Bruh... there's a "master key" that grants access to every Cosmos DB on Azure? Wut?
https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db
Post
Bruh... there's a "master key" that grants access to every Cosmos DB on Azure? Wut?
https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db
@campuscodi Yet another demonstration that putting your data on other people's computers is a bad idea..
@campuscodi every DB at least needs a place where the internal key to setup replicas is placed. I guess every DB vendor has such a key saved (per database)bin their control plane data store. E.g. AWS only gives you a non superuser credential (or gave you a few years back) and I guess the real superuser was reserved for internal stuff like replica setup and monitoring.
@campuscodi I see this and know why it was incredibly bad. I also know on my server I have a user "root" that gives full access to every Mariadb database on the server and a backup user that has full read access to every Mariadb database to facilitate doing backups.
Yes, I know the scale is vastly different and it was microsloppy having a single key for a huge number of datacentres but this is just what I and many other server owners do scaled up to ridiculous size.
@campuscodi There WAS a master key that granted access to every Cosmos DB on Azure. As part of mitigating this vulnerability MS changed the architecture and got rid of it.
Still bad, but not _quite_ as bad.
@campuscodi Jeez, ChaosDB was not even that long ago.
https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough
Both of these walkthroughs are a scary peeks at what cloud infra really is. The two together are damning of Service Fabric, there are security failures at multiple levels but escalation from one host to an entire region happens with basically no effort, in both exploits. It just looks like bad design.
@campuscodi I close the blinds and turn down the lights, then take an aluminium foil hat out of the bottom drawer, all while mumbling about NSA backdoors.
@campuscodi I am sure you will like this blog post: https://isolveproblems.substack.com/p/how-microsoft-vaporized-a-trillion
@campuscodi
I get that key management is hard, but man, if the risk is complete takeover of all resources in a service that I'm hosting for customers as a hyperscaler, I might try to do better than a single main key that grants access to literally everything...
@campuscodi Remember when “they” said let’s put everything in the cloud? Tools, all of them.
CosmosEscape: Taking Over Every Database in Azure CosmosDB
Any region | Any API flavor | Including private databases
Exploits CosmosEscape
Attacker (using)
Cosmos Master Key
(opens)
Azure Cosmos DB Backend
US East
Org A DBS
Europe
Org B DBS
Asia
Org C DBs
US West
Internal Microsoft DBs
Brazil
Internal Azure DBS
(by) WIZ Research
@campuscodi my "yes I have a key that allows access to everyone's database don't worry about it" t-shirt is causing a lot of questions already answered by the t-shirt.
A minimalist social node dedicated to high-fidelity exchange and digital autonomy. CoreSignal strips away the noise of the modern web to provide a clean, functional space for meaningful connection within the Fediverse