TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Compromised Microsoft key: More impactful than we thought

290 pointsby 882542F3884314Balmost 2 years ago

15 comments

userbinatoralmost 2 years ago
<i>Identity provider’s signing keys are probably the most powerful secrets in the modern world. For example, they are much more powerful than TLS keys.</i><p>They are in many ways equivalent to certificate authoritities&#x27; keys.<p><i>Organizations using Microsoft and Azure services should take steps to assess potential impact.</i><p>People don&#x27;t seem to know that old saying about not putting all your eggs in one basket anymore.
评论 #36823911 未加载
评论 #36823733 未加载
评论 #36823412 未加载
评论 #36824582 未加载
评论 #36823657 未加载
joluxalmost 2 years ago
<i>Our researchers concluded that the compromised MSA key could have allowed the threat actor to forge access tokens for multiple types of Azure Active Directory applications, including every application that supports personal account authentication, such as SharePoint, Teams, OneDrive, customers’ applications that support the “login with Microsoft” functionality, and multi-tenant applications in certain conditions.</i><p>I hope it is just a coincidence that Microsoft recently renamed Azure AD to “Entra ID:” <a href="https:&#x2F;&#x2F;devblogs.microsoft.com&#x2F;identity&#x2F;aad-rebrand&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;devblogs.microsoft.com&#x2F;identity&#x2F;aad-rebrand&#x2F;</a>
评论 #36825642 未加载
insomniacityalmost 2 years ago
&gt; The old public key’s certificate revealed it was issued on April 5th, 2016, and expired on April 4th, 2021, and its thumbprint matched the thumbprint of the key Microsoft listed in their latest blog post, named “Thumbprint of acquired signing key”<p>Am I reading this right? The key was expired? And still in use??
评论 #36826505 未加载
评论 #36826369 未加载
jsiepkesalmost 2 years ago
I highly doubt this key was on a HSM. I keep being amazed by news about keys being stolen which seemingly should have been on a HSM.
评论 #36823480 未加载
评论 #36823447 未加载
评论 #36823474 未加载
评论 #36823379 未加载
kilolimaalmost 2 years ago
Should we just legalize the FAANGs to engage in cyber warfare&#x2F;espionage against each other? Seems like then they would have to reach a minimum of best security practice instead of relying on obscurity.
评论 #36825619 未加载
评论 #36824713 未加载
berkle4455almost 2 years ago
Satya gonna have to say “AI” so many more times during this next earnings call to cover up this mess.
评论 #36824590 未加载
ocdtrekkiealmost 2 years ago
It&#x27;s hard to imagine many worse compromises than a foreign power getting into the email account of our representative to that power. I hope the US government is seriously rethinking the initiatives it&#x27;s undertaken to move computing to major cloud providers.
neilvalmost 2 years ago
&gt; <i>Finally, we want to thank the Microsoft team for working closely with us on this blog and helping us ensure it is technically accurate.</i><p>How was it decided to release this news on a Friday?
评论 #36855713 未加载
high_5almost 2 years ago
&gt; The full impact of this incident is much larger than we Initially understood it to be. We believe this event will have long lasting implications on our trust of the cloud and the core components that support it, above all, the identity layer which is the basic fabric of everything we do in cloud. We must learn from it and improve.<p>How about not putting everything in the cloud for starters. And I think the whole problem is not even the cloud. It&#x27;s the broken capitalistic economy that in the and always begets monopolies or at least a cartel of a few big companies. Because for the long tail of small businesses it does not make sense to use products and services from the big guys. So, giving more power to the market winners ends up in too-big-to-fail companies. Yet, these big companies only have to make one mistake, one slip up, and the target surface is just too big. It&#x27;s not a question if, but when such incidents will happen. Only federated services are the answer for the long term survival of society, sacrificing a part of convenience.
评论 #36824788 未加载
JOnAgainalmost 2 years ago
Great write up. Scary. But very digestible for a complex subject area.
bsuvcalmost 2 years ago
&gt; customers’ applications that support the “login with Microsoft” functionality<p>That&#x27;s a lot of corporate line-of-business applications though, right?<p>And it could end up being the worst part of this hack.
评论 #36825964 未加载
TheRealDunkirkalmost 2 years ago
And there&#x27;s the other shoe. Every major security incident is <i>always</i> worse than initially reported. This one probably has more gas in the tank yet.
almost_usualalmost 2 years ago
Right in time for Microsoft to announce its edge security product..
_a_a_a_almost 2 years ago
&quot;more impactful&quot; = worse?
atemerevalmost 2 years ago
The Chinese: “wow, we actually can do this?”