Microsoft still unsure how hackers stole Azure AD signing key
bleepingcomputer.com
bleepingcomputer.com
Depending on what data the CCP was able to obtain from these state agencies, the bribe they paid or the leverage they held over them was probably a bargain.
[1] May 2023: https://www.theguardian.com/technology/2023/may/16/apple-emp...
If your private key is compromised then any access the key provides is also compromised. The main problem here is that the key was able to be used outside of its intended scope and that MS don’t seem to have the systems in place to detect inappropriate key use in a proactive manner
I'm sorry, I thought this was the point of CT... Although I guess it depends on how one defines "proactive" in this context.
https://azure.microsoft.com/en-us/products/azure-dedicated-h...
A very small number of people should have access to their HSMs. This shouldn’t be too hard to figure out.