CISOOnline

Scattered Spider case raises Microsoft privacy and transparency concerns

Lupton continues: “It is also possible that Microsoft did not hold a complete browsing history. Investigators could instead have correlated Microsoft device, timestamp, and IP records with separate records obtained from ngrok and Tzulo. This is not clear from the wording of the complaint.”

If the records came from Edge, SmartScreen, Defender, Microsoft account services, crash reporting, or another Microsoft component, the privacy and legal implications raised around GDID change from persistent retention of activity associated with an individual user to those that arise from correlating disparate sources of information.

“If Microsoft merely had timestamps, IP addresses, device identifiers, or security telemetry that prosecutors later correlated with ngrok and Tzulo logs, that is different from Microsoft retaining browsing history,” according to Varghese. “The complaint language is too thin to answer that confidently.”



Source link