Scattered Spider case raises Microsoft privacy and transparency concerns | #cybercrime | #infosec


Lupton continues: “It is also possible that Microsoft did not hold a complete browsing history. Investigators could instead have correlated Microsoft device, timestamp, and IP records with separate records obtained from ngrok and Tzulo. This is not clear from the wording of the complaint.”

If the records came from Edge, SmartScreen, Defender, Microsoft account services, crash reporting, or another Microsoft component, the privacy and legal implications raised around GDID change from persistent retention of activity associated with an individual user to those that arise from correlating disparate sources of information.

“If Microsoft merely had timestamps, IP addresses, device identifiers, or security telemetry that prosecutors later correlated with ngrok and Tzulo logs, that is different from Microsoft retaining browsing history,” according to Varghese. “The complaint language is too thin to answer that confidently.”



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW