logoalt Hacker News

I Could've Accessed 17T Microsoft Records

171 points • by luispa • last Monday at 8:32 PM • 77 comments • view on HN

Comments

john_strinlai • today at 4:07 PM

>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.

that is... not great. shame on microsoft.

its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.

➕ show 2 replies
sdfhbdf • today at 3:44 PM

> awarded $5000

It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

What does HN think? Why would it be only $5000?

➕ show 6 replies
verst • today at 4:07 PM

There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.

➕ show 1 reply
throwaway2037 • today at 4:08 PM

    > Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.
Damn, these guys got schooled by a 15 year old! Say less...
➕ show 1 reply
rdtsc • today at 4:23 PM

> {"alg":"none","typ":"JWT"}

I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.

➕ show 2 replies
er0k • today at 3:53 PM

wow I am so surprised to hear once again how JWTs are terrible

https://www.howmanydayssinceajwtalgnonevuln.com/

➕ show 4 replies
f311a • today at 3:26 PM

What is Antares? Can't find anything related to it except for the 1B model, which does not seem to be capable of autoresearch.

UPD: It's his personal bot.

➕ show 1 reply
khalic • today at 3:49 PM

You’re going places kid :) keep up the good work

➕ show 1 reply
moat • today at 5:49 PM

This kid is 16?

Can’t wait to see what he’s up to in 10 years.

starkeeper • today at 6:42 PM

Only $5K when you saved them millions. Pretty cheap!

gnarlouse • today at 5:13 PM

If a 15yo can find it

sdcfgy • today at 3:55 PM

Wait until someone does that to your favourite cloud provider's customer data.

advael • today at 5:24 PM

This is a pretty typical example of the security posture of microsoft, and yet people continually buy their arguments that open-source and therefore auditable alternatives are inherently less secure than their "trust me bro"

Kuyawa • today at 3:48 PM

Next time you find a bug like that, offer it to the black market, you could make millions instead of measly salty peanuts

➕ show 1 reply
nenadg • today at 5:02 PM

You should have.

huflungdung • today at 7:00 PM

[dead]

sophietaylor • today at 4:14 PM

[flagged]

ltbarcly3 • today at 3:21 PM

> Two quick notes first. The impact I describe is hypothetical. It’s what an attacker could have done with this access, but luckily I found the bug instead, reported it, and never touched any customer data or PII.

I am the last person to judge someone for using AI to help them write a blog post, but what I wonder is: Do people not read what the AI produces before putting their name on it, or is the AI writing style not obvious to some people, or do they just not care that it's obviously AI and bad style?

➕ show 3 replies