3 ms·
If this is really an exploit of Microsoft's authentication services, then who knows what all got hacked. More likely, a Treasury IT admin got phished for their
by thinkling 6y ago
If this is really an exploit of Microsoft's authentication services, then who knows what all got hacked. More likely, a Treasury IT admin got phished for their password, no?
And if this is a hack of data hosted on Microsoft Office 365 servers, how does it get detected?
Does Microsoft implement traffic monitoring for high-value clients?
Or do sophisticated organizations embed tracking pixels in emails to see what clients load them, and then check that those are authorized clients?
- bladegash 6y agoYes, I’m quite certain they can/do, as it is a requirement for FedRAMP. However, the US government has their own IDS/IDP that they use for the .gov domain, namely EINSTEIN (and its variants).
- count 6y agoDon't confuse the .gov DNS/email domain and network monitoring tools like Einstein. The brave new world of govt cloud computing use makes this not as straight forward as it might have been 10 years ago.
- bladegash 6y agoThat’s a good point and one I had thought of afterwards. That being said, I have to imagine there is some kind of perimeter established, which cloud providers would exist within (at least the FedRAMP accredited segments). Then again, I have seen crazier things and sometimes government takes quite a while to catch up with technology implementations.