Teen Hacker Uncovers Authentication Flaw in Microsoft's Titan Analytics Service
A 16-year-old hacker using the alias Faav discovered an authentication flaw in Microsoft's Titan analytics service, which could have allowed unauthorized access to 17.3 trillion stored rows of data.
Faav found that Titan checked several claims in authentication tokens but did not verify the tokens' signatures, allowing an attacker to claim another user's identity when accessing the service.
The API was initially tested by Faav on August 25 using Antares, an AI-powered security research tool he developed. He created an unsigned JWT and changed its upn claim to 'admin', which Titan treated as a local username and assigned the account the Admin role.
Faav reported the issue to Microsoft's Security Response Center (MSRC) on September 5, and Microsoft locked down the affected API on September 9. Faav received a $5,000 bug bounty on September 17.