The God Mode Vulnerability That Should Kill "trust Microsoft" Forever
Key topics
The post discusses a vulnerability in Microsoft's Azure EntraID that could have allowed attackers to impersonate any user, and the discussion revolves around the implications of this vulnerability and the trustworthiness of Microsoft and other cloud providers.
Snapshot generated from the HN discussion
Discussion Activity
Very active discussionFirst comment
29m
Peak period
21
0-1h
Avg / period
6.2
Based on 31 loaded comments
Key moments
- 01Story posted
Oct 1, 2025 at 2:06 AM EDT
3 months ago
Step 01 - 02First comment
Oct 1, 2025 at 2:35 AM EDT
29m after posting
Step 02 - 03Peak activity
21 comments in 0-1h
Hottest window of the conversation
Step 03 - 04Latest activity
Oct 1, 2025 at 6:37 PM EDT
3 months ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
https://web.archive.org/web/20250923130941/https://tide.org/...
Moreover, as we navigate this evolving paradigm, we must carefully consider the balance between efficiency, authenticity and a third thing in this list.
Maybe at the end of the day, the point of writing isn't delving into a topic and churning out text as fast as you can, but expressing your opinions in your own authentic voice.
https://en.wikipedia.org/wiki/Isocolon#Tricolon
Not quite; the Ballmer quote has him repeat the word in what sounds to me like one block of six followed by two blocks of four.
tide.com is something very different.
You can certainly move to google and get an overall improvement in track record and end user experience, but the fundamental issue raised in the article is still there
You can move to proton and get a pretty nice experience for mail and calendar, but it adds limitations regular users will be upset by. Their equivalent to word is very beta and they have nothing similar to excel.
You can move to nextcloud, and fix the fundamental issue, but every single piece of the solution will be even worse to use than microsoft's stack, and users will hate you.
If I could solve this, I could drop microsoft and google both
The solution in short: "...distributed in the form a key who’s pieces live across a decentralized network."
If looking for alternatives to Microsoft's products I would recommend Infomaniak [0]. They have a fairly complete solution of business tools (email, contacts, calendar, cloud storage, file sharing, chat, video meetings, docs and sheets).
[0] https://www.infomaniak.com
One Token to rule them all – Obtaining Global Admin in every Entra ID tenant (13 days ago - 51 comment): https://news.ycombinator.com/item?id=45282497
All the security and compliances require that someone operates it, not everyone can design systems like Linux in an year or so.
The more darker truth is the entire existence of proprietary codebases and architectures, there's a saying either ask the question or forever remain foolish
It's time we ask it ourselves and the companies which we depend on to allow atleast open auditing their architecture
It's just one step but it prevents the level of exploits like these
> As long as someone or something holds it, it can be exploited.
Wide distribution, as opposed to centralization, seems to be the most reliable way to ensure continuity. Am I wrong in seeing this pattern in so many different areas? The distributed animal survives ecological or geological collapse in one region, the distributed activist group survives fed infiltration into one entity, the distributed army holds off the centralized one (with infinitely better funding and weaponry) for decades, the distributed political power survives demagogue takeover.
I might be abstracting way too far here, but it makes me wonder why we keep trying to centralize authority, when it keeps failing spectacularly.
There are several bits in the article about how Tide and TideCloak demonstrates that authorityless auth works, but I'm not finding an explainer.