There’s been a string of security blunders in Azure in the last couple years but leaking a signing key and then trying to downplay it is really beyond the pale

You are viewing a single thread.
View all comments
33 points

Not surprising, MS probably have one of the largest attack surfaces of any entity

permalink
report
reply
13 points

It the job of responsible company (especially one Microsoft’s size) to know that and plan for it accordingly.

Risk management is hard baked into the infosec responsibility set, size isn’t an excuse

permalink
report
parent
reply
4 points

Did you say, “Size doesn’t matter”?

(FYI - in hear this excuse all the time at a large company. Somehow our complexity and scale is always an excuse people reach toward. And, as you say, our job from infosec is to shut that whining down.

permalink
report
parent
reply
0 points

It can be if you don’t have the staff. If humans are the most vulnerable part of the system, you can’t stretch them too thin and expect them to be as effective in their role.

permalink
report
parent
reply
2 points

That’s part of another issue which should’ve been handled prior to getting too big.

Manageability is #1 when considering your growth, can’t imagine Microsoft chose to keep a “small staff” out of necessity.

Perhaps fucking private Sting concerts for higher ups should be scrapped in favor of the employees they fired days prior to attending

permalink
report
parent
reply
11 points

I don’t know what the US government runs on its most secure systems but with all the money we pay in taxes, I hope it’s not Windows, Linux, or macOS. I hope they scooped up some 80’s operating system no one would ever suspect and kept it going in parallel. Good luck hacking into a system with a fully custom version of Business Operating System that runs on 64 bit Motorola processors no one knows about but the CIA’s sysadmins.

I know in reality they probably run Windows Vista on 12 year-old laptops or some shit and get hacked all the fucking time but I’d like to think someone had enough sense to not do that.

permalink
report
parent
reply
15 points

The OS they choose is really not the most important part of its most secure systems.

permalink
report
parent
reply
6 points

Ok, fine. Then I hope they use paper and guns to protect secrets.

permalink
report
parent
reply
-2 points

Nah, its a bunch of panasonic toughbook 30s. Except the Airforce, we get M1 Macbooks

permalink
report
parent
reply
2 points

Yeah, but the NFL kept calling them attack ipads.

permalink
report
parent
reply
1 point

Guy is talking about cloud. Azure is not the first cloud provider, it’s simply tha laziest

permalink
report
parent
reply
2 points
Deleted by creator
permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 12K

    Posts

  • 538K

    Comments