Dr. Nestori Syynimaa Profile picture
Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Jul 10, 2022 6 tweets 3 min read
Okay, I just read JDs "scientific" paper.
TL;DR "CitizenLab has not shared all evidence publicly, so their research is fake."

According to JD, one needs to be at least a PhD student to be able to "asses" his research. So here we go. The paper contains a lot of claims without any backing evidence. For instance, in "Author Overview":
Apr 5, 2022 4 tweets 2 min read
This @Secureworks report reveals various APIs that allowed unauthorized access to internal information of any Azure AD tenant.

1/4

secureworks.com/research/azure… Image Most are now fixed, but two issues still exists.

First, you can query directory synchronisation status of any Azure AD tenant. This cannot be prevented, but keeping your synchronisation healthy keeps at least error messages away from others.

2/4