Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Didn't Microsoft create Azure Key Vault for storing and managing secrets?

Why in the world would they not use it?

> The researchers notified Microsoft of the security lapse on February 6, and Microsoft secured the spilling files on March 5.

What???

This doesn't leave me confident of the security of any data in Microsoft's possession.



There is no real penalty for Microsoft here, so there isn't much urgency to address something like this.


There is though, even just OP said:

> This doesn't leave me confident of the security of any data in Microsoft's possession.


You are not wrong, though that penalty may be pretty intangible on a spreadsheet, at least in the near term.


Not familiar with Microsoft’s offering, but $WORK uses a similar product and it is the worst. All sorts of technical and usability problems. Way more friction than doing things the easy way.

I grit my teeth every time I have to interact with it. Not surprised some people use any other solution at hand.


Yeah, in a way I was being tongue in cheek about it.

The truth is that internally they probably don't like using their own solution for key management.

I usually opt for environment variables for secrets, which I know isn't awesome, but keeps them out of code at least.

Regardless, secrets should never ever be committed, even in a private repo (or one you think is private).


> This doesn't leave me confident of the security of any data in Microsoft's possession.

Why would you have ever had confidence in them? They have by far the worst cloud in terms of security, and it isn't even close.

A random selection of serious security incidents:

just from Wiz from the past 2-3 years, and of course they aren't the only ones:

https://www.wiz.io/blog/secret-agent-exposes-azure-customers...

https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...

https://www.wiz.io/blog/azure-active-directory-bing-misconfi...

https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-o...

https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-v...

of course Microsoft AI researchers sucking at security: https://www.wiz.io/blog/38-terabytes-of-private-data-acciden...

Nice overview from Corey Quinn that predates some of those but things were already horrifically bad: https://www.lastweekinaws.com/blog/azures-terrible-security-...

Oh and there's also this, them selling your usage patterns to partners (hopefully they've stopped): https://twitter.com/QuinnyPig/status/1359769481539506180

Oh and another one where they bungled the response: https://twitter.com/QuinnyPig/status/1536868170815795200

I find it impossible to believe that Azure as a whole organisation takes security seriously. There might be individuals that do, but definitely nobody with decision making power. Half of the above described exploits are trivial and should have never passed any sort of competent review process.


> Why in the world would they not use it?

Carelessness of an individual


https://www.securityweek.com/scathing-federal-report-rips-mi...

> The panel said the intrusion, discovered in June by the State Department and dating to May “was preventable and should never have occurred,” blaming its success on “a cascade of avoidable errors.” What’s more, the board said, Microsoft still doesn’t know how the hackers got in.

...

> It said Microsoft’s CEO and board should institute “rapid cultural change” including publicly sharing “a plan with specific timelines to make fundamental, security-focused reforms across the company and its full suite of products.”




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: