4 ms·
The writeup by Microsoft is far more illustrative than the frankly confusing post and blog from the main article: https://www.microsoft.com/en-us/security/blog/
by epups 3y ago
The writeup by Microsoft is far more illustrative than the frankly confusing post and blog from the main article: https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/ https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...
Also, unlike what (I think) is being claimed here, Microsoft did fix the issue after learning about it: https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...
- tgv 3y agoA lot later. The damage was done. Whoever had those keys could have had access to all MS accounts and services. And those people had already hacked an engineer's account. Because the chances of stumbling upon this key when only hacking one engineering account are very low, it's reasonable to assume many MS engineering accounts had already been hacked. Basically, your MS account is not safe.
- mjburgess 3y ago> many MS engineering accounts had already been hacked This isnt being focused on enough here. MS is set up in such a way that there are individual members of staff, with individual devices, that just need to be compromised for all their infrastructure is compromised. This fact alone means that's its near certainly presently compromised. states have the resources to place an engineer at MS, let alone compromise one of their devices. This, critically, is not necessary. There is nothing technologically necessary about one person, or one device, having the keys to the kingdom. It's security malpractice.
- epups 3y agoMicrosoft knows which accounts were targeted by the attacker. They say so in the first link: "Our telemetry and investigations indicate that post-compromise activity was limited to email access and exfiltration for targeted users." Therefore, no, it is hyperbole that this attack means any and all MS data is compromised. The key that was compromised from one MS engineer was used in conjunction with a specific bug - crash dumps were including secret keys, accessible on a debug environment -, this is not how the system is intended to work at all and they implemented measures to fix it. So this is another hyperbole from the original post.
- mjburgess 3y agovia the state department, they know which emails in outlook for the state dept were compromised by their access patterns. That's the access patterns of a single application for a single user. They know absolutely nothing about what's happened to their infrastructure.
- epups 3y agoIf you would read the first link, you would see that what you're claiming is unsubstantiated. They could track it to a great level of detail because they identified the threat vector and patched it quickly.