BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//orangecon-2024//speaker//JQFF7C
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-orangecon-2024-GMGBGE@pretalx.com
DTSTART;TZID=CET:20240905T143000
DTEND;TZID=CET:20240905T151500
DESCRIPTION:While Microsoft Entra Primary Refresh Tokens remain mostly undo
 cumented\, on Windows there has been quite some research in how they work 
 and how they can be attacked or protected. Despite several hiccups (read: 
 vulnerabilities) in getting there\, the implementation is now mostly secur
 e if you have a Trusted Platform Module (TPM). On other platforms\, the Pr
 imary Refresh Token is also used but its implementation is undocumented. W
 e decided to investigate how Microsoft implemented Primary Refresh Tokens 
 on MacOS\, how they are protected and how hard (or easy) it is for attacke
 rs to steal them. During the investigation\, we encountered more undocumen
 ted protocol features\, leading to the discovery of deviceless Primary Ref
 resh Tokens (PRTs). These deviceless PRTs\, which as the name implies are 
 only tied to a user and not a device. In some environments this might alre
 ady be enough for an attacker to achieve their goal\, since these PRTs cou
 ld be obtained during phishing. \n\nIn this session\, we will talk about t
 he PRT internals\, their protection on MacOS\, and on the current and new 
 PRT implementation Microsoft introduced using the Platform SSO capabilitie
 s.
DTSTAMP:20260718T143849Z
LOCATION:Main track
SUMMARY:Attacking Primary Refresh Tokens using their MacOS implementation -
  Olaf Hartong\, Dirk-jan Mollema
URL:https://pretalx.com/orangecon-2024/talk/GMGBGE/
END:VEVENT
END:VCALENDAR
