How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach.

242 points•luispa•2 days ago•107 comments•

107 comments

john_strinlaiabout 9 hours ago
>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.

that is... not great. shame on microsoft.

its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.

rkagererabout 8 hours ago
Love to hear more on the motivation for agreeing to this.

e.g. The $5000? Amnesty from being sued?

menomatterabout 5 hours ago
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed. I wonder what’s the consensus on this? Do people normally report it or not?

On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.

srdjanrabout 8 hours ago
Also he's 16. I'd definitely be less willing to push back (especially on something like this) at his age
icantevenholdabout 8 hours ago
Not getting your life ruined by getting sued by a trillion dollar company sounds like a pretty good motivation
john_strinlaiabout 6 hours ago
i think the answer is simple: they're a kid, and microsoft bullied them.
igleriaabout 8 hours ago
reminds me of a former job in which my goodbye letter was heavily editorialized...
the__alchemistabout 7 hours ago
Would love to hear more.
sdfhbdfabout 9 hours ago
> awarded $5000

It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

What does HN think? Why would it be only $5000?

omoikaneabout 6 hours ago
Every HN post regarding security exploits inevitably results in some comment saying the bounty is too low. I find it helpful to read previous comments by tptacek regarding bug bounties and market values:

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

This one probably has the best summary:

https://news.ycombinator.com/item?id=43025038

elmer2about 6 hours ago
This is correct. I've made well over six figures over the last couple of years through bug bounty programs. I wouldn't spend months finding one bug. It's usually days or a week or two max.

$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.

AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.

Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.

muglugabout 9 hours ago
As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".

Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.

buckle8017about 8 hours ago
Try 10-20 million USD for a zero click iPhone exploit.
yieldcrvabout 7 hours ago
thats the true market value of bug bounty awards

the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability

TeMPOraLabout 7 hours ago
I think HN, like a lot of people in this industry, have strongly skewed perception of the actual importance of these bugs.

You could view the bounty prices as market evidence that most of this is rightfully treated as nothingburgers. I.e. the alternative to paying $5000 to some random person for this class of vulnerability research is not risking a trillion dollar hack the next day - it's just risking shmaybe some kerfuffle down the line, followed by fixing it through normal triage process. The bounty program is as much marketing as security, and $5000 is probably about the right price for marginal effort into sustaining the "we are treating security seriously" message.

In a way, the very existence of those bug bounty programs in large companies is evidence they don't see a reason to treat vulnerabilities seriously enough to proactively find and fix them in-house.

If security vulnerabilities would be anywhere serious as most commenters on-line seem to think, companies would pay hundreds of thousands for serious vulnerabilities, just to save a day before they get hit by them - on top of spending millions in-house to try and stay ahead of the attackers.

But they don't. Because most exploits are inconsequential and/or aren't being exploited much.

giancarlostoroabout 7 hours ago
What's worse is the alternative is winding up like Aaron Swartz... (all he did was scrape PDFs for mostly public funded / tax funded papers) Which is even worse, I think I'd be glad to receive $20 for Starbucks instead of being legally chased for showing them they messed up.

There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.

elmer2about 6 hours ago
"all he did was scrape PDFs for mostly public funded / tax funded papers"

He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.

We shouldn't support theft and he should have gotten some jail time/punishment for it.

"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."

Too many 'security researchers' demand money or threaten to release the vulnerabilities.

I don't know anyone that got into trouble going through a legit bug bounty program.

bix6about 8 hours ago
$5k is a literal penny for Microsoft. Give the kid $100k.
k2xlabout 8 hours ago
Per their market cap...

3.85 billion is actually closer to a "penny" for Microsoft.

throwaway2037about 8 hours ago

    > Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.
Damn, these guys got schooled by a 15 year old! Say less...
bsoqkabout 8 hours ago
You assume that whoever was responsible for the implementation of this feature cares in the slightest beyond “it seems to work”.
lurk2about 7 hours ago
His comment didn’t assume that at all.
ocdtrekkieabout 7 hours ago
Physical security vendors usually stop exactly there. I can't count how many vendors responsible for badge systems shut off the Windows Firewall just because it’s easier than adding a rule.
ToucanLoucanabout 7 hours ago
Honestly that series of blog posts that came across here semi-recently about what an utter disaster the Azure team is (through little fault of their own, mind you), combined with a lot of things I've read about the development behind Halo Infinite, have convinced me Microsoft is to avoided whenever possible. It's not even that they're too big to care, though that is an issue. It's that organizationally they are SO reliant on short-term contractors and junior devs plugging away with copilot, along with an ever more exhausted group of seniors who actually work for them but are continually disempowered, that I think it's safe to say anything they manage to ship is a minor miracle if it works at all, and it's certainly not going to have any guarantee at all of solid software engineering fundamentals.

And to be clear, this is not an issue with them using contractors, overseas or otherwise, or with their senior dev staff, or even with AI really. It's an issue with them organizationally being so incredibly penny-pinching, and so dedicated to shipping new shit versus fixing anything long term, constantly chasing new revenue and letting their existing offerings rot.

If a Microsoft product is good nowadays, it is literally a miracle.

TeMPOraLabout 7 hours ago
You assume there is any actual reason to care more than that in this case.
verstabout 9 hours ago
There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.
jhfdbkofdchkabout 8 hours ago
There is so much work to do for SFI that is still being ignored. The only way that some of these services will update is by being the target of the red team, security researcher, or threat actor.
verstabout 8 hours ago
And all of that is definitely happening.

That being said, just last night I observed that the identity team is now opening up agent-assisted PRs against individual service team repos to force MISE adoption and upgrade to the latest version and best practices. I think that's a great thing because many individual service teams simply lack the bandwidth or knowledge. Prior to GenAI availability I wasted many cycles on this kind of work. While GenAI made it easier - internal source documentation still does not unambiguously address every use case. So having the identity team drive this now with the help of agent sessions initiated by them is great.

rdtscabout 8 hours ago
> {"alg":"none","typ":"JWT"}

I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.

pixl97about 7 hours ago
Yea, and it was a big issue years ago. I can't believe there is any modern implementation that has it.... or another way to put this is, how old is this damned implementation they are using?
flowerladabout 7 hours ago
It should be retroactively removed the spec, and all implementations should remove the "none" algorithm. It is a huge security hole.

Read the full thread on Hacker News →

Related stories