GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kris (isotopp@infosec.exchange)'s status on Sunday, 01-Dec-2024 23:33:10 JST Kris Kris
    Microsoft can't cloud

    Microsoft, the company that lost the cryptographic keys that protected their cloud customers from attackers, now lost important log files.

    https://archive.is/UZGyh

    People go to the cloud, despite the fact that cloud is more expenive than on-premises by a factor of 5, because cloud promises to get operations right so that companies can outsource that and focus on dev.

    Microsoft is NOT an operations company at all.

    It can't cloud.

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://all.It/
    • Embed this notice
      Kris (isotopp@infosec.exchange)'s status on Sunday, 01-Dec-2024 23:33:09 JST Kris Kris
      in reply to

      https://follow.agwa.name/notice/AoZSMI38xcA3TrN1sm

      Microsoft doesn't know how to do operations.

      In conversation about 6 months ago permalink

      Attachments


    • Embed this notice
      Kris (isotopp@infosec.exchange)'s status on Sunday, 01-Dec-2024 23:33:10 JST Kris Kris
      in reply to

      https://cyberplace.social/@GossiTheDog/113534774251010222

      Microsoft can't cloud because it doesn't know how to do operations

      In conversation about 6 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cyberplace.social
        Kevin Beaumont (@GossiTheDog@cyberplace.social)
        from Kevin Beaumont
        Attached: 1 image 5 days into the launch of Microsoft Flight Simulator 2024, there's one critic review of the game - which is unscored and says there's nothing to review as the game is unusable. To give a flashback to Microsoft Flight Simulator 2020, it was one of the highest scoring releases of that year.
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Kris (isotopp@infosec.exchange)'s status on Monday, 06-Jan-2025 23:07:22 JST Kris Kris
      in reply to

      Microsoft can't cloud anymore, because one of their providers, edg.io, is bankrupt (and instead of doing the clouding themselves, which they could have been doing, they did not, and now suddenly have to move a lot of things around).

      Original posting

      • https://cyberplace.social/@GossiTheDog/113777410120359523

      leading to

      • https://devblogs.microsoft.com/dotnet/critical-dotnet-install-links-are-changing/dotnet installers need to use different URLs – maybe your own installers need change, too. Microsoft had been hosting stuff on azureedge.net, which was running via edg.io. The domains will cease to exist.

      Microsoft assures us that "No other party will ever have access to use these domains", so maybe they will not immediately become malware distribution endpoints.

      • https://learn.microsoft.com/en-gb/azure/frontdoor/migrate-cdn-to-front-door
        If you had been using Azure CDN, you have work to do.

      • Digicert dropped IPv6.

      A lot of other people may also be affected.

      In conversation about 5 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: images.ctfassets.net
        Deliver Your Business on the Leading Edge with Edgio
        The world's most innovative companies develop and deliver online experiences faster, safer, and with more control with Edgio's platform.

    • Embed this notice
      Kris (isotopp@infosec.exchange)'s status on Monday, 06-Jan-2025 23:07:23 JST Kris Kris
      in reply to

      https://www.heise.de/news/Microsoft-Azure-MFA-Schutz-war-aushebelbar-10198961.html

      Microsoft can't cloud because it doesn't know how to do operations

      In conversation about 5 months ago permalink

      Attachments


    • Embed this notice
      Kris (isotopp@infosec.exchange)'s status on Monday, 06-Jan-2025 23:07:23 JST Kris Kris
      in reply to

      Microsoft can't cloud because, well Microsoft can't.

      https://www.bloomberg.com/news/articles/2024-12-12/amazon-paused-rollout-of-microsoft-office-for-a-year-after-hacks

      https://archive.ph/6vq4f
      Freed version

      But Amazon paused the rollout after Microsoft discovered a Russia-linked hacker group had gained access to some of its employees’ email accounts. After conducting its own analysis of the software, Amazon asked for changes to guard against unauthorized access and create a more detailed accounting of user activity in the apps, some of which Microsoft also markets as Office 365.

      In conversation about 5 months ago permalink
    • Embed this notice
      Kris (isotopp@infosec.exchange)'s status on Monday, 06-Jan-2025 23:07:23 JST Kris Kris
      in reply to

      Microsoft can't cloud...

      https://www.derstandard.at/story/3000000250797/der-grund-fuer-die-ausfaelle-von-chatgpt-heisst-microsoft

      Was ist aus "Stromversorgung der Rechenzentren mit AI optimieren" geworden?

      In conversation about 5 months ago permalink
    • Embed this notice
      Kris (isotopp@infosec.exchange)'s status on Monday, 06-Jan-2025 23:07:23 JST Kris Kris
      in reply to

      Microsoft not only can't cloud, they actually can't. Like not anything at all.

      https://media.ccc.de/v/38c3-from-simulation-to-tenant-takeover

      From Simulation to Tenant Takeover

      Then I tried building a phishing simulation program myself and the last thing I needed was to allowlist my IP address in Exchange Online.

      I ended up in a rabbit hole where I discovered that Microsoft outsourced their support department to a Chinese company that wanted all my access tokens.

      I then tried intercepting client-side requests made by the Security & Compliance center with the goal of replaying these to a backend API, only to discover that by fiddling with some parameters I could now hijack remote PowerShell sessions and access Microsoft 365 tenants that were not mine. Tenants where I could now export everything, e-mail, files, etc.

      In conversation about 5 months ago permalink
      Lenz Grimmer repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.