Bonum Certa Men Certa

Unwarranted Media Hysteria Over (Allegedly) China Almost Sneaking Compromised xz Into Stable, Production Operating Systems (It Failed) While the US Government Blames Microsoft for Allowing China to Break Into Vital Government Systems Via Windows

posted by Roy Schestowitz on Apr 03, 2024

Shifting attention much, Microsoft-funded media? Microsoft: my dog ate my homework. So what if our whole internal infrastructure and all of Azure got compromised? "LOOK OVA' THAR!"

Beautiful white and brown dog lying under the table

THIS morning we wrote about how nearly 2 decades ago rms (Richard Stallman), who had given public talks about GNU since the mid-80s, warned that proprietary operating systems like Windows were a "back door" threat and, to make matters worse, you would not even know, no matter if that got detected or not (this already happened to Microsoft) [1, 2].

The "mainstream" (corporate, advertisers-funded and typically oligarch-owned) media won't mention any of this and instead it has helped distract from severe Microsoft Exchange issues. There is now a follow-up (see [1-4] below), but the media is shifting attention to "Linux" and it blames "Open Source" because some random user on Microsoft's GitHub (proprietary) pulled off a social engineering attack, aided by Microsoft systemd (also GitHub) and made "famous" by a Microsoft employee.

"Not only is there the 17k Microsoft Exchange server problem," an associate notes this morning, "but there is also the recent report excoriating Microsoft over its mishandling of the China-origin breach of its infrastructure."

See the links below.

"Allegedly" in the title of this post is because (while China is confirmed for the Microsoft breach) we don't even know what happened to xz. GitHub (Microsoft) makes it harder by hiding the evidence. The issue here or the culprit remains unattributed, an associate has said. "Red China is as likely as Israel, Russia, Netherlands, or US."

"However, in the other break-in [Microsoft], it is directly attributable to Red China."

Funnily enough, the corruptible media portrays the source of the FUD, Microsoft, as the saviour here. As if a campaign of misinformation or strategically-timed drama is something to be commended/praised for.

We're collectively paying the price for having very bad media/press. Media standards in the West have fallen closer to Red China's levels.

  1. Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack

    In a scathing indictment of Microsoft corporate security and transparency, a Biden administration-appointed review board issued a report Tuesday saying “a cascade of errors” by the tech giant let state-backed Chinese cyber operators break into email accounts of senior U.S. officials including Commerce Secretary Gina Raimondo.

    The Cyber Safety Review Board, created in 2021 by executive order, describes shoddy cybersecurity practices, a lax corporate culture and a lack of sincerity about the company's knowledge of the targeted breach, which affected multiple U.S. agencies that deal with China.

  2. Cyber review board blames cascading Microsoft failures for Chinese hack

    The CSRB lays the blame for the incident squarely on Microsoft: “The Board concludes that this intrusion should never have happened. Storm-0558 was able to succeed because of a cascade of security failures at Microsoft.”

    The report represents the conclusion of a seven-month review and comes against the backdrop of growing concern in Washington that a series of severe breaches at Microsoft has made the company a national-security liability at a time when the federal government is increasingly relying on that company for a raft of cloud computing services. In January, Microsoft disclosed the latest such incident, in which Russian hackers were able to access emails belonging to senior company officials and company source code.

  3. Microsoft slammed for lax infosec that led to Exchange crack

    A review of the June 2023 attack on Microsoft's Exchange Online hosted email service – which saw accounts used by senior US officials compromised by a China-linked group called "Storm-0558" – has found that the incident would have been preventable save for Microsoft's lax infosec culture and sub-par cloud security precautions.

    The review, conducted by the US government's Cybersecurity and Infrastructure Security Agency's Cyber Safety Review Board (CSRB), calls for "rapid cultural change" at Microsoft. Among the Board's recommendations: [...]

  4. Review of the Summer 2023 Microsoft Exchange Online Intrusion [PDF]

    In May and June 2023, a threat actor compromised the Microsoft Exchange Online mailboxes of 22 organizations and over 500 individuals around the world. The actor—known as Storm-0558 and assessed to be affiliated with the People’s Republic of China in pursuit of espionage objectives—accessed the accounts using authentication tokens that were signed by a key Microsoft had created in 2016. This intrusion compromised senior United States government representatives working on national security matters, including the email accounts of Commerce Secretary Gina Raimondo, United States Ambassador to the People’s Republic of China R. Nicholas Burns, and Congressman Don Bacon.

    Signing keys, used for secure authentication into remote systems, are the cryptographic equivalent of crown jewels for any cloud service provider. As occurred in the course of this incident, an adversary in possession of a valid signing key can grant itself permission to access any information or systems within that key’s domain. A single key’s reach can be enormous, and in this case the stolen key had extraordinary power. In fact, when combined with another flaw in Microsoft’s authentication system, the key permitted Storm-0558 to gain full access to essentially any Exchange Online account anywhere in the world. As of the date of this report, Microsoft does not know how or when Storm-0558 obtained the signing key.

    This was not the first intrusion perpetrated by Storm-0558, nor is it the first time Storm-0558 displayed interest in compromising cloud providers or stealing authentication keys. Industry links Storm-0558 to the 2009 Operation Aurora campaign that targeted over two dozen companies, including Google, and the 2011 RSA SecurID incident, in which the actor stole secret keys used to generate authentication codes for SecurID tokens, which were used by tens of millions of users at that time. Indeed, security researchers have tracked Storm-0558’s activities for over 20 years.

Other Recent Techrights' Posts

After Softpedia Pushed Out Its Linux News Editor - and Effectively Killed the Linux Section - it Killed the Whole News Section (Altogether)
So they've killed Linux coverage, then their whole "news" section died
Cybersecurity is a structural not behavioural problem.
Reprinted with permission from Cyber|Show
 
The Media Finally Admits (on a Regular Basis) That LLMs Suck
They could not replace medical doctors, teachers, lawyers etc.
Why We're Taking Things Up a Notch
Expect about 20 articles a day this year
Sites That Cover WSL Are Helping Microsoft's Attack on GNU/Linux
Calling out the typical culprits
Plans for June
We'll try to publish Daily Links every time we have enough of these
The War on Free Software Reporters - Part III - Doxing and LARPing
LARPing is an issue I've had to deal with for nearly 20 years
Links 01/06/2024: Ukraine Updates, MongoDB Collapses
Links for the day
Gemini Links 01/06/2024: MNT Pocket Reform, Gemini and Content Length
Links for the day
Links 01/06/2024: WeblogPoMo2024, Pentagon’s Increasing Reliance on (i.e. Bailouts to) Microsoft
Links for the day
Twitter is (in Many Ways) Already Dead
Put an 'X' on it
Posts About Free Software, BSD, and GNU/Linux
Focus shifts have occasionally been discussed here over the years
Their Goal is Control, Not Security (and Their Staff Advocates Fake Security or Pricey Gimmicks That Disempower the Users)
Those companies just want control, or simply domination over users (and their computers)
[Meme] The Lowest Standards of Security
No need for any qualifications
IRC Proceedings: Friday, May 31, 2024
IRC logs for Friday, May 31, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Free Software is the Future, Open Source is Just Openwashing (Proprietary With a False Marketing Twist)
Also see postopen.org
Society Has Been Destabilised by Social Control Networks
Is it time to get rid of them, if not by sanctions/bans then simply by popular boycotts?
Gemini Turns 5 This Month
As long as Geminispace exists and is accessed by enough people, Gemini Protocol will continue to matter
Links 01/06/2024: More Crackdowns in Hong Kong, Street Named After Navalny
Links for the day
The War on Free Software Reporters - Part II - Antisocial Mobs
how various GNU/Linux bloggers got "canceled" over the years
Microsoft's Share of Physical Web Servers Fell From 9.14% to 9.04% in One Month
What's interesting to us is how Microsoft continues moving down in everything measured
Links 31/05/2024: Escalations in Ukraine and Russia, National Reporter's Shield Law in US
Links for the day
Links 31/05/2024: Generating and Using Identifiers, Why Unicode
Links for the day
A 3-Year Campaign to Coerce/Intimidate Us Into Censorship: In Summary
Some high-profile examples of defamation include Linus Torvalds, Richard Stallman...
[Meme] Never "Missing Out" in FOSS Conferences
The sexists who objectify women and bully women are going to FOSS events in pursuit of sex, according to themselves
Racism, Ageism, and Ableism at IBM/Red Hat and Kyndryl
IBM's Kyndryl is now accused of "racial, age, disability discrimination"
The War on Free Software Reporters - Part I - Why Techrights Cannot be Censored (and Won't be Censored)
Microsoft remains by far the biggest culprit
In Spite of Boot-locking (Trying to Make It Hard If Not Impossible to Install BSDs and GNU/Linux on New PCs) Microsoft's Grip is Rapidly Slipping
Escaping the Microsoft prison
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 30, 2024
IRC logs for Thursday, May 30, 2024
Microsoft's Problem in Puerto Rico
Notice how much Windows has fallen
Gemini Links 31/05/2024: MNT Pocket Reform and Benben v0.5.0
Links for the day
"I once preached peaceful coexistence with Windows. You may laugh at my expense -- I deserve it." -Be's CEO Jean-Louis Gassée
Execution of Red Hat: But I helped promote Azure and .NET
In Many Countries Vista 11's Market Share Goes Down, Not Up (Even Microsoft-Funded Mainstream Media Admits This)
More people are moving to GNU/Linux
10 More Days
Tux Machines turns 20.
[Meme] Meeting People on 'Dating Apps'
On the Internet, nobody knows you're a dog until you bark
The Campaign to 'End' Richard Stallman - Part IV - The Legitimate Concerns
So at least we now know why the FSF does not mention public talks
Links 30/05/2024: Public Domain and Kangaroo Courts
Links for the day
Canonical Works for Microsoft
Where are the antitrust regulators or CMA?
Links 30/05/2024: Microsoft Layoffs Back in Headlines, RISC-V and Standards
Links for the day
Gemini Links 30/05/2024: A Lonely Friend and Deletion of Old Posts
Links for the day
[Meme] 10 Years Down the New Career System (NCS) and What it Did to Our Collegiality
New from SUEPO, the staff union of the EPO
[Chart] Chromebooks in Micronesia Grew at the Expense of Microsoft Windows
As of today...
Angola: Microsoft Windows Down From 98% to 12%
Africa is "lost territory" for Microsoft colonialism
No News Drought in Techrights
Leaving my job after almost 12 years also contributes to available time for research and publication
A 3-Year Campaign to Coerce/Intimidate Us Into Censorship: Targeting My Wife
In my view, it is a form of overt sexism
Death Valley
The truth can be twisted
[Meme] UEFI 'Secure' Boot's Model of Security
Lion cage with people
Climbing a Tall Mountain for 2 Decades
In Web terms, 20 years is a very long time. Very few sites (or a small proportion of the whole) make it to 20.
If You're Going to Concern-Troll "Linux" Make Sure You Actually Use It (Or Tried It)
Concern-trolling has long been a key ingredient of GNU/Linux Fear, Uncertainty, and Doubt
The Serial Strangler From Microsoft is About to Be Served Court Papers
You can run, but you cannot hide
The Campaign to 'End' Richard Stallman - Part III - The Reddit Mob (Social Control Media Controlled, Steered or Commandeered by Wall Street)
This is totally reminiscent of what authoritarian regimes do
Caged by Microsoft
Are you telling me that preventing people from booting their Linux is security?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, May 29, 2024
IRC logs for Wednesday, May 29, 2024