Harmony Evans's Blog, page 734

August 3, 2023

Sarah Palin Says Trump’s Indictment Is ‘Injust’ And Is Making People ‘Afraid Of Their Thoughts’

Former Republican Vice Presidential candidate Sarah Palin is very concerned that Donald Trump’s indictment is “injust” and like Orwell’s 1984 is making people “afraid of their thoughts.”

Sarah Palin says former President Donald Trump’s D.C. indictment is “injust” and making people “afraid of their thoughts.”

Watch:


Sarah Palin says former President Donald Trump’s D.C. indictment is “injust” and making people “afraid of their thoughts”:


“They [are attempting] to jail him for expressing his opinion!” pic.twitter.com/bL3pQOOyrJ


— Heartland Signal (@HeartlandSignal) August 3, 2023


Ms. Palin said, “It’s surreal what’s going on. It’s injust. My other word for this though is Orwellian.”

The Republican compared it to Orwell’s dystopian masterpiece of 1984, “Remember, the book 1984. We saw freedom of speech in that book once it was thwarted, people began then to be afraid of their thoughts, of thinking something, because they were afraid to articulate it or they were going to be busted by the government.”

We can probably understand why Sarah Palin is afraid of her own thoughts, but one is not forced into articulating their thoughts aloud unless one chooses to do so. If one does choose to do so, one is accountable for those words, especially if one is in public office.

But also, 1984 warned about a government run a lot like Trump tried to run the U.S., a government that had the power to determine what is real, what comprises history and what the facts are. Right now in the U.S., Republican governors are trying to seize control of history. 1984 warns about the power of Big Brother to control information. Orwell repeatedly warned about the dangers of propaganda.

“That is what is happening to Donald Trump,” Palin continued. “He expressed his opinions on the elections. A whole lot of Americans expressed their opinions on the elections. Democrats for years have denied election results.”

This is not actually true. The indictment actually addressed Trump’s right to freedom of speech. He’s being indicted for his actions, not his thoughts.

“And now, what has that resulted in? The head honcho, the attempt to jail him for expressing his opinion. That is Orwellian, and it leads a slippery slope and into much more than controlling speech.”

This talking point, however mangled, about Trump’s “free speech” being prosecuted originated from Trump’s lawyer John Lauro announcing on Fox News that Trump was being indicted for “what he believed in and the policies and the political speech that he carried out as president.”

Vox has an excellent breakdown of exactly why trying to overturn an election and disenfranchise voters is not free speech:

“One is that Smith repeatedly accuses Trump of pressuring other government officials to commit criminal acts of election fraud, and it is well established that soliciting another individual to commit a crime is not protected by the First Amendment. As the Supreme Court held in United States v. Williams (2008), “offers to engage in illegal transactions are categorically excluded from First Amendment protection.”

But also, “The First Amendment does not protect the kind of lies Trump is accused of telling. Additionally, the First Amendment provides much weaker protections for people who knowingly make false statements than it does for other speakers.”

Then there’s the issue of the RIGHT to vote and have it counted, which is essential in a democracy.

It’s absurd to argue that Trump’s free speech is being prosecuted, but then it doesn’t take much to convince his supporters that he is God almighty and can do no wrong. They’ll even tell reporters as much.

It’s kind of perfect that Palin’s comments on Trump’s indictment include a vintage Palinism like “injust.”

Before Trump brought us “covfefe”, “big-league” as an adverb (also known as “bigly”), and “Nambia” two times at an event with African leaders, Sarah Palin was elevating American political discourse with words like ‘refudiate’ and who can forget when she tweeted ‘cackle of rads’ on the anniversary of women’s suffrage.

Palin defended herself by comparing herself to William Shakespeare, “‘Refudiate,’ ‘misunderestimate,’ ‘wee-wee’d up.’ English is a living language. Shakespeare liked to coin new words too. Got to celebrate it!”

Sarah Palin ushered in Trumpism before Donald Trump did. She was the OG of Pugnacious, Willful Ignorance Meets Autocratic Entitlement. The half-term governor believed God had chosen her to be President, for example, and so she ignored her top-of-the-ticket running mate Senator John McCain’s instructions not to give a concession speech and rushed the stage. She long believed she had been chosen by God to be president, and no one was going to keep her down.

Palin then became the Queen of the Tea Party, riding a wave of “whitelash” racist rage at President Obama’s White House win into a high profile Fox job and tons of media attention. But then Palin made the mistake of crying it was “Blood Libel” to hold her even somewhat accountable for the gun sights she put over Democrat Rep. Gabby Giffords’ district, after Giffords and 18 others were shot during a constituent meeting outside in a parking lot.

Ms. Palin was unable to reclaim her former glory and has since lost two elections for a House seat in Alaska, where they know her best.

Sarah Palin walked so Donald Trump could run. And isn’t that just so injust.

Listen to Sarah on the PoliticusUSA Pod on The Daily newsletter podcast here.

Sarah has been credentialed to cover President Barack Obama, then VP Joe Biden, 2016 Democratic presidential candidate Hillary Clinton, and exclusively interviewed Speaker Nancy Pelosi multiple times and exclusively covered her first home appearance after the first impeachment of then President Donald Trump.

Sarah is two-time Telly award winning video producer and a member of the Society of Professional Journalists.

Connect with Sarah on Post,  Mastodon @PoliticusSarah@Journa.Host, & Twitter.




Source link

The post Sarah Palin Says Trump’s Indictment Is ‘Injust’ And Is Making People ‘Afraid Of Their Thoughts’ appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 03, 2023 19:50

EVIL TO THE CORE: Portland Hospital Denies Woman Cancer Treatment After She Sent a Message Criticizing the Transgender Flag | The Gateway Pundit

Do not question the woke trans agenda.

A report has revealed that a woman has been denied cancer treatment at a Portland area hospital after she criticized the facility for displaying the trans flag.

The woman in question was identified only as Marlene to protect her identity. She sent a message to conservative activist Chaya Raichik on her popular social media account Libs of Tiktok revealing what happened to her.

As one can see, Marlene’s message was originally sent to a person at Oregon Health and Science University (OHSU) Hospital after multiple prior communications with staff there.

LOOK:


A woman receiving cancer treatment at @OHSUNews was told she can no longer be a patient at the clinic after she sent a message criticizing a trans flag hanging prominently at the entrance.


She told us that they requested she go for “re-education” and she refused. pic.twitter.com/WdAvRoYoMV


— Libs of TikTok (@libsoftiktok) August 2, 2023


In Marlene’s statement, she notes that other staff members at OHSU were not handling her communications in good faith. She says she feels unsafe coming into the hospital with a massive transgenderism banner hanging behind the front desk.

Moreover, Marlene reveals that she has been getting death threats from radical trans activists.

Credit: Libs of Tiktok

The staffer ignored her pleas and made a decision that can only be described as pure evil. Marlene was told she would no longer be receiving medical care at the clinic due to alleged “ongoing disrespectful and hurtful remarks” about the LGBTQ community and their staff. She was banned her from their facilities effective July 29, 2023.

Credit: Libs of Tiktok Twitter

Marlene also told Raichik that the hospital demanded that she receive “re-education” training, which she refused. She might end up losing her life for not playing ball with the hospital.

One can expect to hear far more of these stories in the future. Leftists have infiltrated the majority of institutions in America and are all-in on pushing gender identity politics.

This includes the medical establishment, which has helped lead the way in denying science and truth about gender ideology at the expense of others, especially women.

Marlene is currently exploring her legal options. Raichik is requesting people reach out and help her.


I spoke with Marlene today and she said she would like to explore actions she can take against the hospital. If you or someone you know can help her- please dm me https://t.co/RsqyrlirUG


— Chaya Raichik (@ChayaRaichik10) August 2, 2023





Source link

The post EVIL TO THE CORE: Portland Hospital Denies Woman Cancer Treatment After She Sent a Message Criticizing the Transgender Flag | The Gateway Pundit appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 03, 2023 01:25

Apple Watch 9 promises no radical changes but a new pink colour

Don’t expect the Apple Watch 9 to look any different to the Apple Watch 8, but anyone who’s ever fantasised about a pink model might be set to have their dreams realised.

That’s the claim being made by an established tipster with a track record of making accurate predictions on such matters. ShrimpApplePro has taken to Twitter/X to offer their pronouncement on Apple’s forthcoming smartwatch refresh, which is likely just a month or so away from being announced.


Shrimp’s update
– Apple Watch Series 9
Well, i wish i can see anything that is new outside but it looks the same


Added a pink color along with the other 4 colors with the same case material.
There is a new box this time (better than nothing) more compact box.
New chip i guess. pic.twitter.com/rh95TNuady


— ShrimpApplePro 🍤 (@VNchocoTaco) August 1, 2023


As you can see, the tipster reckons that the Apple Watch 9 will be externally nigh-on identical to the Apple Watch 8, which was hardly a bold reinvention itself. “Well, I wish I can see anything that is new outside but it looks the same,” they say. There’ll be the same 41 and 45mm sizing options and a “new chip I guess”.

One thing that does sound new is that Apple has apparently “added a pink color along with the other 4 colors with the same case material”.

This makes it sound like a full on pink finish to the metal body. This isn’t nailed on, of course, but it doesn’t seem like the tipster is talking about something like the rose gold Apple Watch 5 here, which only looked truly pink when you paired it with a pink band.

Of course, the real radical change with last year’s Apple smartwatch range was the introduction of the Apple Watch Ultra, and the tipster follows up with prediction of an Apple Watch Ultra 2. That too will have the same design, which is understandable. This year, however, there’ll be the option of a black titanium option.




Source link

The post Apple Watch 9 promises no radical changes but a new pink colour appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 03, 2023 01:16

Far Left Rep. Pramila Jayapal Who Opposed Trump Border Wall Builds Security Fence Around Her Home | The Gateway Pundit

Far left ‘squad’ member Rep. Pramila Jayapal of Washington State was a vocal opponent of Trump’s border wall, but apparently has a different attitude when it comes to her home.

She has spent over $45,000 on security at her home, including a fence, because of course she has.

It’s also important to note that she used campaign donations to do this.

That’s not necessarily illegal, but it doesn’t look good.

The Seattle Times reports:


U.S. Rep. Jayapal spends over $45k on security, including fence


U.S. Rep. Pramila Jayapal, D-Seattle, reported spending over $45,000 this year on home security using campaign donations, according to Federal Election Commission records.


The leader of the Congressional Progressive Caucus is one of many congressional leaders who have ramped up spending on personal security, an effort that has increased since the deadly riot on Jan. 6, 2021, at the U.S. Capitol and the hyperpolarization of the political climate.


As a national figure in U.S. politics and a chair of the 104-member progressive caucus, Jayapal never expected to focus so keenly on her personal security.


“I’ve had threats against my life, including a man showing up with a gun at my door, and I never in a million years thought that I would need to take such strong steps to protect my safety and security just to be able to do my job, the job that people elected me to do,” Jayapal said in an interview with The Seattle Times.


All of the security-related expenditures were recorded between January and June.


Let’s take a walk down memory lane with Rep. Jayapal, shall we?


The hypocrisy of Trump’s vanity wall. He wants to show it being built—at enormous cost to taxpayers—even if it helps people break through easier. It’s just an expensive hoax.


P.S. People can get through walls. That’s why they don’t work. https://t.co/o96AsTdiDN


— Rep. Pramila Jayapal (@RepJayapal) November 13, 2019



Walls go against the very heart of our nation as we’re supposed to be a beacon of hope.


I’m glad to see Biden act. Now, we must invest in policies that protect the rights of communities in the borderlands and end the mass militarization of the region.https://t.co/QlMY0yJmPW


— Rep. Pramila Jayapal (@RepJayapal) February 14, 2021


Anyone surprised?

It’s totally different when she does it.




Source link

The post Far Left Rep. Pramila Jayapal Who Opposed Trump Border Wall Builds Security Fence Around Her Home | The Gateway Pundit appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 03, 2023 00:24

August 2, 2023

Kevin O’Leary on U.S. Credit Downgrade: ‘There’s No Way to Sugarcoat This at All. It’s Bad.’ (VIDEO) | The Gateway Pundit

Investor and financial advisor Kevin O’Leary recently appeared on FOX News to offer his opinion about the recent downgrade of the credit of the United States. He did not hold back.

The host pointed out that the Biden administration is trying to pin this on Donald Trump, but O’Leary reminded him that this sort of thing is based on government and policy.

This is happening on Biden’s watch and he has no one to blame but himself and his administration.

Transcript via FOX News:


KEVIN O’LEARY: There is no way to sugarcoat this at all. It’s bad. And I’ll tell you how you measure it’s bad. Basically, when you downgrade the U.S. economy, which is what this downgrading is, you are losing a little faith in the U.S. dollar and the U.S. Treasury bill because the default currency of the world, defined by every commodity priced by U.S. dollars, is the good faith of the U.S. government and the whole world. Trust it.


Most sovereign funds keep the majority of their liquidity in U.S. dollars. That got hurt 24 hours ago because now you start to ask yourself, well, where is this going? A downgrade from AAA to AA, does it go to single? Now, if you’re a sovereign wealth fund, you start to put that in your mind. And the bottom line for you and me is the cost of capital goes up. In other words, what it costs for us to borrow money to fund the government and deficit goes up. No sugarcoating that.


Now, how does this actually affect the next 24 months? Well, let me explain. Think about the CHIPS Act and the Inflation Reduction Act. We’re printing billions of dollars. Government claims it has merit. It’s important to do this. But at the same time, that’s just a lot of spending, and that increases the deficit. And that’s why Finch did this. They downgraded it.


And I wouldn’t say it was the two bills that caused the camel’s back to be broken, but it was enough for them to say, OK, I’ve seen enough now for me and you or anybody. The kitchen table in America, your car loan just went up from five to somewhere between seven and nine percent.


Here’s the video:

Joe Biden and Democrats cannot spin their way out of this.

Their policies are horrible for the health of the United States.


Source link

The post Kevin O’Leary on U.S. Credit Downgrade: ‘There’s No Way to Sugarcoat This at All. It’s Bad.’ (VIDEO) | The Gateway Pundit appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 02, 2023 23:23

Mike Pence Went On Fox News And Gave Eyewitness Evidence That Could Convict Trump

Mike Pence went on Fox News on what seems like a burn Trump to the ground tour and laid out how Trump specifically asked him to throw out votes and overturn the election.

Pence said:

I say that is completely false and contrary to American history, to our constitution and to the laws of this country. I never considered it, Martha. The first time I heard speculation that as vice president that I had authority to overturn the election by rejecting votes, I frankly dismissed it out of hand. The founders of this country had just won a war of independence against a king. I was confident as a student of American history that those founders would have never vested the vice president or anyone else with unilateral authority to decide what electoral college votes to count and which not to count.

I was clear on that — I was clear with president trump throughout all the way up to the morning of January 6. Let’s be clear on this point. It wasn’t that they asked for a pause. The president specifically asked me in his gaggle of crackpot lawyers asked me to literally reject votes, which would have resulted in the issue of being turned over to the House of Representatives and literally chaos would have ensued.

So Martha, people can read the indictment. Frankly, I’ve said before, I hope that it not come to this point. I don’t know if the government can meet the burden of proof beyond reasonable doubt for criminal charges. But the American people deserve to know that president Trump and his advisers didn’t just ask me to pause. They asked me to reject votes, return votes. Essentially overturn the election. I rejected that out of hand and I did my duty that day.

 

Video:


Mike Pence says Trump asked him to throw out votes, “The president specifically asked me and his gaggle of crackpot lawyers asked me to literally reject votes, which would have resulted in the issue of being turned over to the House of Representatives.” pic.twitter.com/5LqIwAkn0t


— Sarah Reese Jones (@PoliticusSarah) August 2, 2023


If this is what Mike Pence told Jack Smith, this is the sort of eyewitness testimony that leads to a conviction. It is way too late for Pence to be speaking out now, but saying what he said where he said was clearly a shot at Trump. Mike Pence’s presidential bid has gained no traction, so it isn’t the worst move in the world for him to pick a fight with Trump and hope that Trump elevates him.

Pence isn’t a hero, but if his comments on Fox News reflect what he told federal prosecutors, Trump has a good chance of becoming a convicted felon.

Jason is the managing editor. He is also a White House Press Pool and a Congressional correspondent for PoliticusUSA. Jason has a Bachelor’s Degree in Political Science. His graduate work focused on public policy, with a specialization in social reform movements.

Awards and  Professional Memberships

Member of the Society of Professional Journalists and The American Political Science Association




Source link

The post Mike Pence Went On Fox News And Gave Eyewitness Evidence That Could Convict Trump appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 02, 2023 22:21

Meta releases open source AI audio tools, AudioCraft

Meta

On Wednesday, Meta announced it is open-sourcing AudioCraft, a suite of generative AI tools for creating music and audio from text prompts. With the tools, content creators can input simple text descriptions to generate complex audio landscapes, compose melodies, or even simulate entire virtual orchestras.

AudioCraft consists of three core components: AudioGen, a tool for generating various audio effects and soundscapes; MusicGen, which can create musical compositions and melodies from descriptions; and EnCodec, a neural network-based audio compression codec.

In particular, Meta says that EnCodec, which we first covered in November, has recently been improved and allows for “higher quality music generation with fewer artifacts.” Also, AudioGen can create audio sound effects like a dog barking, a car horn honking, or footsteps on a wooden floor. And MusicGen can whip up songs of various genres from scratch, based on descriptions like “Pop dance track with catchy melodies, tropical percussions, and upbeat rhythms, perfect for the beach.”

Meta has provided several audio samples on its website for evaluation. The results seem in line with their state-of-the-art labeling, but arguably they aren’t quite high quality enough to replace professionally produced commercial audio effects or music.

Meta notes that while generative AI models centered around text and still pictures have received lots of attention (and are relatively easy for people to experiment with online), development in generative audio tools has lagged behind. “There’s some work out there, but it’s highly complicated and not very open, so people aren’t able to readily play with it,” they write. But they hope that AudioCraft’s release under the MIT License will contribute to the broader community by providing accessible tools for audio and musical experimentation.

Advertisement

“The models are available for research purposes and to further people’s understanding of the technology. We’re excited to give researchers and practitioners access so they can train their own models with their own datasets for the first time and help advance the state of the art,” Meta said.

Meta isn’t the first company to experiment with AI-powered audio and music generators. Among some of the more notable recent attempts, OpenAI debuted its Jukebox in 2020, Google debuted MusicLM in January, and last December, an independent research team created a text-to-music generation platform called Riffusion using a Stable Diffusion base.

None of these generative audio projects have attracted as much attention as image synthesis models, but that doesn’t mean the process of developing them isn’t any less complicated, as Meta notes on its website:

Generating high-fidelity audio of any kind requires modeling complex signals and patterns at varying scales. Music is arguably the most challenging type of audio to generate because it’s composed of local and long-range patterns, from a suite of notes to a global musical structure with multiple instruments. Generating coherent music with AI has often been addressed through the use of symbolic representations like MIDI or piano rolls. However, these approaches are unable to fully grasp the expressive nuances and stylistic elements found in music. More recent advances leverage self-supervised audio representation learning and a number of hierarchical or cascaded models to generate music, feeding the raw audio into a complex system in order to capture long-range structures in the signal while generating quality audio. But we knew that more could be done in this field.

Amid controversy over undisclosed and potentially unethical training material used to create image synthesis models such as Stable Diffusion, DALL-E, and Midjourney, it’s notable that Meta says that MusicGen was trained on “20,000 hours of music owned by Meta or licensed specifically for this purpose.” On its surface, that seems like a move in a more ethical direction that may please some critics of generative AI.

It will be interesting to see how open source developers choose to integrate these Meta audio models in their work. It may result in some interesting and easy-to-use generative audio tools in the near future. For now, the more code-savvy among us can find model weights and code for the three AudioCraft tools on GitHub.


Source link

The post Meta releases open source AI audio tools, AudioCraft appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 02, 2023 22:15

Spider-Man 2 has already been discounted ahead of launch

Marvel’s Spider-Man 2 hasn’t even been release for the PS5 yet, but one of the year’s biggest AAA games has already been discounted.

Those reliable purveyors of gaming bargains, Hit.co.uk, are offering Marvel’s Spider-Man 2 on pre-order for a price of just £61.85. That’s a saving of £8.14 on the £69.99 RRP.

Save £8.14 on Marvel’s Spider-Man 2 for PS5

Hit is offering a Marvel’s Spider-Man 2 PS5 pre-order for just £61.85, which is a saving of £8.14.

HitSave £8.14Now £61.85

View Deal

Given that this is widely expected to be one of the biggest and best game releases of 2023 – which is really saying something when you look at this year’s roster so far – that’s quite a deal.

We now know that Marvel’s Spider-Man 2 will hit shops on October 20, which is just under three months away. It’ll be a PS5 console exclusive, just like the first game in the series.

In case you missed the original Marvel’s Spider-Man, it was one of the finest games of 2018, offering a compelling version of Peter Parker and a rich open world New York to swing around in. Insomniac Games really nailed the movement of this unique hero, complemented by some highly mobile combat.

Scan forward to the launch of the PS5, and Marvel’s Spider-Man: Miles Morales proved to be a similarly compelling stand-alone launch game, with suitably ramped up graphics (including ray tracing) and expanded gameplay to suit its bright young hero. It wasn’t quite the full-sized sequel we were aching for, of course.

That full-sized sequel is now right around the corner, and Hit looks to be just about the best place to order it from.


Source link

The post Spider-Man 2 has already been discounted ahead of launch appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 02, 2023 22:08

WATCH: California 7-Eleven Workers Beat the Tar Out of Man for Stealing and Threatening to Shoot Them | The Gateway Pundit

Credit: @stillgray Twitter screenshot

Stockton, California- Ordinary citizens on regular basis are being forced to take matters into their own hands to stop brazen robberies in blue states.

The Daily Mail reported Tuesday that two 7-Eleven workers in Stockton, California beat the absolute tar out of a brazen shoplifter who was using a trash can to steal tobacco products.

In a video filmed by a customer earlier on Tuesday, the employees are seen bravely confronting the suspect about why he was stealing so much. The thief threatens to shoot them and continues to scoop up cigarettes, cigars, and vapes into the trash can.

“I’ll pull my strap on your b***h a**,” the suspect says.

The customer then advises the employees to let the man continue to brazenly steal: “just let him go. Ain’t nothing you can do until the police come here.”

The workers decide that taking the initiative and halting the crime themselves is the better option instead.

They come together to restrain the suspect. One can be seen holding the thief down while the other wallops him with a stick.

WATCH:

Part Two:

The customer starts cheering on the employees delivering the epic beatdown.

That’s called whoopin’ your a**! Whoop his a**! Get him!

The robber is hit at least 25 TIMES with the stick. At the end of the beating, he screams for mercy.

Okay, okay! Yeah, I’m done! I’m going to go.

In another video shot by the customer, the thief says he was beaten so badly that he can’t stand up and walk out on his own. The customer convinces the employees to let him lead the thief out of the store but has no patience for the suspect’s whining.

He tells the thief “he better walk tonight” and ignores his cries for a soda as they leave the store.




Source link

The post WATCH: California 7-Eleven Workers Beat the Tar Out of Man for Stealing and Threatening to Shoot Them | The Gateway Pundit appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 02, 2023 21:20

Microsoft comes under blistering criticism for “grossly irresponsible” security

Microsoft has once again come under blistering criticism for the security practices of Azure and its other cloud offerings, with the CEO of security firm Tenable saying Microsoft is “grossly irresponsible” and mired in a “culture of toxic obfuscation.”

The comments from Amit Yoran, chairman and CEO of Tenable, come six days after Sen. Ron Wyden (D-Ore.) blasted Microsoft for what he said were “negligent cybersecurity practices” that enabled hackers backed by the Chinese government to steal hundreds of thousands of emails from cloud customers, including officials in the US Departments of State and Commerce. Microsoft has yet to provide key details about the mysterious breach, which involved the hackers obtaining an extraordinarily powerful encryption key granting access to a variety of its other cloud services. The company has taken pains ever since to obscure its infrastructure’s role in the mass breach.

Critics pile on

On Wednesday, Yoran took to LinkedIn to castigate Microsoft for failing to fix what the company said on Monday was a “critical” issue that gives hackers unauthorized access to data and apps managed by Azure AD, a Microsoft cloud offering for managing user authentication inside large organizations. Monday’s disclosure said that the firm notified Microsoft of the problem in March and that Microsoft reported 16 weeks later that it had been fixed. Tenable researchers told Microsoft that the fix was incomplete. Microsoft set the date for providing a complete fix to September 28.

“To give you an idea of how bad this is, our team very quickly discovered authentication secrets to a bank,” Yoran wrote. “They were so concerned about the seriousness and the ethics of the issue that we immediately notified Microsoft.” He continued:

Advertisement

Did Microsoft quickly fix the issue that could effectively lead to the breach of multiple customers’ networks and services? Of course not. They took more than 90 days to implement a partial fix—and only for new applications loaded in the service.

A Microsoft representative said Microsoft didn’t immediately have a comment in response to Yoran’s post. Responding to Wyden’s letter last week, Microsoft brushed off the criticisms, saying: “This incident demonstrates the evolving challenges of cybersecurity in the face of sophisticated attacks. We continue to work directly with government agencies on this issue, and maintain our commitment to continue sharing information at Microsoft Threat Intelligence blog.”

Tenable is discussing the issue in only general terms to prevent malicious hackers from learning how to actively exploit it in the wild. In an email, company officials said: “There is a vulnerability that provides access to the Azure fabric, at the very least. Once the details of this vulnerability are known, exploitation is relatively trivial. It is for this reason that we are withholding all technical details.” While Yoran’s post and Tenable’s disclosure avoid the word vulnerability, the email said the term is accurate.

The post came on the same day that security firm Sygnia disclosed a set of what it called “vectors” that could be leveraged following a successful breach of an Azure AD Connect account. The vectors allow attackers to intercept credentials via man-in-the-middle attacks or to steal cryptographic hashes of passwords by injecting malicious code into a hash syncing process. Code injection could also allow attackers to gain a persistent presence inside the account with a low probability of being detected.

“The default configuration exposes clients to the described vectors only if privileged access was gained to the AD Connect server,” Ilia Rabinovich, director of adversarial tactics at Sygnia, wrote in an email. “Therefore, a threat actor needs to perform preliminary steps before proceeding with the exploitation process of the vectors.”

Advertisement

Both Tenable and Sygnia said that the security vulnerabilities or vectors they disclosed weren’t related to the recent attack on Microsoft cloud customers.

Serious cybersecurity defects

In last week’s letter to the heads of the Justice Department, Federal Trade Commission, and the Cybersecurity and Infrastructure Security Agency, Wyden accused Microsoft of hiding its role in the 2020 SolarWinds supply chain attack, which Kremlin hackers used to infect 18,000 customers of the network management software. A subset of those customers, including nine federal agencies and 100 organizations, received follow-on attacks that breached their networks.
The senator went on to pin blame on Microsoft for the recent mass breach of the Departments of State and Commerce and the other Azure customers. Specific failings, Wyden said, included Microsoft having “a single skeleton key that, when inevitably stolen, could be used to forge access to different customers’ private communications.” He also faulted Microsoft for waiting five years to refresh the signing key abused in the attacks, saying best practices are to rotate keys more frequently. He also criticized the company for allowing authentication tokens signed by an expired key, as was the case in the attack.

“While Microsoft’s engineers should never have deployed systems that violated such basic cybersecurity principles, these obvious flaws should have been caught by Microsoft’s internal and external security audits,” Wyden wrote. “That these flaws were not detected raises questions about what other serious cybersecurity defects these auditors also missed.”

In Wednesday’s post, Yoran voiced largely the same criticisms.

“What you hear from Microsoft is ‘just trust us,’ but what you get back is very little transparency and a culture of toxic obfuscation,” he wrote. “How can a CISO, board of directors or executive team believe that Microsoft will do the right thing given the fact patterns and current behaviors? Microsoft’s track record puts us all at risk. And it’s even worse than we thought.”


Source link

The post Microsoft comes under blistering criticism for “grossly irresponsible” security appeared first on Harmony Evans.

 •  0 comments  •  flag
Share on Twitter
Published on August 02, 2023 21:14