BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//talk//MMAHS
 M
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250924T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Let It Sync In - Dylan Bradley
DTSTART;TZID=Australia/Sydney:20260924T143000
DTEND;TZID=Australia/Sydney:20260924T145500
DTSTAMP:20260727T185503Z
UID:pretalx-bsides-canberra-2026-MMAHSM@cfp.bsidescbr.com.au
DESCRIPTION:In this talk\, I'll present my research into the internals of 
 the Microsoft Edge Sync Service\, examining how the platform authenticates
  users\, protects synchronized data\, and exposes functionality through it
 s backend APIs. We'll begin by exploring Family of Client ID (FOCI) tokens
 \, how they fit into Microsoft's authentication ecosystem\, and why they p
 lay a critical role in Edge Sync.\n\nFrom there\, we'll dive into the Edge
  Sync APIs themselves\, demonstrating how FOCI tokens can be leveraged to 
 interact directly with synchronization endpoints. We'll examine the struct
 ure of synchronized data\, the cryptographic protections applied to it\, a
 nd the mechanisms used to store and transmit sensitive information.\n\nBui
 lding on this foundation\, I'll demonstrate how synchronization functional
 ity can be abused to extract sensitive data including saved passwords\, hi
 story and other sync data from a victim's Edge profile. \n\nFinally\, I'll
  reveal a novel technique that leverages the Edge Sync Service to transfor
 m a FOCI token into a fully authenticated user session through the acquisi
 tion of ESTSAUTH cookies\, currently the ONLY known method of performing t
 his type of token-to-session conversion.\n\nAttendees will leave with a de
 ep understanding of Microsoft Edge Sync's architecture\, authentication mo
 del\, data protection mechanisms\, and associated attack surface. Defender
 s will gain practical guidance for identifying\, detecting\, and mitigatin
 g these techniques within Microsoft 365 environments.
LOCATION:Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MMAHSM/
END:VEVENT
END:VCALENDAR
