How I Could’ve Accessed 17 Trillion Microsoft Records
A missing JWT signature check let a researcher impersonate a local administrator on a Microsoft analytics service and issue SQL queries across 17 connected databases. The researcher says they limited validation to metadata and two one-row Bing samples, and reported the flaw; Microsoft locked down the endpoint on September 9.
The headline’s 17.3-trillion figure is an estimate from database metadata, not a count of records downloaded. It may include historical, duplicated, or derived rows. The write-up also says Microsoft had editorial control and changed sections and figures before publication, which makes its impact framing worth reading with care. The author credits an AI-assisted recon agent for persistent probing, but says a human recognized that the upn claim was being treated as a local username.
The Hacker News discussion raised concerns about Microsoft’s editorial influence and the researcher’s age, bounty, and legal position; commenters disagreed about how safely researchers can disclose vulnerabilities. No single consensus emerged.