6 ms·
"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their intero
by yborg 3y ago
"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz."
I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
- jug 3y agoI love how they emphasize only few were exposed. Like just a few, only our senior staff and cybersecurity team... I mean -- they aren't lying, but... Wow
- voidwtf 3y ago"very small percentage" 1% of 238,000 employees is a "very small percentage" and still 2,380 employees. Insight into certain operational information and potentially undisclosed/unpatched zero days could be monumentally valuable to a nation state actor.
- Fire-Dragon-DoL 3y agoIsn't the rule "if you are being targeted directly, lose all hope"?
- nycdatasci 3y agoThe Friday evening blog post also seems designed to brush this under the rug. "We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes" In other words: Microsoft will adopt their own security standards. Curious whether their SOC reports mention these are optional?
- thrwwycbr 3y agoAnd somehow it's always cross tenant issues for easy lateral movement, because Azure ASNs are always allowlisted specifically to bypass all kinds of filters. Microsoft is pretty learning resistant lately. Always prioritize the spamming customers, I guess?
- bamboozled 3y agoNot to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events. Azure was owned pretty hard a while back, very little was ever heard of it again. Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?
- bobmaxup 3y agoHow do you know if nothing happens? It isn't like the people siphoning, selling, or purchasing this data are broadcasting their wins on news aggregators.
- tempodox 3y agoIt makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.
- bamboozled 3y agoThe company will be making record profits next year. There maybe consequences but nothing consequential in the grand scheme of things.
- malermeister 3y agoTurns out there's more possible consequences than company profits being impacted. Users are more than just things you milk for cash, they're people that trusted you and your product.
- PoignardAzur 3y agoI find this reply incredibly cynical. GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy? This is vice-signaling.
- shultays 3y agoI like this bit ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. Yeah, at least they make a very small percentage of all Microsoft employees I guess
- fauigerzigerk 3y agoAlso this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.
- fremenite 3y agoThey mean root access on the production email servers, not access to individual email accounts.
- fauigerzigerk 3y ago"any access to customer environments, production systems, source code, or AI systems" does not mean root access. It can also mean access to data.
- lazyasciiart 3y agoNo, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.
- fauigerzigerk 3y agoThat may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.
- snickerbockers 3y agoIs there any basis for this group being "nation-state" or are they just trying to make themselves seem less incompetent by inflating the attackers' reputation?
- hulitu 3y agoWell, Microsoft always took security very seriously. Oh, wait... /s