Newsletter Archives

  • Why is software security so hard?

    ON SECURITY

    Susan Bradley

    By Susan Bradley

    I’ve had discussions with developers about how and why software bugs get introduced into software.

    Most of the time, it’s because humans write the code, and then we humans use the code, often doing things that the software developer just didn’t think we’d do. But then there are those bonehead decisions that developers have made along the way — because someone decided it was faster or easier to do something that later proved to be a problem, rather than taking the time to do it right in the first place.

    Read the full story in our Plus Newsletter (22.06.0, 2025-02-10).

  • Using Office 365 and can’t log on? (Again?) Looks like multi-factor authentication is down again

    For the second time in as many weeks, I’m seeing widespread reports that folks can’t log on to Office.

    Mary Jo Foley reports on ZDNet:

    Starting around 9:15 a.m. ET, a number of Office 365 customers began reporting on Twitter that they were unable to sign into that service because of an MFA issue. Office 365 is one of a number of Microsoft services that uses Azure Active Directory MFA to authenticate.

    You can see the current status report here. At the moment we’re treated to this delightful ditty:

    Starting at 14:25 UTC on 27 Nov 2018 a subset of customers using Multi-Factor Authentication may experience intermittent issues signing into Azure resources, such as Azure Active Directory, when Multi-Factor Authentication is required by policy. Impacted customers may encounter timeout errors. Engineers are aware of this issue and are actively investigating mitigation options. The next update will be provided in 60 minutes, or as events warrant.

    Here we go again.

  • Mary Jo Foley: Microsoft’s self-analysis of what caused the multi-factor authentication meltdown

    Remember the bug on November 19 that brought down everybody who was using two factor authorization on Microsoft sites?

    We just got an explanation. Per Mary Jo:

    Actually, Microsoft unearthed three independent root causes, along with monitoring gaps that resulted in Azure, Office 365, Dynamics and other Microsoft users not being able to authenticate for much of that day.

    In a different, but sort-of-related glitch, lots of people are reporting problems today with Exchange Online, Office 365 and Outlook.

    https://twitter.com/MSFT365Status/status/1067101513242169344