TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft Warns That a Chinese Cyberattack Breached Government Email Accounts

16 pointsby realshadowalmost 2 years ago

2 comments

jsnellalmost 2 years ago
The quote in the article about what happened seems muddled. But even going to the original source [0], I don&#x27;t think I understand what happened. Some of it might be because terminology differences, some because this seems to be written mainly for ass-covering. Does anyone know any more details?<p>&gt; They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key<p>Is this saying that the attackers got Microsoft&#x27;s cookie signing private key? I don&#x27;t know how else to interpret it, but &quot;acquiring&quot; sure ain&#x27;t the language you use for that level of breach. And <i>how</i> was the key &quot;acquired&quot;? From a security vulnerability in their production systems? Breach of their corp network?<p>&gt; The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail.<p>So not only did they leak the private key, but their validation code was also broken and checked the signatures against the wrong key? How does that even happen?<p>[0] <a href="https:&#x2F;&#x2F;msrc.microsoft.com&#x2F;blog&#x2F;2023&#x2F;07&#x2F;microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;msrc.microsoft.com&#x2F;blog&#x2F;2023&#x2F;07&#x2F;microsoft-mitigates-...</a>
评论 #36776277 未加载
JoeAltmaieralmost 2 years ago
I&#x27;m astonished that Chinese cyberattacks don&#x27;t warrant some kind of shutdown between the Chinese internet and the rest of the word (or NATO anyway).<p>Devastating to commerce? Sure! For a day or so. Then the Chinese cyberattacks would cease and we could go back to normal.<p>How could you tell? Well, there are countless websites that purport to graph such things realtime. Ask one of them to monitor the situation. It goes above a trivial threshold - the pipe is shut off for a day.<p>But that&#x27;s just a naieve citizen, wondering why government is so screwed up that it allows constant unrelenting financial attacks against its people without repercussions.
评论 #36698520 未加载