home.social

#signingkey — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #signingkey, aggregated by home.social.

  1. Beim letzten SRE Meetup gab es einen Vortrag über Post Mortems und deren Wichtigkeit.

    Bester Kommentar aus dem Publikum beim Thema Post Mortem und öffentliche Transparenz: Ist jemand von Microsoft da?

    #microsoft #signingkey

  2. The Comedy of Errors That Let China-Backed Hackers Steal Microsoft’s #SigningKey

    After leaving many questions unanswered, #Microsoft explains in a new postmortem the series of slipups that allowed attackers to steal and abuse a valuable #cryptographic key.
    #privacy #security #encryption #china

    wired.com/story/china-backed-h

  3. Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.

    How can you believe anything they say months later? This blogpost was written by lawyers and noone else.

    #signingkey #microsoft #storm0558 #ms #m365 #infosec

  4. Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.

    How can you believe anything they say months later? This blogpost was written by lawyers and noone else.

    #signingkey #microsoft #storm0558 #ms #m365 #infosec

  5. Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.

    How can you believe anything they say months later? This blogpost was written by lawyers and noone else.

    #signingkey #microsoft #storm0558 #ms #m365 #infosec

  6. Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.

    How can you believe anything they say months later? This blogpost was written by lawyers and noone else.

    #signingkey #microsoft #storm0558 #ms #m365 #infosec

  7. Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.

    How can you believe anything they say months later? This blogpost was written by lawyers and noone else.

    #signingkey #microsoft #storm0558 #ms #m365 #infosec

  8. Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!

    msrc.microsoft.com/blog/2023/0

    #ms #microsoft #Storm0558 #signingkey

  9. Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!

    msrc.microsoft.com/blog/2023/0

    #ms #microsoft #Storm0558 #signingkey

  10. Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!

    msrc.microsoft.com/blog/2023/0

    #ms #microsoft #Storm0558 #signingkey

  11. Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!

    msrc.microsoft.com/blog/2023/0

    #ms #microsoft #Storm0558 #signingkey

  12. Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!

    msrc.microsoft.com/blog/2023/0

    #ms #microsoft #Storm0558 #signingkey

  13. Good to know:
    1️⃣ Without the US government, we probably wouldn't know about the #Microsoft #SigningKey #Leak at all.
    2️⃣ The report ⬆️ seems to be accurate
    3️⃣ Apparently, the only piece missing from the report is that the Signing Key had expired in 2021 and that the expiration time wasn't (still isn't?) checked.
    cyberplace.social/@GossiTheDog

  14. Microsoft finally explains cause of Azure breach: An engineer’s account was hacked - Enlarge (credit: Getty Images)

    Microsoft said the corporate ac... - arstechnica.com/?p=1965985 #signingkey #storm-0558 #microsoft #security #biz#azure

  15. Habt Ihr von dem entwendeten #SigningKey von #Microsoft gehört? Wir haben das einmal (halbwegs ;-) verständlich zusammengefasst. Ein bisschen IT-Verständnis braucht man schon...

    Der entscheidende Satz aus meiner Sicht:
    "Der entwendete Signing Key ist für alle #Azure #ActiveDirectory Applikationen gültig, die sowohl persönliche Microsoft Accounts als auch sogenannte gemischte Accounts (sprich: persönliche Konten und Konten in Organisationsverzeichnissen) nutzen."
    1/2

    agilimo.de/microsoft-signing-k

  16. #Microsoft Signing Key Stolen by #Chinese - #Schneier on #Security

    Actually, two things went badly wrong here. The first is that #Azure accepted an expired signing key, implying a #vulnerability in whatever is supposed to check key validity. The second is that this key was supposed to remain in the the system’s #HardwareSecurityModule —and not be in software
    #privacy #China #signingkey

    schneier.com/blog/archives/202