US senator blasts Microsoft for “negligent cybersecurity practices”
Full article464 words · extracted from arstechnica.com · click to collapse
Microsoft said an “in-depth analysis” found that the hackers were able to use the Microsoft Account, abbreviated as MSA, key to forge valid Azure AD login tokens. While Microsoft had intended MSA keys to sign only tokens for consumer accounts, the hackers managed to use it to sign tokens for access to Azure AD. The forgery, Microsoft said, “was made possible by a validation error in Microsoft code.”
Wyden called on US Attorney General Merrick B. Garland, Cybersecurity and Infrastructure Security Agency Director Jen Easterly, and Federal Trade Commission Chair Lina Khan to hold Microsoft accountable for the breach. He accused Microsoft of hiding the role it played in the SolarWinds supply chain attack, which Kremlin hackers used to infect 18,000 customers of the Austin, Texas, maker of network management software. A subset of those customers, including nine federal agencies and 100 organizations, received follow-on attacks that breached their networks.
He likened those practices in the SolarWinds case to those that he said led to the more recent breach of the Departments of Commerce and State and the other large customers.
In Thursday’s letter, Wyden wrote:
Even with the limited details that have been made public so far, Microsoft bears significant responsibility for this new incident. First, Microsoft should not have had a single skeleton key that, when inevitably stolen, could be used to forge access to different customers’ private communications. Second, as Microsoft pointed out after the SolarWinds incident, high-value encryption keys should be stored in an HSM, whose sole function is to prevent the theft of encryption keys. But Microsoft’s admission that they have now moved consumer encryption keys to a “hardened key store used for our enterprise systems” raises serious questions about whether Microsoft followed its own security advice and stored such keys in an HSM. Third, the encryption key used in this latest hack was created by Microsoft in 2016, and it expired in 2021. Federal cybersecurity guidelines, industry best practices, and Microsoft’s own recommendations to customers, dictate that encryption keys be refreshed more frequently, for the very reason that they might become compromised. And authentication tokens signed by an expired key should never have been accepted as valid. Finally, while Microsoft’s engineers should never have deployed systems that violated such basic cybersecurity principles, these obvious flaws should have been caught by Microsoft’s internal and external security audits. That these flaws were not detected raises questions about what other serious cybersecurity defects these auditors also missed.
Wyden’s remarks came six days after researchers from security firm Wiz reported that the MSA key acquired by the hackers gave them the ability to forge tokens for multiple types of Azure Active Directory applications. They include all applications that support personal account authentication, such as SharePoint, Teams, OneDrive, and some custom applications.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/07/us-senator-blasts-microsoft-for-negligent-cybersecurity-practices/