I Could've Accessed 17T Microsoft Records(blog.faav.net) |
I Could've Accessed 17T Microsoft Records(blog.faav.net) |
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
e.g. The $5000? Amnesty from being sued?
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.
3.85 billion is actually closer to a "penny" for Microsoft.
That being said, just last night I observed that the identity team is now opening up agent-assisted PRs against individual service team repos to force MISE adoption and upgrade to the latest version and best practices. I think that's a great thing because many individual service teams simply lack the bandwidth or knowledge. Prior to GenAI availability I wasted many cycles on this kind of work. While GenAI made it easier - internal source documentation still does not unambiguously address every use case. So having the identity team drive this now with the help of agent sessions initiated by them is great.
I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.
> Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.
Damn, these guys got schooled by a 15 year old! Say less...Complexity is a spec failure in security issues.
It's that simple.
I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.
The fact that mistakes are so easy to make is indicative of poor design in the spec itself.
UPD: It's his personal bot.
I am the last person to judge someone for using AI to help them write a blog post, but what I wonder is: Do people not read what the AI produces before putting their name on it, or is the AI writing style not obvious to some people, or do they just not care that it's obviously AI and bad style?
Did you give the article a once-over beyond that? It’s one of the decidedly not-AI lines.