5 ms·
A breach like that requires a very good understanding of Microsoft's internal infrastructure. It's safe to assume that the breach was a coordinated effort of a
by dgudkov 3y ago
A breach like that requires a very good understanding of Microsoft's internal infrastructure. It's safe to assume that the breach was a coordinated effort of a team of hackers. This is not a cheap effort, but the payback is enormous. Hyper-centralization leads to a situation when hackers concentrate their efforts on a few high-value targets because once they are successful, the catch is enormous. I'm pretty much sure that there are teams of (state-sponsored) hackers that are already doing deep research and analysis of the internal infrastructure of Google, Microsoft, Amazon, etc. The breach gives an idea of how well already the hackers understand it.
I would argue, it's time to decentralize inside a wider security perimeter.
- splitstud 3y ago[dead]
- deleted 3y ago[deleted]
- sargun 3y agoYou have to assume that you have nation state actors working at your organization at sufficient size. Unfortunately, it’s difficult to work around this assumption, because anyone can be compromised at any time.
- transcriptase 3y agoI find it somewhat amusing that companies like Microsoft and Google that have pivoted a large portion of their business model to collecting, keylogging, recording, scanning, exfiltrating, telemetrizing, collating, inferring, and analyzing every last iota of data they can about as many people as possible under the guise of improving their products or personalizing ads... ... can't identify nation state actors within their own company. I suppose that would be illegal. Whereas using it to improve AdSense CTR or selling it to brokers is perfectly acceptable.
- bostik 3y agoIf you are up against an adversary with an unlimited budget and organisational event horizon measured in years, your quarter-to-quarter thinking will always kneecap you.
- petesergeant 3y agoI dunno, I reckon the amount Microsoft pay in defensive security and the amount China pay for offensive cyber security are going to be in the same order of magnitude. The real advantage is that MS has to play at least somewhat inside the legal system.
- bostik 3y agoI have to disagree, because it's more subtle than just (im)balance of budgets. It's about the highly asymmetric nature of the ongoing conflict. A nation state has effectively unlimited budget in money, but more than that, their incentives are different. Any defender has to maintain an increasingly complex system with an evolving attack surface. A nation state attacker has to maintain ongoing access to any parts of that system. Access grants opportunities. They can wait, and can afford to do so. They have a massive time budget to tap. A company who does not prioritise or budget ongoing maintenance will eventually reassign their expensive resources to projects that do produce visible or at least measurable results. And in doing so, they neglect the unmeasureable outcomes from the prior projects that are now starved of proper resources. (Or even just attention.) Compromises will happen. That's the ground truth. The important part is the blast radius. In this particular case the impact was magnified by string of failures. Missing or ineffective revocation of a signing certificate was a big factor, but the failure was further compounded by the applicable scope of what that certificate could sign things for. Those two process failures caused this incident - everything else is attributable to bugs. In short, MS dropped the ball on an organisational level.
- petesergeant 3y ago> A nation state has effectively unlimited budget in money Why do you think this is true?
- mhh__ 3y agoAt or in? I would assume both