5 ms·
Though this is bad for Microsoft, does it make the situation substantially worse from a security perspective? Assuming they’re following good practices like not
by thatsamonad 6y ago
Though this is bad for Microsoft, does it make the situation substantially worse from a security perspective? Assuming they’re following good practices like not storing access keys, passwords, etc, in their source control system(s), this seems like more of an IP protection issue.
I could be wrong about that, though, and I’d be curious to learn and understand more.
- j_walter 6y agoExploits are much easier to find if you have pure source code and not having to reverse engineer it.
- acct776 6y agoAssuming your source isn't a fucking mess, is commented, APIs documented, etc
- rhexs 6y agoNo, it’s still much easier.
- onionisafruit 6y agoRight. One place I worked would probably benefit from attackers getting access to the source code. It would cost them weeks of productivity trying to figure it out.
- tpmx 6y agoThe core Windows source code is surprisingly readable/well written, I've heard.
- sn_master 6y agoWe are morons! http://atdt.freeshell.org/k5/story_2004_2_15_71552_7795.html http://atdt.freeshell.org/k5/story_2004_2_15_71552_7795.html
- tpmx 6y ago> Despite the above, the quality of the code is generally excellent. Modules are small, and procedures generally fit on a single screen. The commenting is very detailed about intentions, but doesn't fall into "add one to i" redundancy.
- sn_master 6y agoyup, similar sentiments are always given whenever MS code leaks, whether the MS DOS 6 that MS officially released, or the more recent Windows XP leak. Nobody who looked into it claimed any of the code was "messy" or anything but excellent engineering.
- deleted 6y ago[deleted]
- unionpivo 6y agoEvery state actor already has MS source code, because Microsoft is giving them access (including china). And this doesn't look like something bored 15 year old would pull, So I doubt it was to access their source. If I had to guess, they were either trying to find something specific, about one of MS's customers (some gov org) or the target was Azure. Lots of corps keep a lot of data there.
- arkadiyt 6y agoIt just lowers the cost of exploit development, that's all.
- frombody 6y agoThere was at least one SAML bug found in Office 365 federation some years back that would allow anyone to log into anyone else's account.
- munchbunny 6y agoIf SolarWinds was compromised and the attackers could use that as a backdoor into Microsoft's datacenter, the problem isn't really about protecting source code. The problem is whether attackers were able to leverage that into stealing data from or sabotaging Microsoft customers. After all, that customer list contains many parts of the US government and civilian infrastructure in general, plus major international corporations.
- TechieKid 6y agoThe update literally says that "found no evidence of access to production services or customer data."
- munchbunny 6y agoI think you're misunderstanding my point. The "risk" mentioned in the quote a few comments up, and in the context of the post by MSRC, isn't about the risk of leaking Microsoft IP. It's about the risk that Microsoft customers might have been affected. Whether or not MSRC found evidence of a breach of customer accounts/data is a related but separate question.
- zinekeller 6y agoPlease note: the source code of Windows 10 can be requested if you are a large enterprise or a government already (as long as you agree that you won't release it). The only possible significant difference here is the lag - you can read the source code of the internal builds, whereas you can only access the corresponding source code for stable builds officially. So, if you are a government, you can actually request it for a legitimate purpose and pass it into the other side of that government if you really want to.
- somethingwitty1 6y agoThere are two aspects to the comment though: 1. Did they access services/data as part of this? 2. Can/did they use what they got to impact customers/gain access to customer data. The comment in the article speaks to #1. And of course, we have to take that with a grain of salt. I doubt any company impacted by this would be fully honest if there was a customer breach. Regardless, you also can't prove a negative. So all they can really say is what they did. Which doesn't mean services/data weren't compromised. Given the size of Microsoft, I find it hard to believe that every service running there has the logs/audit trail to know whether they were inappropriately accessed. But I took the OPs comment to be focused on #2 as well. There is a very real possibility that having access to the source code could help the attackers attack customers. Having access to the source code can help in locating vulnerabilities that allow future attacks against customers/services.