luispa · 100 points · 48 comments · yesterday · Open original
Comments
5 preview comments · loading full thread
Log in to use comments
Log in to h4cker, then connect Hacker News to publish comments.
JOjohn_strinlai58 minutes ago
>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
SDsdfhbdf1 hour ago
> awarded $5000
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
VEverst58 minutes ago
There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.
THthrowaway203757 minutes ago
> Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.
Damn, these guys got schooled by a 15 year old! Say less...
RDrdtsc42 minutes ago
> {"alg":"none","typ":"JWT"}
I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.
Comments
5 preview comments · loading full threadLog in to h4cker, then connect Hacker News to publish comments.
>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication. that is... not great. shame on microsoft. its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
> awarded $5000 It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low. On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under. What does HN think? Why would it be only $5000?
There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.
> Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger. Damn, these guys got schooled by a 15 year old! Say less...
> {"alg":"none","typ":"JWT"} I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.