TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft government email compromised (and quietly fixed)

21 pointsby deckiedanalmost 2 years ago

2 comments

donmcronaldalmost 2 years ago
&gt; They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key.<p>How does that work? Is the key part of some kind of complex auth flow where it&#x27;s only allowed to sign tokens that have Exchange access?<p>A compromised key that can sign authentication tokens seems like a pretty big deal.
评论 #36701159 未加载
nonfamousalmost 2 years ago
Actual title of linked article: &quot;Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email&quot;