Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

All vendors have weaknesses, but few have Microsoft's cavalier attitude towards security. Case in point: https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...

If you bragged to me about being locked into Azure I would be very puzzled.



Meh. That whole issue is way overblown by the twitter researcher types trying to build buzz and make a name. It's a serious issue don't get me wrong but security incidents are a question of when not if and the dialog surrounding the issue doesn't come across as charitably capturing the scope and impact. Microsoft's response, which has been to handle the issue responsibly is far from the "radio silence coverup" and "the attackers are still in the network" and "you can't trust anything Microsoft signs anymore" reality you'd be inclined to believe if you only read the hype angle and believe the alarmist comments from other "any chance to bash on M$ is a heyday" types.

I hadn't seen the article you linked though and will say it seems to be in good taste.


They were able to spoof tokens for a long time, access mailboxes, etc.

If this isn't enough for you, there's also ChaosDB, the cross-account vulnerability Palo Alto found (https://unit42.paloaltonetworks.com/azure-container-instance...), among many others.

This isn't an isolated instance, that's a pattern.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: