Hacker News new | past | comments | ask | show | jobs | submit login

This sounds like no basic pen testing was performed - quite surprised Microsoft isn't doing that.

Seems like their resources (billions in cash) aren't allocated correctly.




I'm sure it was pentested, but the problem is pentesting quality can vary wildly. Hard to know if you have a great tester or a great dev team.


How are you sure when Windows is tested by the users and they scaled down their testing teams? Genuinely curious?


Late to reply but the answer is services are different than desktop software. Azure services fall under a rigorous compliance regime and pentesting (3rd party even) is part of that. Just goes to show compliance does not always mean secure.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: