A 16-year-old researcher publishing under the handle Faav found that Titan, Microsoft's internal data analytics service, would accept an access token that carried no signature at all. With it he reached administrator privileges and the ability to run SQL queries against 17 connected analytics databases holding roughly 17.3 trillion rows.
Microsoft blocked the endpoint four days after the report and paid a 5,000 dollar bounty.
What the token looked like
JSON Web Tokens carry a header that names the algorithm used to sign them. The specification permits the value none, for tokens that are deliberately unprotected because something else in the system guarantees integrity. A token using it ends with a trailing dot where the signature would be, and there is nothing after it.
Faav built exactly that: a header declaring the none algorithm, and in the field that normally holds the user's email address, the string admin. Titan read it and resolved him as a local administrator.
The service was not careless in general. It checked the tenant. It checked the audience. It checked the application identifier. It checked the user identity. What it did not check was whether any of that had been signed by anyone — which is the check that makes the other four mean something. Without it, every field in the token is a claim the attacker wrote.
This bug has been on the checklist since 2015
The none-algorithm bypass is not obscure. It has been the first item in JWT security guidance for a decade, every mature library refuses it by default, and it appears in the introductory module of every web security course that covers tokens.
Which raises the more useful question: not how the bug existed, but where. Titan is internal. Access is restricted to Microsoft employees, and an internal analytics tool is not the system anyone assigns to a penetration test ahead of the products customers pay for.
That is the pattern worth taking from this. The authentication on internal tooling tends to be written once, early, by the team that needed the tool, and then inherited. It is rarely re-reviewed, because nothing about it is customer-facing and nothing about it changes. The data behind it grows for years regardless.
Seventeen trillion rows behind a four-field check
The scale is what makes the finding more than a trivia item. Titan holds employee records, organisational data and Bing analytics. The researcher reports reaching 17 connected databases through the same interface.
One detail says something about how the surface was mapped. He recovered 56 archived table names from a 2023 snapshot of Titan's login pages on the Wayback Machine. A login page from three years ago, preserved by a public archive, was part of the reconnaissance — which is a reminder that taking something down does not take it out of circulation.
The work was done with an AI tool of his own called Antares, which found the Titan API on 25 August. The admin token worked on 5 September, and he reported it the same day.
Microsoft's handling was the good part
The timeline after the report is short. 5 September: reported to the Microsoft Security Response Center. 9 September: the endpoint blocked. 17 September: a 5,000 dollar award.
MSRC also asked him to stop testing and for his IP address, so it could confirm that the activity it saw in its logs was his research and nothing else. That is the correct request, and it is only answerable because the researcher reported rather than continued.
Whether 5,000 dollars is the right price for unauthenticated administrative access to 17 trillion rows of internal data is a separate argument, and a reasonable one to have.
Two sixteen-year-olds in a week
It is worth putting this beside the other teenager in the news this week — the 16-year-old arrested in Alicante as the suspected administrator of the KillSec extortion brand.
Same age, comparable technical reach, entirely different outcome. The difference is not capability. It is that one found a bug and sent an email, and the other ran a leak site. The bounty programme is the thing that makes the first choice available, which is most of the argument for funding them properly.
What to do
- Audit token validation on internal services, not just external ones. The specific test is trivial: send a token with the algorithm set to none and see what happens.
- Reject the none algorithm explicitly rather than relying on a library default. Defaults change, and a library pinned years ago may not have the one you assume.
- Treat the claims in a token as untrusted until the signature is verified. Checking tenant, audience and user before verifying the signature is checking the attacker's own writing.
- Remember that archived copies of your interfaces are public. A login page you replaced in 2023 is still describing your API to anyone who looks.
What is not established
- Whether anyone else found or used the flaw before the report. Microsoft asked for the researcher's IP to check its logs; what it concluded has not been published.
- How long the gap existed in Titan.
- What the 17.3 trillion rows contain in detail, beyond the general categories described.
- Whether other internal Microsoft services share the same validation code.