practice was 6-12 months ago.
If anything, I'd expect them to cement in incumbents and bad practices, since fewer people will be reading documentation and thinking critically about how to do better.
This is incredibly insensitive and dismissive, and victim-blaming.
But if that someone hunts down the mugger, dances a jig in front of him, starts mocking, "oh come on, I have a thousand bucks cash on me, point the gun at me already"... well, telling them that they're doing it to themselves isn't victim blaming. It's objective truth, the only truth that matters.
They're doing it right now. As we speak. We're having this conversation watching them while they try to throw themselves in front of the gun. It's time to stop worrying about whether or not we're insensitive when we describe what's happening in front of our eyes.
We clearly reached it at the 90's. We have been waiting for the other shoe to drop since then.
This is also not the first time they cover up some serious problem and refuse to fix it. In fact, that's a daily activity for them. This one is just a larger problem than usual because they are broken too, not only their clients (even though, that makes it only slightly larger).
Several million dollars gone from one virus. But they forged ahead, entreating further with Microsoft.
Victims absolutely shouldn’t be blamed, however, you don’t buy a Pinto if you are concerned about being trapped in a fiery wreck, you don’t go to Skid Row after dark if you’re concerned about violent crime, and you don’t buy Microsoft if you’re concerned about security. These are all things we’ve known for decades.
The ironic part is that Bitcoin and Ethereum, altcoins like Filecoin and the entire space of decentralized protocols (EVM, the coming-soon FVM, etc) was designed to eliminate centralized middlemen, including banking cartels, Amazon (which is being sued for monopolistic practices) and the soon-to-come CBDCs etc. In fact, all the responsible protocols (IPFS, UniSwap on Ethereum, Aave marketplace etc etc.) kept humming along regardless of bull and bear markets. It’s just distributed code!
But middlemen were able to convince the public that their centralized companies “ARE web3” and then overpromised yields and other crap.And now the public conflates that with all decentralized protocols that carry value — that’s why we can’t have nice things.
And a bunch of fly-by-night teams cloned contracts delivering no utility at all and some even put backdoors in them. Like PHP “give me the spaghetti codes” crowd and Javascript script kiddies and HTML personal sites with <blink> tags script kiddies… but with some money invested.
Cryptographers were right to protest the word “crypto” being associated with this.
If cryptocurrency-based financial instruments were regulated and protected to the same degree as traditional companies - but with the relevent technical competence to match! - I'm sure 'pay with ETH' and the like would be as common as PayPal and VISA.
Hard to take your comments seriously with such obvious disdain against the company and ridiculous victim blaming.
I guarantee 99/100 humans on this forum either currently host with AWS/GCP/Azure or have worked at a shop that does. And I bet an outsized portion of those AWS/GCP shops also host on Azure for Azure AD.
There is no one that is ready for a de-Microsofted world. Even Linux distros have been increasing their support for integrating into the MS ecosystem and forsaking alternatives because how prevalent AD is. Even the most prominent alternative FreeIPA is designed to compliment an AD installation, not replace it. The best supported directory/central login server on Linux is AD.
They have contributed to the Linux Kernel, they own GitHub and NPM, they make an extremely popular editor, among other things.
It’s a different set of risks than depending on them directly, but they’re still there.
Personally i'm using lldap, which is a neat no-footgun ldap daemon for small/personal deployments.
Ok. So are you suggesting that the most practicable alternative is to be a slave to [list of 100+ other vendors]? Going out of your way to defenestrate a trillion dollar technology vendor is a bit bananas to me. If you are trying to run a business, I think you are completely fucking yourself over with this sort of attitude.
How much business convenience are you willing to squander over these principles? And, are you truly upholding your principles on a consistent basis or is this a reductive "at least it's not Microsoft" line of thinking? Microsoft is a big place. Some parts good some parts bad. You may be leaving a lot of upside on the table by never considering them as an option.
We are a "Microsoft shop", but we still use other vendors when it makes sense. I don't trip over myself trying to get 100% off AWS over some ridiculous tribalism. Their domain registration and S3 object stores work really well for us so we continue to use them, even when it creates a bit of integration overhead (SCIM identity sync w/ AAD, etc).
All of your arguments are "made up" arguments, they contradict themselves or each other or assume some very unlikely situations, especially on behalf of what the post you replied to wanted to say, where it's clear it's not what it wanted to say.
Let's dive in!
> So are you suggesting that the most practicable alternative is to be a slave
Clearly, the post you replied to doesn't suggest that. (But you went on arguing as if it did).
> a trillion dollar technology vendor is a bit bananas to me.
Nobody's killing Microsoft. But even if they were, maybe that's the right thing? You make no arguments not to.
> If you are trying to run a business, I think you are completely fucking yourself over with this sort of attitude.
The company I work for runs on Linux. The company I worked for before this runs on Linux. The company I worked for before the last one also runs on Linux. And the one before those two -- yes, you guessed it, also runs on Linux. The operating system chosen to run a business was never a serious factor in terms of whether the company succeeded or failed. By and large, it's not important.
Are there specific technologies / products only available on Windows? -- You bet! What should be done about those? -- find a way asap to not make them exclusive to that platform. One of the most tragic situations in this respect is in medicine. Windows is ubiquitous in this field. To the point that I'd say that governments should step in and invest into the healthcare they control to change the situation. I.e. to do the complete opposite of what you are suggesting.
> Microsoft is a big place.
All under the same roof, with the same objectives and strategy, which are to screw you (the "Microsoft shop") in particular, but also, if possible even those who managed to stay away from them. The problems Microsoft creates for the world aren't somehow local to one or two departments of the company. The company, no matter how big is responsible for its policies.
While I don’t think that statement is universally true because for certain products OS matters, but generally, why would anybody migrate away from windows just because of a security incident? Linux has had its fair share of RCEs and 0-day exploits. Are you saying Linux is intrinsically better?
Can we say that the market has spoken?
https://en.wikipedia.org/wiki/Usage_share_of_operating_syste...
I look forward to the day that windows is mostly a UI over WSL and things like the regsitry become a distant memory.
Microsoft aggressively abused its monopoly position in order to make sure that Linux would never win in the desktop market, and then inertia took over, so no we can't say that the market has said anything useful
The idea of a market works if it costs ~0 to enter a market, consumers have an infinite access to knowledge and infinite time to make a decision BUT make it in 1s when at the store, and also enough money so as to not be a problem. Basically, consumers have all the power and vendors have none.
Nothing is really a market, and operating systems definitely shows it.
Huh, why not?
You don't see them in stores because there is not enough demand for them, and because stores are dying anyway. Very easy to find them online to buy.
Dial up was widespread well into the early 2000's, and even then ADSL started to spread slowly.
> You don't see them in stores because there is not enough demand for them
There is no demand because, again, the market is a lie. One OS is forced to consumers, on the computers they buy in the stores, they use at school, they use at work. That's exactly what I'm saying.
> Very easy to find them online to buy.
Computer literacy of the population is not comparable to the one of people on HN, so no, I wouldn't say it is as easy as buying a linux computer online than buying any computer offline.
> Dial up was widespread well into the early 2000's, and even then ADSL started to spread slowly.
Cable became common in the early 2000s, and even if you couldn't get it at home you could go somewhere that had decent speed, certainly to download a 600mb ISO.
Not bothering to address the rest of your contrarian points.
I keep trying to communicate this whenever people are attempting to manifest an Invisible Hand to control bad behavior. More people need to be aware of this.
I like your succinct point. I wish there was something so short and understandable for an even fuller picture. Like including that for a marked to price things in a way that works for societies, consumers need to choose long term over short term gains and that the price needs to not make economic externalities of human rights or destroying the climate.
It still enables users to open random mail attachments in Office or similar. And Office doesn't have any sandboxing or other mitigation in place, again it's insecure by default. If you enable users to do stuff like this, you have noone to blame if you get owned.
Are the usual Linux distro's better? Hell no! They have the same flawed security architecture as Windows, only without any motivated attackers (yet).
But there are actually secure alternatives: QubesOS and ChromeOS.
QubesOS is probably not that suitable to end-users, they can do too much wrong to twart it's security (using the "financial" qube to browse p0rn... etc.).
ChromeOS is a reasonably secure OS: It's root filesystem is read-only with tamper-proof authentication, user's home directory is encrypted. Chrome runs with the usual privilege separation in multiple processes each in it's own tight sandbox. There is no way to autostart anything.
Even in the nuclear case of a 0-day RCE + chained sandbox breakout + privilege escalation to root, the threat can not persist itself... you just reboot the device and are save again.
And Google has lot's of experience in security, they one of the few who build their own browser, the most hostile environment. They are clearly thinking about security front and center and not as an afterthought (like Microsoft).
Similarly, I'm not against Microsoft products being used in hospitals. I'm for transparency of standards, rules used by hospitals to acquire and maintain software, public interfaces, reporting...
If such rules are created and Microsoft is playing by the rules -- then I have no problem with it, but having Microsoft decide what the rules are is a disaster.
Edit:
Adding a quote from the OP’s linked blog on the subject:
> There is this well cited argument that cloud companies like Google, Apple, Amazon, Facebook, and you-name-it are able to protect your personal data much better than you are able to. They have military grade security restrictions, better backup methods, and are able to do this much cheaper.
> While this argument being absolutely true, people seem to forget that giving away your data to any third party is the root of many problems in the first place. It is not relevant to whom you are giving your data to.
>Let me explain…
So OP is arguing that this is why you can’t trust anybody not just MS. That’s a stance too, and perhaps for an incredibly security sensitive product the correct one, but definitely an impractical one for probably 98% of software products.
I haven't seen such a clear statement of this idea in a very long time[1].
The "principles" you are trading for convenience include control of your network.
[1] Last time was a talk by Bruce Schneier, a long time back. He famously declared if you give people a choice between security and dancing pigs, they'll take the pigs every time.
What do principles have to do with ANY of this? Microsoft promised a level of security and didn't deliver, and is now covering up, BADLY.
The only logical solution is to start looking elsewhere, even if you can't switch right now.
YOUR cope appears absolutely delusional.
What you're arguing is essentially the Too Big to Fail proposition. The solution of which is to Not Let Things Get That Way.
Maybe, but you're also avoiding a whole lot of downside. I don't think it's unreasonable to avoid Microsoft products, either as a business or as a person.
Whether or not it makes business sense to depends on your business, of course, but there are plenty of successful businesses who avoid Microsoft.
This is mixed with an ever increasing legislative push and higher fines for leaking PII.
e.g.: https://www.cnbc.com/2022/10/11/companies-are-finding-it-har...
All architectures based on certificate authorities are fundamentally fragile in the same way. People look at me like my head is spinning when I suggest just adding ephemeral self-signed CA root certs to deployment pipelines (or, god forbid, use SSH keys, or even symmetric keys).
However, those approaches have a much, much smaller attack surface than HTTPS or standard X.509 SSH authentication, so I'll keep recommending it.
I think the reason for the pushback is that, in this space, attack surface is roughly proportional to monetization potential.
But one reason I might initially look at you with alarm if you suggest self-signing or symmetric keys as part of a solution in general is… while it might reduce the attack surface, attack surface is not the only thing to worry about. Another thing to consider is the ‘fuckup surface’ of a particular architecture.
And one problem that self managed key distribution strategies tend to run into is that they massively increase your fuckup surface. Losing the keys to everything can become a real danger.
I’m a big believer in building security systems that also reduce the blast radius of dumb errors (accidentally running rm -rf /* is harmless if you religiously run with least privilege).
Saying ‘I’m going to build my own trust root’ generally seems to me like it probably increases the blast radius.
Test it out, if curious - Pretty straight-forward. And a heck of a lot more economical.
If an admin is able to navigate in all that shit, I don't know why they would not understand e.g. random unix tools.
I am a linux sysadmin. Honest question: Would I have an edge on a Microsoft-y admin or are linux sysadmin skillset limited to Linux ? I can find my way around a lot of network appliances (sophos, cisco, junyper, etc.) and I'd expect a windows system to be as capable.
https://www.qubes-os.org/ https://www.qubes-os.org/doc/system-requirements/