SDF Chatter
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
hector_titucius [he/him]@hexbear.net to chapotraphouse@hexbear.netEnglish · 2 years ago

🫡🫡🫡Link in description

hexbear.net

message-square
21
fedilink
62

🫡🫡🫡Link in description

hexbear.net

hector_titucius [he/him]@hexbear.net to chapotraphouse@hexbear.netEnglish · 2 years ago
message-square
21
fedilink

https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/

alert-triangle
You must log in or register to comment.
  • blobjim [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    23
    ·
    2 years ago

    This was made possible by a validation error in Microsoft code

    lol microsoft

  • pooh [she/her, love/loves]@hexbear.net
    link
    fedilink
    English
    arrow-up
    19
    ·
    edit-2
    2 years ago

    amerikkka xicko

  • Duży Szef [he/him]@lemmygrad.ml
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 years ago

    :sicko-jammin:

  • Findom_DeLuise [she/her, they/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 years ago

    yes-hahaha-yes-l

    xinternet

  • Starlet [she/her, it/its]@hexbear.net
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 years ago

    deng-salute

  • mustardman [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 years ago

    What can they do with a signing key?

    • hector_titucius [he/him]@hexbear.netOP
      link
      fedilink
      English
      arrow-up
      15
      ·
      edit-2
      2 years ago

      Leak Hillary Clinton Emails

      • FourteenEyes [he/him]@hexbear.net
        link
        fedilink
        English
        arrow-up
        9
        ·
        2 years ago

        delicious buttery mails

    • blobjim [he/him]@hexbear.net
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 years ago

      Pretend to be someone they aren’t

      An actor that can acquire a private signing key can then create falsified tokens with valid signatures that will be accepted by relying parties. This is called token forgery.

      • mustardman [none/use name]@hexbear.net
        link
        fedilink
        English
        arrow-up
        8
        ·
        2 years ago

        Oh cool so they can distribute updates?

        • blobjim [he/him]@hexbear.net
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 years ago

          The article just says they signed authentication tokens which gave them access to outlook emails. I don’t think it was code signing that would let them distribute software, and that’s not what they were after.

          • mustardman [none/use name]@hexbear.net
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 years ago

            Thanks for actually reading the article o7

  • radiofreeval [any]@hexbear.net
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 years ago

    Is that hacker news over telegram?

  • Awoo [she/her]@hexbear.net
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    2 years ago

    I really struggle to believe that a military performing espionage actions is stupid enough to operate without spreading hours of operation in a harder to track way. But maybe they don’t give a shit? Just seems like something you could easily hide.

    EDIT: Question - Why would an inactive microsoft consumer account have the ability to forge tokens for Outlook.com? Would this not limit it to a specific subset of accounts?

    We determined that Storm-0558 was accessing the customer’s Exchange Online data using Outlook Web Access (OWA).

    Ahh yes, this would be one specific customer of microsoft that was targeted. Hopefully the NSA or some shit lmao

    • hector_titucius [he/him]@hexbear.netOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 years ago

      Really makes you think

      • Awoo [she/her]@hexbear.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        2 years ago

        Yeah you can go full conspiracy brain with this if you want to question whether microsoft and the state would collaborate for propaganda. I’m not quite so tinfoil hat but there’s certainly questions.

        • hector_titucius [he/him]@hexbear.netOP
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          Calling everything potential Inter-intel-agency warfare is my favorite new tinfoil one-upmanship move

          • Awoo [she/her]@hexbear.net
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 years ago

            The more things deteriorate the more sus everything everywhere looks.

  • dualmindblade [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 years ago

    I have just skimmed this so maybe it’s answered, but seems the entire thing boils down to:

    Storm-0558 acquired an inactive MSA consumer signing key

    How?

  • babyman [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 years ago

    Removed by mod

  • aby [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    foot authority roof thunder dark apple selection off point trick complete scale grey wave copper any enough part tired sail writing amount growth chain female red place curtain servant sugar smash not way enough flag powder necessary milk doubt adjustment damage payment cruel be he other fertile writing sister edge

  • babyman [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 years ago

    Removed by mod

  • aby [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    mountain mist sweet snow growth cry stem cloud run house all dead example solid toe watch how get whip flat journey noise growth of light request town language low space window last cup dry brother force automatic growth approval who body bee even knot idea rub black male machine blade

  • babyman [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 years ago

    Removed by mod

  • babyman [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 years ago

    Removed by mod

chapotraphouse@hexbear.net

chapotraphouse@hexbear.net

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !chapotraphouse@hexbear.net

Banned? DM Wmill to appeal.

No anti-nautilism posts. See: Eco-fascism Primer

Slop posts go in c/slop. Don’t post low-hanging fruit here.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 782 users / day
  • 1.67K users / week
  • 2.66K users / month
  • 5.25K users / 6 months
  • 30 local subscribers
  • 13.8K subscribers
  • 20.5K Posts
  • 303K Comments
  • Modlog
  • mods:
  • LENINSGHOSTFACEKILLA [he/him]@hexbear.net
  • MiraculousMM [he/him, any]@hexbear.net
  • Nakoichi [they/them]@hexbear.net
  • corgiwithalaptop [any, love/loves]@hexbear.net
  • PorkrollPosadist [he/him, they/them]@hexbear.net
  • ZoomeristLeninist [they/them, she/her]@hexbear.net
  • EmmaGoldman [she/her, comrade/them]@hexbear.net
  • sweet_pecan [love/loves, they/them]@hexbear.net
  • a_little_red_rat [he/him, comrade/them]@hexbear.net
  • khizuo [ze/zir]@hexbear.net
  • gaystyleJoker [she/her]@hexbear.net
  • thelastaxolotl [he/him]@hexbear.net
  • context [fae/faer, fae/faer]@hexbear.net
  • Infamousblt [any]@hexbear.net
  • Sulvy [he/him, comrade/them]@hexbear.net
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org