10 ms·
Microsoft lost its keys, and the government got hacked
- neilv 3y agoDid anyone start getting Microsoft "single use code" emails last night? (Maybe if you have an Microsoft consumer account that you don't use, forgot you had, and might be incompletely set up.)
- nubinetwork 3y agohttps://news.ycombinator.com/item?id=36690598 https://news.ycombinator.com/item?id=36690598 https://news.ycombinator.com/item?id=36692494 https://news.ycombinator.com/item?id=36692494 https://news.ycombinator.com/item?id=36693121 https://news.ycombinator.com/item?id=36693121 https://news.ycombinator.com/item?id=36693469 https://news.ycombinator.com/item?id=36693469 https://news.ycombinator.com/item?id=36694188 https://news.ycombinator.com/item?id=36694188 https://news.ycombinator.com/item?id=36696413 https://news.ycombinator.com/item?id=36696413 https://news.ycombinator.com/item?id=36696852 https://news.ycombinator.com/item?id=36696852 https://news.ycombinator.com/item?id=36697272 https://news.ycombinator.com/item?id=36697272 https://news.ycombinator.com/item?id=36699844 https://news.ycombinator.com/item?id=36699844 https://news.ycombinator.com/item?id=36704776 https://news.ycombinator.com/item?id=36704776 https://news.ycombinator.com/item?id=36705671 https://news.ycombinator.com/item?id=36705671 https://news.ycombinator.com/item?id=36708294 https://news.ycombinator.com/item?id=36708294 https://news.ycombinator.com/item?id=36713560 https://news.ycombinator.com/item?id=36713560 https://news.ycombinator.com/item?id=36716028 https://news.ycombinator.com/item?id=36716028 https://news.ycombinator.com/item?id=36719412 https://news.ycombinator.com/item?id=36719412 https://news.ycombinator.com/item?id=36722538 https://news.ycombinator.com/item?id=36722538 https://news.ycombinator.com/item?id=36731110 https://news.ycombinator.com/item?id=36731110 https://news.ycombinator.com/item?id=36731308 https://news.ycombinator.com/item?id=36731308 https://news.ycombinator.com/item?id=36731731 https://news.ycombinator.com/item?id=36731731 https://news.ycombinator.com/item?id=36736306 https://news.ycombinator.com/item?id=36736306 https://news.ycombinator.com/item?id=36740133 https://news.ycombinator.com/item?id=36740133 https://news.ycombinator.com/item?id=36757016 https://news.ycombinator.com/item?id=36757016 https://news.ycombinator.com/item?id=36757512 https://news.ycombinator.com/item?id=36757512 https://news.ycombinator.com/item?id=36759808 https://news.ycombinator.com/item?id=36759808 https://news.ycombinator.com/item?id=36759865 https://news.ycombinator.com/item?id=36759865
- michaelteter 3y agoPerhaps preceding your list of related links you could state that the following is a list of (recent?) related HN submissions.
- nubinetwork 3y agoI'll consider it.
- bozhark 3y agoIt’s implied imo
- abrookewood 3y agoYeah, the submission IDs are all very close.
- sysop073 3y agoYou thought perhaps they commented a list of random unrelated HN submissions?
- michaelteter 3y agoThe links are all just https://news.ycombinator.com/item?id=######## https://news.ycombinator.com/item?id=########. It's obvious they refer to some content on HN, but it could be comments, replies to comments, etc. By adding a small bit of human text, the human doesn't have to ponder the list and wonder what they will get if they click a link. And if there were human text, someone arriving by way of the parent comment link would have an easy time understanding the context without having to scan a lot of characters and make assumptions.
- djbusby 3y agoHow did you even get all those so fast?
- JamesonNetworks 3y agoSeems like they are assuming the same key was used to forge tokens and jump from that assumption to the conclusion that they found all instances of requests. If more keys were used to generate more tokens, isn’t it possible this attack had a much wider surface area?
- breadwinner 3y agoAs a rule of thumb, hacks are always worse than initially thought. See https://circles.page/5680a56b5c28af0998656e09/Hacks-worse-than-initially-thought https://circles.page/5680a56b5c28af0998656e09/Hacks-worse-th...
- jamesjuicy55 3y agoAbsolutely. Maybe Louisiana and Oregon DMV hacks?
- 2OEH8eoCRo0 3y ago> Microsoft still doesn’t know — or want to share — how China-backed hackers stole a key that allowed them to stealthily break into dozens of email inboxes, including those belonging to several federal government agencies.
- dralley 3y agoSpeculation: insider threat
- 2OEH8eoCRo0 3y agoThat would be my amateur guess as well which scares me in a couple of ways.
- victor106 3y agoOne of the reasons why we moved away from using Microsoft products for our identity management to Okta. Not that they are bad products per se, but as many organizations use Microsoft products they are prime targets for too many hackers and it’s hard going to bed thinking that your identity info might be hacked someday and/or not knowing if it will be. The surface area that Azure/Microsoft have is just too large for it to assume to be protected by one company whose security as not been the most stellar. So we are actively moving to GCP as well.
- likecarter 3y agoOkta has been hacked a couple times now...
- azemetre 3y agoWas about to say, wasn't all their source code stolen too? https://techcrunch.com/2022/12/22/okta-breach-source-code-github https://techcrunch.com/2022/12/22/okta-breach-source-code-gi... Okta looked very bad during the entire saga where they kept denying they were hacked until the proof was insurmountable. Pretty sure there was a large discussion on HN at the time too.
- EthanHeilman 3y agoTo toot my own companies horn[0] we designed our authentication protocol OpenPubkey[1] to have two signers on tokens: 1. The IDP signer (like microsoft or google) 2. The Cosigner (like bastionzero.com) ...so that even if microsoft's signing key is stolen, the attacker also needs to compromise the cosigner's signing key as well. It's like multisig for authentication tokens. I don't know if OpenPubkey would have helped in this particular case as the details are still coming out[2], but I think the future of authentication schemes must require that authentication tokens must be signed by multiple signers at different organizations; Authentication systems with single point of compromise signing keys is too fragile. Or put another way authentication via multiple independent roots of trust is just too powerful of a security tool not to use. [0]: BastionZero, https://bastionzero.com https://bastionzero.com [1]: OpenPubkey: Augmenting OpenID Connect with User held Signing Keys, https://eprint.iacr.org/2023/296 https://eprint.iacr.org/2023/296 [2]: It appears the key stolen was an MSA key, not an Azure AD signing key. The MSA architecture might not fit into the OpenPubkey model (or it might I don't know enough about MSA signing keys work to say). Had it been an Azure AD signing key then OpenPubkey would mitigate the theft of an Azure AD Signing key. https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/ https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...
- exabrial 3y agoAny Windows product/system is a liability. I'm not sure how to put this lightly. It was designed to create a monopoly first before any other goal. And it's not that the alternatives are perfect, but Windows is as secure as swiss cheese.
- 666satanhimself 3y ago[dead]
- Rygian 3y ago> as secure as swiss cheese In IT security jargon, the "Swiss cheese" model is a good practice: https://en.wikipedia.org/wiki/Swiss_cheese_model https://en.wikipedia.org/wiki/Swiss_cheese_model
- nyolfen 3y agothis is not windows
- lostmsu 3y ago> Any Windows product/system is a liability. A self-evident realization: every single product/system is a liability.
- TheRealDunkirk 3y agoI know this is a bit of a thread jack, but this same attitude now playing out on Xbox in the console space. The recent FTC attempt to block the Activision merger surfaced emails saying that they were just going to outspend Sony to further consolidate and buy a higher position in the market, because they can. There's nothing in any of Microsoft's revealed communications over the years where they ever seem to aspire to make better products. I mean, sure, obviously, there are pockets inside the company, but that has never seemed to be the purview of the board or the executives. If there's a thought leader in there somewhere who had passion to make great products like Jobs, I can't think of who it would be. I almost feel bad for Microsoft, and I say this as a Microsoft-hater and Linux zealot who ran it on the desktop for 19 years before switching to Mac. It's the legacy backward-compatibility that makes Windows so attractive to a lot of organizations which makes it so vulnerable. OTOH, corporate IT divisions love it because Microsoft lets them do all sorts of stupid things to it, like prevent me from changing the desktop background, so it's kind of a deserved punishment.
- 666satanhimself 3y ago[dead]
- zingababba 3y agoInteresting that it aligned with their AAD rebrand.
- jtbayly 3y agoThis headline does a good job of pointing out why we shouldn't allow backdoors in encryption.
- naikrovek 3y agono one said it was a backdoor, though. you have to have a key to encrypt stuff, and it was that key which got leaked, somehow. a backdoor is a way around the use of a key to see secret messages, or an alternate key which allows you to view messages without compromising the key which encrypts messages in normal operation. could have been a backdoor, sure, could have been something else. could have been carelessness. could have been blackmail. could have been a rogue employee. could have been malware, spear fishing, or any one of a hundred other things. did I miss something or are you premature in blaming this on a backdoor?
- mikrotikker 3y ago[flagged]
- deleted 3y ago[deleted]
- ketralnis 3y agoThey didn't say it was an intentional backdoor. But if it were, the result would be the same. It's hard to secure encryption keys. If you had a backdoor based on a key that you had to keep secret, leaks like these can happen. If Microsoft (or anyone) can't keep their encryption keys secure, they'd be equally unable to keep a backdoor key secure for the same reason.
- thephyber 3y agoBut an encryption back door is either a second key that someone else holds or it is some piece of information the public should not know about. Either way, when the details about the back door leak, the system ceases to retain the properties of secure encryption.
- thomastjeffery 3y ago
- Zelphyr 3y agoI hate to go negative. I really do because, usually it doesn't improve the discourse whatsoever. However, I feel like it needs to be said: Microsoft makes bad products[1]! They're overpriced, insecure, slow (it's astounding to me how slow their web properties are), and hard to use. Easily some of the worst UI I've ever seen and, what's worse, they've been like that my entire career. They keep slapping lipstick on the same pigs and claiming to have reinvented themselves. Their support is so ungodly bad that it literally took one of their reps over a day to figure out what timezone I'm in. Meanwhile, two of my employees' emails were being randomly CC'd to the CEO for no apparent reason. The cause? Nobody knows. It just stopped happening. Even Microsoft couldn't tell me why it happened. With a $2.5 trillion market cap, it may seem like they're killing it but, I really think they're riding on momentum just like IBM did. Twenty years ago, IBM's market cap was double what is is now and, in my experience, their products are every bit as bad (admittedly, I have almost no exposure to their big iron products). So, what are our alternatives? I know many people who don't like Apple for various reasons. Linux on the desktop has been promised for 20 years. It's closer than it has ever been to being a solid replacement but I don't know that it's quite there yet. It saddens me to say, I don't know what the answer is. I just know that we need to get away from Microsoft products and fast. 1: In my experience, the only two exceptions are VS Code and SQL Server.
- mschuster91 3y ago> With a $2.5 trillion market cap, it may seem like they're killing it but, I really think they're riding on momentum just like IBM did. Twenty years ago, IBM's market cap was double what is is now and, in my experience, their products are every bit as bad (admittedly, I have almost no exposure to their big iron products). People are only not shitting on IBM so much anymore because they sold off Lotus Notes...
- fatfingerd 3y agoI don't see Lotus Notes as all that different than other Offices products developed by big Tech. I think it would be similar to Google's business platform with some more legacy automation but not unlike SalesForce or ServiceNow. Having used Microsoft recently, after Google for work, I'm absolutely flabbergasted at how terrible Word, Teams, Outlook, etc are. I would describe the average Microsoft product as a zombie in its own feature set, at war with a different version of itself, and attempting to steal organs from other products to try to transition to every possible entirely different role in the suite. Attempting to use a Microsoft product is like watching developers capitulate to some kind of bizarre internal political war between Product managers.
- collsni 3y agoIsn't cloud fun? Same keys to everyone's kingdom!
- Incipient 3y agoWhat's with all this fairly overt state sponsored hacking and everyone going "aww shucks" and moving on quietly?
- mikrotikker 3y agoWar with China already started in the cyber space. In fact its probably the pre war intelligence gathering and backdoor installations
- dgoodell 3y agoI work for NASA. Our budget is like $25B. We’re definitely inefficient and wasteful, but we still do a lot of new things. Just not nearly as much as we could. Microsoft’s operating budget was like $123B last year. There are bugs in office products that have been there for years What exactly are they doing with all that money?
- diarrhea 3y ago[flagged]
- jdm2212 3y ago[flagged]
- notjoemama 3y agoAh, no, but point taken. I can't think of an example myself because I don't know how Nasa functions. Besides that, I think the valid critique (without the subtext) is, it's probably not a good comparison to measure a very large companies failings to a much smaller companies failings because their size is a definitively weighted factor in the outcome. The caveat that I would add, is Nasa is publicly funded and it's probably ok to ask the question in the public interest. For private companies like Microsoft, just stop buying their products.
- oskarw85 3y ago"Just stop buying their products" is silly answer when those products are epitome of corporate IT offerings. Especially where people doing "the buying" are completely different than people doing the support. On the contrary - criticism should be loud, clear and persistent. Being private company does not make you immune to criticism.
- sundarurfriend 3y agoFunding the current AI revolution, for example? https://techcrunch.com/2019/07/22/microsoft-invests-1-billion-in-openai-in-new-multiyear-partnership/ https://techcrunch.com/2019/07/22/microsoft-invests-1-billio... https://techcrunch.com/2023/01/23/microsoft-invests-billions-more-dollars-in-openai-extends-partnership/ https://techcrunch.com/2023/01/23/microsoft-invests-billions... https://www.reuters.com/technology/microsoft-talks-invest-10-bln-chatgpt-owner-semafor-2023-01-10/ https://www.reuters.com/technology/microsoft-talks-invest-10...
- deleted 3y ago[deleted]
- iJohnDoe 3y agoSpeculation. This type of key issuance is given to FBI and NSA and other partnerships Microsoft has. China hacked their way up to get the keys.
- yttribium 3y agoAmerican companies are generally forbidden by EEOC rules from having reasonable security precautions unless some product is associated with a government contract and can require full blown security clearances. As a result you can safely assume that any given department with a juicy portfolio is fully compromised by foreign intelligence.
- pjdemers 3y agoThis sounds like an inside job.
- amai 3y agoWhat do you expect? Microsoft is a gaming company. They don’t care about security.