I Could've Accessed 17T Microsoft Records

(blog.faav.net)

64 points | by luispa 1 day ago

11 comments

  • john_strinlai 8 minutes ago
    >Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.

    that is... not great. shame on microsoft.

    its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.

  • sdfhbdf 31 minutes ago
    > awarded $5000

    It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

    On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

    What does HN think? Why would it be only $5000?

    • bix6 1 minute ago
      $5k is a literal penny for Microsoft. Give the kid $100k.
    • muglug 19 minutes ago
      As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".

      Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.

    • Perz1val 8 minutes ago
      Microsoft's bounty program and payouts are known to be pathetic, see that nightmare eclipse situation
  • verst 8 minutes ago
    There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.
  • throwaway2037 7 minutes ago

        > Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.
    
    Damn, these guys got schooled by a 15 year old! Say less...
  • er0k 22 minutes ago
    wow I am so surprised to hear once again how JWTs are terrible

    https://www.howmanydayssinceajwtalgnonevuln.com/

    • fabian2k 10 minutes ago
      Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.
    • Perz1val 5 minutes ago
      Idk if that's not too much of an oversimplification, maybe more like JWTs are an indicator/enabler of architecture level bugs?
  • f311a 49 minutes ago
    What is Antares? Can't find anything related to it except for the 1B model, which does not seem to be capable of autoresearch.

    UPD: It's his personal bot.

    • Alifatisk 13 minutes ago
      > I also started building AI into how I hunt, which led me to develop Antares, my personal AI hackbot.
  • khalic 26 minutes ago
    You’re going places kid :) keep up the good work
    • matroxmemories 21 minutes ago
      Possibly jail if the wrong people get upset.
      • Waterluvian 16 minutes ago
        Great way to use up that 6-10 years of vacation and sabbatical time.
  • Kuyawa 27 minutes ago
    Next time you find a bug like that, offer it to the black market, you could make millions instead of measly salty peanuts
    • sdcfgy 20 minutes ago
      I bet someone already did that and didn't disclose it.
      • arm32 15 minutes ago
        Now some blackhat somewhere can't afford their monthly Lamborghini payment.
  • sdcfgy 20 minutes ago
    Wait until someone does that to your favourite cloud provider's customer data.
  • sophietaylor 1 minute ago
    [flagged]
  • ltbarcly3 54 minutes ago
    > Two quick notes first. The impact I describe is hypothetical. It’s what an attacker could have done with this access, but luckily I found the bug instead, reported it, and never touched any customer data or PII.

    I am the last person to judge someone for using AI to help them write a blog post, but what I wonder is: Do people not read what the AI produces before putting their name on it, or is the AI writing style not obvious to some people, or do they just not care that it's obviously AI and bad style?

    • t-writescode 48 minutes ago
      That.. looks like a normal sentence to me, and very probably one of the ones Microsoft required they add.

      Did you give the article a once-over beyond that? It’s one of the decidedly not-AI lines.

      • 0x_rs 26 minutes ago
        It's not a "normal" sentence and is quite clearly produced by an LLM, it's a typical Claudeism so probably that. The entire post is also flagged by Pangram, so OP is correct.
      • ltbarcly3 45 minutes ago
        Prefixing saying something with "Two quick notes first" is extremely common AI meta commentary. You may be right that it is something Microsoft insisted he put at the top, which would also explain the weird style.
        • functionmouse 31 minutes ago
          From where do you think AI learned that?
          • vonneumannstan 25 minutes ago
            Weird user preferences during RLHF. Also how we got bulleted lists and emojis everywhere.
          • Forgeties79 28 minutes ago
            All AI semantic tendencies were “learned” from us. That doesn’t change anything.
    • gosub100 2 minutes ago
      Explain why easily 40% of HN posts are about AI, and when people actually _use_ AI for this task, they are vilified for (allegedly) using it.