Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Microsoft Signing Key Stolen by Chinese - Schneier on Security

⁨43⁩ ⁨likes⁩

Submitted ⁨⁨1⁩ ⁨year⁩ ago⁩ by ⁨sv1sjp@lemmy.world⁩ to ⁨cybersecurity@infosec.pub⁩

https://www.schneier.com/blog/archives/2023/08/microsoft-signing-key-stolen-by-chinese.html

source

Comments

Sort:hotnewtop
  • hillbicks@feddit.de ⁨1⁩ ⁨year⁩ ago

    Actually, two things went badly wrong here. The first is that Azure accepted an expired signing key, implying a vulnerability in whatever is supposed to check key validity. The second is that this key was supposed to remain in the the system’s Hardware Security Module—and not be in software. This implies a really serious breach of good security practice. The fact that Microsoft has not been forthcoming about the details of what happened tell me that the details are really bad.

    Jesus fucking Christ… I really did not expect this from Microsoft I have to say. The first one is strange already but the second one? Really looking forward to their explanation of this cluster fuck…

    source
  • housepanther@lemmy.goblackcat.com ⁨1⁩ ⁨year⁩ ago

    Ooops!? I mean what can a person really say about this other than this was an epic failure on Microsoft’s part. Either through hubris, lack of oversight, or just good plain old incompetence of management the Chinese have the keys to the castle. This really highlights the inherent weakness of proprietary software solutions and (in)security through obscurity. This is why everything I do that is not related to my job as a Windows desktop support engineer is going to be on open source.

    source
  • assembly@lemmy.world ⁨1⁩ ⁨year⁩ ago

    How does one even recover from this. I guess the assumption stays the same that everything on a corp network is compromised. Can’t imagine this is going to win Azure new business for DoD workloads.

    source
  • detoxlife@exploding-heads.com ⁨1⁩ ⁨year⁩ ago

    Maybe our government shouldn’t be using corporate products. Maybe we should use that shit ton of money in our military budget to create our own software.

    source
    • Sabata11792@kbin.social ⁨1⁩ ⁨year⁩ ago

      The government could save so much money gathering data directly instead of buying it from Microsoft.

      source
      • xylogis@infosec.pub ⁨1⁩ ⁨year⁩ ago

        Remember the OPM hack? Remember when pretty much every bit of PII for everyone in the government leaked? What makes you think the US government could do a better job?

        source
        • -> View More Comments
    • Nougat@kbin.social ⁨1⁩ ⁨year⁩ ago

      https://en.wikipedia.org/wiki/Red_Star_OS

      source
      • detoxlife@exploding-heads.com ⁨1⁩ ⁨year⁩ ago

        Apple OSX clone.

        source