624
submitted 2 years ago by ooli@lemmy.world to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] AlmightySnoo@lemmy.world 126 points 2 years ago

It seems this isn't about customer data:

The exposed data included full backups of two employees' computers. These backups contained sensitive personal data, including passwords to Microsoft services, secret keys, and more than 30,000 internal Microsoft Teams messages from more than 350 Microsoft employees.

[-] ChapolinColoradoNZ@lemmy.world 38 points 2 years ago

Some of that data could be from (or for) customer use, like the service passwords.

[-] Aurenkin@sh.itjust.works 31 points 2 years ago

Who TF is keeping secret keys on their dev machine, that shit is toxic. Not to mention passwords

[-] xthexder@l.sw0.com 58 points 2 years ago

They probably mean like private ssh keys and developer credentials, not production keys. Microsoft does not give signing keys to developers, code releases have to get signed through the build servers.

[-] ciko22i3@sopuli.xyz 28 points 2 years ago* (last edited 2 years ago)

What's the other 37.9TB?

[-] crypticthree@lemmy.world 18 points 2 years ago

The lax security is still worrying when they have so much data in general

[-] henfredemars@infosec.pub 10 points 2 years ago

The cloud is just somebody else's computer. You give up some control and get some convenience. I'm paranoid about their cloud services and cloud services in general.

[-] GigglyBobble@kbin.social 2 points 2 years ago

On a local pc no less. They don't use password repos at Microsoft?

this post was submitted on 18 Sep 2023
624 points (98.9% liked)

Technology

70529 readers
1364 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS