5 ms·
CSRB's report on the Exchange Online breach that dropped a couple weeks ago was pretty damning. Microsoft had a situation where a threat actor had access to the
by helpfulclippy 2y ago
CSRB's report on the Exchange Online breach that dropped a couple weeks ago was pretty damning. Microsoft had a situation where a threat actor had access to the entirety of Exchange Online, and possibly their entire cloud. CSRB describes the entire incident as completely avoidable, and resulting from Microsoft's inadequate security culture, and it calls Microsoft out for making public statements about the breach and its response that it knew to be inaccurate.
The ONLY way that breach got detected was because the State department bought the premium package with extra logging that let them see when mailboxes get opened. It turned out, Microsoft had a signing key that could create access tokens for anything in their cloud, and it was stolen by Storm-0558. (More precisely, the key was only supposed to be useful for a portion of their services, but a bug allowed Storm-0558 to bypass that scope limitation.) And they used that to go read the e-mails of the State department and a bunch of other organizations, and private individuals. There was nothing customers could do to prevent the attack, and apparently no other indication in their logs that it was taking place, besides this category of entry that was gatekept behind a premium subscription package.
Microsoft generated the key in 2016 and discontinued it years prior to the incident, but it was never revoked. Microsoft didn't even bother with key rotations anymore after 2021 because one time they fucked it up and it caused an outage, so they decided to just not do that anymore. Also, Microsoft apparently didn't have any means of detecting the obvious use of a zombie key.
Also, Microsoft still doesn't really know how they got the key. They made a blog post about their theory, representing it as something they were highly confident in based on the evidence. After 6 months of pressure from the government, Microsoft finally updated the post to admit that they had no evidence of critical parts of what they claimed, and several key points in their narrative were factually incorrect.
Then earlier this year, Microsoft got hacked AGAIN because they had an unused-but-active test account with a guessable password and no MFA, and it was authorized for access to e-mail boxes of (at a minimum) numerous members of Microsoft senior leadership.
Microsoft has got serious problems.
edit: I keep futzing with my phrasing. Those wanting a much better account should just read the report, since it has a great deal more nuance and information.
https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review_of_the_Summer_2023_MEO_Intrusion_Final_508c.pdf https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review...
- quantified 2y ago> Microsoft didn't even bother with key rotations anymore after 2021 because one time they fucked it up and it caused an outage, so they decided to just not do that anymore. Key rotation is almost like restoring from backups. It's an absolutely necessary capability and practice.
- krooj 2y agoYou'd be surprised at how little cloud vendors give a shit about security internally. Story time: I recently went ahead and implemented key rotation for one of our authz services, since it had none, and was reprimanded for "not implementing it like Google". Fun fact: Google's jwks.json endpoint claims to be "certs" from the path (https://www.googleapis.com/oauth2/v3/certs https://www.googleapis.com/oauth2/v3/certs). They are not certs - there is no X.509 wrapper, no stated expiration, no trust hierarchy. Clients are effectively blind when performing token validation with this endpoint, and it's really shitty. Other nonsense I've seen: leaking internally signed tokens for external use (front-channel), JWTs being validated without a kid claim in the header - so there's some sketchy coupling going on, skipping audience validation, etc... Not much surprises me anymore when it comes to this kinda stuff - internally, I suspect most cloud providers operate like "feature factories" and security is treated as a CYA/least-concern thing. Try pushing for proper authz infrastructure inside your company and see what kinda support you'll get.
- ajmurmann 2y agoAre there any large companies that don't operate like feature factories? It seems to be such a common issue and the natural result of the incentive structure.
- mistrial9 2y agoalthough this is a valid insight, it reduces the detail of the conversation into "yes or no" on a topic that is not a "yes or no" topic.. it is behavior and messaging among a dozen critical functions of business. Almost every business is different in their mix.. perhaps faced with similar rhetoric, law says "show me an example then we can discuss" instead of "classify all examples then apply to a situation"