Hacker News new | past | comments | ask | show | jobs | submit login

One big problem is that there's no way of knowing what other holes/backdoors were introduced during the period when the attacker had all those credentials. Maybe they are immediately able to get the new key.



Let's hope someone has spent the last 3 months reinstalling Azure from the original CD.


FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8


Thanks. I used to have that on a piece of paper taped to my tower. I don't have that tower but instantly recognized it.


You can but you need to install NT4 first, then do all the upgrades


[Laughs in Trusting Trust Problem]


"MSN Limited Edition Gold CD" is actually a thing.


Why is there no way of knowing? I would think Microsoft is able to do forensic snapshot comparisons for their datacenters -- at least, I would assume a trillion dollar company does.


Establishing that ability costs money (i.e. having snapshots & co.), and actually executing it costs further money.

Absent either customers paying for it, or regulations requiring it, Microsoft certainly won't sink money out of the goodness of their heart. I don't believe there are a lot of regulations for this — and how many customers do you think would pay for something like this? Realistically? :-(


I mean, they at least have SOC2 compliance, and obviously a lot more (FEDRAMP). To get those certifications an auditor is going to make sure you have basic shit in place like logging, etc.


They're not going to make sure of anything, in my experience, except that an org's IT management had a disappointing conversation with their team and then aspirationally checked boxes claiming to have things in place.


yeah, but SOC auditors barely understand the stuff you’re providing as proof.


It's gonna depend on the auditor, but yeah of course SOC2 doesn't mean "you're secure" but unless you actively lie to your auditor you're going to have some basic stuff in place.


no one can do what you suggest. it's nonsense.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: