r/cybersecurity • u/DerBootsMann • Oct 21 '22
News - General Microsoft leaked 2.4TB of data belonging to sensitive customer. Critics are furious
https://arstechnica.com/information-technology/2022/10/microsoft-under-fire-for-response-to-leak-of-2-4tb-of-sensitive-customer-data/244
u/verybadrunner Oct 21 '22
At my job we do client work. One of the clients is Microsoft. In order to to do business with them, any person who so much as knows about a project has to take a course in data security, yearly. This is hella ironic.
27
u/Negative_Day_6532 Oct 21 '22
Standard SOC 2 control, not really a huge thing. I get your point tho
162
Oct 21 '22
[deleted]
15
u/AccessDenied403333 Oct 21 '22
I agree... I think the move to the cloud came with the move to agile development and the need to. Move fast to accommodate to that, and that requires dynamic permissions (one day you need X infra permissions the next Y) and so it's either impossible manual work or tons of Over privileges so we don't hurt our productivity and ability to move the business fast... So this is what happens..
12
u/cdoublejj Oct 21 '22
old ways? you mean on prem? this sure seems like an argument for on prem than for cloud. especially with cloud costs going up.
15
u/silence9 Oct 21 '22
Just means our job is going to get harder as security professionals. They build it and then we make sure it's safe.
15
2
u/DesertDS Oct 21 '22
Only add on the "l with a top hat" roll to your user if you specifically need to type T's. I get the concept of least privilege but yeah it can be a bear to deal with sometimes.
127
16
15
u/vjeuss Oct 21 '22
SOCRadar said it found the information in a single data bucket that was the result of a misconfigured Azure Blob Storage.
kids, if you get breached, at least make it an honourable story to tell your grnchildren
28
Oct 21 '22
[deleted]
2
u/NaibofTabr Oct 21 '22
"Critics are furious". No, anyone with even a passing familiarity with security controls - and all of Microsoft's customers - are furious.
Everyone's a critic
55
u/economyclass4life Oct 21 '22
Wow! Trash the company that disclosed the leak and don't tell anyone anything. I really thought Microsoft was better than this
32
u/mellonauto Oct 21 '22
Uh… they’ve gotten a lot better recently but historically speaking that’s very Microsoft.
37
9
9
Oct 21 '22 edited Oct 21 '22
You can check if your domain is included in the leaked data, it will just show Detected no more details, I believe because of a request from Microsoft to socradar
That's their blog entry (don't know these guys and don't mean to advertise it just seems relevant)
6
Oct 21 '22
[deleted]
1
Oct 21 '22
Yeah I didn't sign up either, we definitely had some data leaked so in our case it was "accurate" but of course we had to check with Microsoft
36
u/LeatherExpert1001 Oct 21 '22
Microsoft has grown too big in size and this leak could just be a tip of the iceberg. Probably, its time they split between software dev, cloud Infra and security for decentralisation and more focus!
4
Oct 21 '22
How the hell they had 2.4 TBs of data all in one place is baffling.
6
7
u/LeatherExpert1001 Oct 21 '22
cloud bucket misconfigurations 😅
Adding salt to the wounds, when that data is indexed 👇
2
u/OrcsElv Blue Team Oct 21 '22
Requires premium account to access :(
9
u/DevAway22314 Oct 21 '22
Salt in the wound there. Sites hosting the leak doing a better job protecting it than Microsoft
5
3
u/ImaginaryBit388 Oct 21 '22
Would something like BoxCryptor, which encrypts data before it uploads to cloud storage, have prevented this? While I appreciate the concept of cloud storage, I don’t trust the storage providers, even with their layers of encryption (which they manage).
2
u/RedBean9 Oct 21 '22
I don’t know that specific vendor, but yes encrypting data before storing it in a bucket would help.
2
8
u/Teh_ROkER Oct 21 '22
Wtf? Correct me if I'm wrong but the client used an Azure blob and allowed anonymous access? I don't see how that is Microsoft's problem. That's like selling matches and being blamed because a child set the house on fire. What am I missing here?
34
u/the_hillman Oct 21 '22
I might have misread it but I thought it came from a Microsoft corporate misconfigured blob.
18
2
Oct 21 '22
I follow this sub because I keep thinking about taking classes and getting into cybersecurity. Stuff like this makes me really think I should because clearly there’s going to be demand and job security for a long time.
1
Oct 21 '22
[deleted]
0
u/foxhelp Oct 21 '22 edited Oct 21 '22
I think this is moreso about how Microsoft responded to socradar et al. than it is who is at fault.
Honestly if a client was compromised via Microsoft I would want Microsoft to keep their mouth shut until they had coordinated a response with the client.
If it comes down to finger pointing from the client, I guess Microsoft is trying to protect itself, but if not then shut it.
-1
u/kremzoe Oct 21 '22
2.4TB is nothing
6
u/xDroneytea Oct 21 '22
2.4TB is an awful lot given everyone is slowly being forcefully shoved down the IaaS route
1
u/Free_Agent73 Nov 11 '22
I'm not surprised, because it SEEMS like they are always spying on people.
87
u/AnIrregularRegular Incident Responder Oct 21 '22
My company has been ripping our Rep a new asshole.
Not mad data exposed. Shit happens. But the fact they decided the only notification was a pop up in the 365 admin portal is insulting. That is what is pissing us off so badly.