news.volyx.in

Copilot broke audit logs, but Microsoft won't tell customers (pistachioapp.com)

821 points by Sayrus · 342 days ago · 309 comments on HN

Article summary

A vulnerability was discovered in Microsoft's Copilot that allowed it to access files without creating an audit log entry, potentially allowing malicious insiders to go undetected. The issue was reported to Microsoft, who fixed it but decided not to notify customers or assign a CVE. The author argues that this decision is problematic, as organizations rely on accurate audit logs for security and compliance purposes. The vulnerability was reportedly easy to exploit and could have been triggered accidentally.

Main themes

  • Microsoft Copilot vulnerability
  • Audit log security
  • CVE assignment
  • Microsoft's handling of vulnerabilities
  • AI-powered security risks

What commenters say

  • The vulnerability deserves a CVE assignment to provide a standardized reference point for discussion and tracking.
  • CVEs are not limited to vulnerabilities affecting multiple products, but can be assigned to individual product vulnerabilities.
  • Microsoft's decision not to notify customers about the vulnerability is problematic, as organizations rely on accurate audit logs for security and compliance.
  • The use of LLMs to manage audit logs is a flawed design and can lead to security risks.
  • The vulnerability is not a significant issue, as it was fixed and does not require a CVE assignment.
  • Microsoft's handling of the vulnerability was appropriate, as they fixed the issue and do not need to notify customers about every minor vulnerability.
  • The issue highlights the need for deterministic systems in security and compliance, rather than relying on AI-powered solutions.
  • The vulnerability is a symptom of a larger problem with Microsoft's approach to security and transparency.