PrivacyDigest · @PrivacyDigest
570 followers · 2185 posts · Server mas.to

The Comedy of Errors That Let China-Backed Hackers Steal Microsoft’s

After leaving many questions unanswered, explains in a new postmortem the series of slipups that allowed attackers to steal and abuse a valuable key.

wired.com/story/china-backed-h

#China #encryption #security #privacy #cryptographic #Microsoft #signingkey

Last updated 2 years ago

Tech news from Canada · @TechNews
992 followers · 27479 posts · Server mastodon.roitsystems.ca

Ars Technica: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked arstechnica.com/?p=1965985 -0558 &IT

#Tech #arstechnica #it #technology #signingkey #storm #microsoft #security #biz #azure

Last updated 2 years ago

Christoffer S. · @nopatience
1417 followers · 571 posts · Server swecyb.com

Did Microsoft publish more information about the origin of the MSA signing key?

I don't recall having seen any updates after the "original" post from July 11.

#microsoft #signingkey #intrusion #cyberattack

Last updated 2 years ago

PrivacyDigest · @PrivacyDigest
525 followers · 1948 posts · Server mas.to

Signing Key Stolen by - on

Actually, two things went badly wrong here. The first is that accepted an expired signing key, implying a in whatever is supposed to check key validity. The second is that this key was supposed to remain in the the system’s —and not be in software

schneier.com/blog/archives/202

#signingkey #China #privacy #hardwaresecuritymodule #vulnerability #azure #security #schneier #chinese #Microsoft

Last updated 2 years ago