Question

Answer

What are "cryptographic keys" and why does stealing them matter?

Cryptographic keys are like master keys that unlock encrypted data and verify the authenticity of digital communications. In SharePoint's case, these keys (called ValidationKey and DecryptionKey) are used to ensure that requests to the server are legitimate. When hackers steal these keys, they can create fake but valid-looking requests that SharePoint will trust and process. It's like someone stealing the master key to your office building and being able to make perfect copies. Even after you change the locks (patch the vulnerability), they can still get in using their copied keys until you replace the entire locking system.

Explore similar FAQs related to this one.

Navigation

The Fixinc website is supported by thorough FAQs and resources. From business continuity services, to technology, blogs and even proposal components, each has a list of useful FAQs. Explore where each FAQ originally came from via the links below.

ITDR

Discover

This FAQ features on our ITDR Advisory Service page.

ITDR advisory services in New Zealand, Australia, Malaysia. By Fixinc
Microsoft SharePoint under mass attack with no patch available

Discover

This FAQ features on one of our resilience blogs covering AI and Cyber. Click here to read the post.

A AI and Cyber, ITDR blog by Fixinc, Microsoft SharePoint under mass attack with no patch available

modernised resilience

Built on experience. Driven by tech. Shaped in your region.

Explore our solutions

Providing 12 Core Services

End-to-end coverage, from business continuity to executive training, and software.

72 Additional Disciplines

Deep, actionable components that make each service stick. Designed to embed resilience.

Trusted Across 25+ Industries

Resilience solutions tailored to public and private sectors, from utilities to aviation and education.

Designed for Real-World Disruptions

Not built for theory. Built for reality. Every solution is shaped by real-world experience.

Get to know Fixinc.
We're family owned, boutique, and local.

Fixinc provides medium to large enterprise in Oceania and ASEAN regions modernised, clean resilience solutions.

Ollie Law and Brad Law, Co-Founders of Fixinc