> They were able to implant #backdoors, self-made keys, ... all over the place.
I mean, emphasis on able to, as in "in theory, based on what I know, it is POSSIBLE", not that they did.
> If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get rid of the intruders. Everything authenticated by Microsoft is tainted. Even #Windows auth.
Microsoft's response also seems to clearly state that they have rotated the keys, moved them to a more secure storage, etc. They don't say they've removed the attackers, I guess, but they certainly don't indicate that the attack is ongoing. Certainly they don't indicate that all auth is forever broken.
I feel like the conclusions being drawn are extreme.
https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...