Microsoft government email compromised (and quietly fixed)
msrc.microsoft.com
Microsoft government email compromised (and quietly fixed)
1–4 of 4 posts
Re: Microsoft government email compromised (and quietly fixed)
#2How does that work? Is the key part of some kind of complex auth flow where it's only allowed to sign tokens that have Exchange access?
A compromised key that can sign authentication tokens seems like a pretty big deal.
Re: Microsoft government email compromised (and quietly fixed)
#3Re: Microsoft government email compromised (and quietly fixed)
#4> They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key. How does that work? Is the key part of some kind of complex auth flow where it's only allowed to sign tokens that have Exchange access? A compromised key that can sign authentication tokens seems like a pretty big deal.
How can you forge a token? Did they use quantum machinery to retrieve a JWT Private Key? Did they factor RSA keys?
But no, they used a bug/weakness to exchange a token.