HN user

jimbojet

82 karma

https://jimm.my

Posts0
Comments11
View on HN
No posts found.

Malicious script can (1) fingerprint and detect lab machines and therefore not do bad thing — this is arbitrarily easy if Google test lab is the first to ever execute their script, (2) over time build a graph of IPs, geos, test machine characteristics that essentially allow them to avoid the world’s entire test lab infrastructure (there’s only a fixed number of test lab providers in the world since it’s so expensive to set up this infrastructure), (3) yes, bypassing testing like this is a violation of ToS, but that is fairly meaningless as entities and IPs are cheap to incorporate, (4) not sure what you’re saying about permission policies across its domains? Google does have such policies unless I’m missing something.

What’s the p-value on this bad boy? Also I wonder if they controlled for confounding factors. Ones I can think of are: “Thanks” more likely on emails containing requests, which inherently requires response if from colleague; personality could dictate which valediction you choose, which could also be reflected on how you wrote your email; whether “Best” and “Thanks” are used can be very cultural - eg everyone at Microsoft uses “Thanks” ONLY, and it would be very weird to see a “Best” and extremely rare to see a “Cheers”, those same communities may happen to have a larger response rate since some companies have better email culture, thus given their non-random sampling since they just used the responses from a small handful of online communities, that could bias results.

As someone who worked on reputation at Microsoft, it sounds like a bad case of the right hand not talking to the left. Outlook SmartScreen judgment should be available to tier 3 support along with the IP block list check as a primary investigation step. The author should not have needed to go through tier 3 on two tickets before escalating to someone who had visibility into SmartScreen judgments. Hopefully this blog gets some publicity and Microsoft support amends their investigation process, as I’m sure the author is not the only person running into this issue.

All opinions are my own and not that of Microsoft.

Better than trusting the perimeter. A single breach in a “trustful” intranet still results in full network compromise. Best to assume breach and work from there. Hating on zero trust is non-sensical to me, feels like the same as hating on security.