> Since the pseudo code doesn’t I’d bet there are more implementations which trust any key Microsoft has ever published
Bingo, this is the most worrying bit to me. Pasting from a comment I posted earlier:
> Microsoft's own developers failed to implement a secure authentication check on top of their own libraries and infrastructure.
If Microsoft can't use its own identity platform correctly in a flagship Microsoft product (Outlook), what chance does anyone else stand?