4 ms·
It sounds like the credentials were embedded in code, so the fix probably involved all the steps of any production code change and deployment. I'm not defendin
by bsuvc 2y ago
It sounds like the credentials were embedded in code, so the fix probably involved all the steps of any production code change and deployment.
I'm not defending it, because it is abysmal, just explaining probably why it took so long.
- k8svet 2y agoI want to be snarky, but even MS isn't that slow at deploying these days. Unless things have seriously regressed.
- bastawhiz 2y agoFaced with leaking internal data or having a broken system, you pretty much always choose the latter. You simply don't leave your front door open. Roll the secrets, break the system, and then fix the mess. The system was already broken from the moment credentials were leaked (or if you're a purist, from the moment they were hard coded into a file). The impact just wasn't realized or felt yet.
- bsuvc 2y agoAgreed, 100% I'm definitely not defending it, just saying the red tape in some orgs can be nearly impossible to defeat. This problem should have escalated as high as needed though to bypass the red tape and fix the security issue immediately. Probably a failure of weak middle management not having the guts to communicate the problem up.
- sunnybeetroot 2y agoSoftware isn’t black and white. You weigh the impact of both options.
- bastawhiz 2y agoIf there's a risk of exposing business secrets or user data, no, it's 100% black and white. It's weighing some downtime and/or annoyance against _unbounded risk_. It's unethical at best to choose uptime over revealing user data or the remote access to internal systems which you don't understand the complexity of.
- sunnybeetroot 2y agoI struggle to see when a business responsible for life support services in an industry like medical would choose to end lives over delaying the addressing of a data breach but maybe I’m not seeing the bigger picture?
- bastawhiz 2y ago1. Microsoft isn't in the business of life support systems. Turning off a system with exposed credentials isn't going to shut off all of Azure. Even if it did, are you really claiming that Azure downtime is life-and-death? 2. In what hypothetical universe does a life support system connected to the internet contain a trove of customer PII? And where disconnecting this hypothetical system from the internet _cause the patient it's supporting to die_?
- sunnybeetroot 2y agoI thought the discussion was extending beyond Microsoft and applying to any software. But if you are asking if it’s possible for Microsoft Azure to be the hosting provider for very important systems ie government, medical, then yes, these could impact a high degree of quality of life for people, even now or in the future.
- bastawhiz 2y ago> if it’s possible for Microsoft Azure to be the hosting provider for very important systems ie government, medical, then yes, these could impact a high degree of quality of life for people, even now or in the future. If you design a system that could cause significant personal harm or a meaningful degradation of quality of life for someone due to cloud provider downtime, you're just a bad engineer. There's no such thing as a data center that's failure-proof. If someone's well-being depends on a system, it's simply negligent to be intolerant of failure conditions.
- sunnybeetroot 2y ago