>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
show comments
sdfhbdf
> awarded $5000
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
> Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.
Damn, these guys got schooled by a 15 year old! Say less...
show comments
verst
There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.
show comments
rdtsc
> {"alg":"none","typ":"JWT"}
I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.
show comments
er0k
wow I am so surprised to hear once again how JWTs are terrible
The kicker... only 5k reward for this is insane. That said probably the attacker didn't need to run as many queries as they did...
09/17/26 - Awarded $5,000
f311a
What is Antares? Can't find anything related to it except for the 1B model, which does not seem to be capable of autoresearch.
UPD: It's his personal bot.
show comments
darepublic
> I’m 16 now, and this one is a little bigger.
Holy! Child prodigy
khalic
You’re going places kid :) keep up the good work
show comments
moat
This kid is 16?
Can’t wait to see what he’s up to in 10 years.
charcircuit
Seriously, who is responsible for "none" JWT tokens. It has caused so many critical security bugs over the years.
advael
This is a pretty typical example of the security posture of microsoft, and yet people continually buy their arguments that open-source and therefore auditable alternatives are inherently less secure than their "trust me bro"
sdcfgy
Wait until someone does that to your favourite cloud provider's customer data.
show comments
froggertoaster
Geohot vibes
gnarlouse
If a 15yo can find it
starkeeper
Only $5K when you saved them millions. Pretty cheap!
nenadg
You should have.
Kuyawa
Next time you find a bug like that, offer it to the black market, you could make millions instead of measly salty peanuts
>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
> awarded $5000
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.
> {"alg":"none","typ":"JWT"}
I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.
wow I am so surprised to hear once again how JWTs are terrible
https://www.howmanydayssinceajwtalgnonevuln.com/
The kicker... only 5k reward for this is insane. That said probably the attacker didn't need to run as many queries as they did...
09/17/26 - Awarded $5,000
What is Antares? Can't find anything related to it except for the 1B model, which does not seem to be capable of autoresearch.
UPD: It's his personal bot.
> I’m 16 now, and this one is a little bigger.
Holy! Child prodigy
You’re going places kid :) keep up the good work
This kid is 16?
Can’t wait to see what he’s up to in 10 years.
Seriously, who is responsible for "none" JWT tokens. It has caused so many critical security bugs over the years.
This is a pretty typical example of the security posture of microsoft, and yet people continually buy their arguments that open-source and therefore auditable alternatives are inherently less secure than their "trust me bro"
Wait until someone does that to your favourite cloud provider's customer data.
Geohot vibes
If a 15yo can find it
Only $5K when you saved them millions. Pretty cheap!
You should have.
Next time you find a bug like that, offer it to the black market, you could make millions instead of measly salty peanuts