|
|
|
|
|
by donmcronald
2175 days ago
|
|
Yeah. It seems low to me. The team writing the auth code is probably paid a fortune comparatively. It’s also surprising to see MS has mistakes like that in the auth flow. I know it’s a combo, but still, damn! I don’t know enough about dev.azure.com, but if they could do more than read info, like spin up VMs, then $3k is an insulting joke. Doubly so if there are credit cards attached to those accounts. The idea of someone spinning up resources on my Azure account gives me nightmares. It’s also worth noting the combo here is really nasty because DNS takeover means you could send phishing emails from a legit sub domain. What’s the damage to MS if someone nefarious had found that and launched a huge phishing campaign? |
|