jerry,
@jerry@infosec.exchange avatar
SpaceLifeForm,

@jerry

The private key would not have been in a crash dump if the signing was done out-of-band.

Security is hard.

merospit,
@merospit@infosec.exchange avatar

@jerry Moving production dumps (memory or storage) to developer machines is a big risk. Not going to question someone elses reasons for doing it without knowing all of the precautions they had setup, but it isn't something I would want to do everyday.

pauliehedron,
@pauliehedron@infosec.exchange avatar

@jerry Unless I missed it their, production internet connected network is infested with APT? This seems very ominous for the rest of us small peeps.

jerry,
@jerry@infosec.exchange avatar

@pauliehedron we prefer the term “undocumented administrators”

pauliehedron,
@pauliehedron@infosec.exchange avatar

@jerry Volunteer as well. Woof.

secminded,

@jerry but, we haz fireWALLs

kurtseifried,
@kurtseifried@infosec.exchange avatar

@jerry are they not using a hardware security module to hold the key?

“Our investigation found that a consumer signing system crash in April of 2021 resulted in a snapshot of the crashed process (“crash dump”). The crash dumps, which redact sensitive information, should not include the signing key. In this case, a race condition allowed the key to be present in the crash dump (this issue has been corrected). The key material’s presence in the crash dump was not detected by our systems (this issue has been corrected).”

The write up never mentions HSM so I assume not…

Having keys like this on regular systems (even is supposedly secured) is bonkers.

jerry, (edited )
@jerry@infosec.exchange avatar

@kurtseifried a congressperson sent a public letter to the attorney general asking that MS be investigated over the breach, and specifically called out that MS was not following their own guidance to customers regarding the use of HSMs, among other controls

kurtseifried,
@kurtseifried@infosec.exchange avatar

@jerry Wow. I mean..

This is "look both ways before you cross the street" levels of basic infosec.

dustinfinn,
@dustinfinn@infosec.exchange avatar

@jerry

I cannot help.

but notice.

and take away...

infact all I can take away is...

MSFT themselves, does not store enough logs to handle their breaches...

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines