posted in Technology
Microsoft Authenticator Spams Sign-In Requests Without Even Needing Your Password - André Klein Dot Net
andreklein.net/microsoft-authenticator-spams-sign-in-requests-without-even-needing-your-password/posted in Technology
Microsoft Authenticator Spams Sign-In Requests Without Even Needing Your Password - André Klein Dot Net
andreklein.net/microsoft-authenticator-spams-sign-in-requests-without-even-needing-your-password/Replying to @schipelblorp@sh.itjust.works
Man, really wondering why you guys hate information so much.
Replying to @lemmydividebyzero@reddthat.com
Automated time-capsule emails: Once you finally sort out standard TOTP, Microsoft sends you an automated setup email enthusiastically asking if you need help configuring your Zune, BlackBerry, or Office 2010.
🥹
Replying to @lemmydividebyzero@reddthat.com
My MS account is doing a thing lately where I have to enter the TOTP twice to login successfuly. It has to be two different TOTPs, too, can’t enter the same one; I have to literally wait until the first one expires and get another one.
Didn’t experience any of the other shenanigans described in the article though, so there’s that.
Replying to @lemmyvore@feddit.nl
TOTP is time based, I’d check the time on the device just in case. Having to enter multiple codes must be so annoying!
I have the machine synced with NTP and I’m not seeing any time issues.
It’s such a super specific quirk, too, that I can’t believe it’s not on their side.
Maybe they’ve decided that TOTP is less secure than passkeys and if I refuse to use passkeys with their app I should be “helped” 😃 by using twice the amount of TOTP?
Replying to @lemmyvore@feddit.nl
I have a few networks where I get the notice but must disconnect from the wifi to approve over my mobile connection instead
Replying to @lemmydividebyzero@reddthat.com
* Microslop
Replying to @MonkderVierte@lemmy.zip
Micro sloppy penis
Everything about authentication and Microsoft is nightmare fuel. I am sure that noone over there has any idea what is going on, and that is the reason why every new thing from microsoft builds their own - soon to be legacy code anyway - authentication portal and ties it to the existing kowloon walled city of authentication with chewing gum and zip ties.
Replying to @Wildmimic@anarchist.nexus
I recently had to install MS authenticator on my work phone, to do so I needed to use the code from MS authenticator. To bypass that I needed to log on to MS to change access option, which wanted the code from MS authenticator to log in.
Replying to @Wildmimic@anarchist.nexus
Kowloon Walled City (Chinese: 九龍城寨)[a] was an ungoverned and densely populated de jure Chinese enclave within the boundaries of British Hong Kong.
spoilerOriginally a Chinese military fort, it became an enclave after the New Territories were leased to Britain in 1898. The Walled City’s population increased dramatically following World War II, and by 1987 it had an estimated 33,000 residents within its 2.6-hectare (6+1⁄2-acre) borders, making it one of the most densely populated places on Earth at approximately 1.2 million inhabitants per square kilometre (3 million per square mile). The city was demolished between 1993 and 1994; the Kowloon Walled City Park was built in its place and opened in December 1995. en.wikipedia.org/wiki/Kowloon_Walled_City
Replying to @Wildmimic@anarchist.nexus
Try supporting Onedrive for business when Onedrive often fails SSO and people use their work email address to create a personal account because by default Microsoft encourages that unless you aggressively lock that down, and then people will have sensitive work data on an account you can’t control, and if they switch computers it gets worse because if they don’t know that password and the old computer is broken there’s nothing the business can do to get the data.
Oh, and Adobe does the same thing. Neither tell you upfront that you should disable creation of personal accounts using the work email address. The user won’t notice because it doesn’t occur to them to select “organization account” and they just click the first option.
Which is also both a security nightmare and GDPR nightmare.
Replying to @Natanael@infosec.pub
Something like this happened to me and I’m not very well tech versed anymore. But I’ll put it this way, somehow confidential government files (nothing too serious) from 2015 ended up on my computer that I built a few years ago. I honestly I’m still baffled and yes, I used my old email because I was lazy and was going to use this for gaming anyway.
Replying to @lemmydividebyzero@reddthat.com
Happened to me as well and I reacted in exact same way (pulling hair, changing password).
Replying to @lemmydividebyzero@reddthat.com
And sure, you could also create a new alias and migrate your sign-in preference to dodge the spam, but why should I have to restructure my whole frigging identity just because Microsoft can’t properly gate a push notification behind a password check?
Why indeed.
Replying to @lemmydividebyzero@reddthat.com
Microsoft can’t properly gate a push notification behind a password check?
Careful now. If you put the MFA prompt after the password, it works as confirmation that you have the correct password even if you’re not able to log in. You don’t want to give that confirmation to the attacker. That’s why MFA happens before the password is validated.
Replying to @frongt@lemmy.zip
Just set a timer after entering the password in every single case (only stopped early by successful MFA). “authentication did not succeed, one or more factors may be incorrect or may have failed verification”
Replying to @frongt@lemmy.zip
Just require the TOTP at the start of the form. It’s that simple.
Replying to @frongt@lemmy.zip
You don’t want to give that confirmation to the attacker.
That’s how it works on > 90% of the websites on the internet. And that’s usually not a probably, because one usually does not suddenly know the password of other people.
Replying to @lemmydividebyzero@reddthat.com
Use something like Aegis?
Replying to @tordenflesk@lemmy.world
Some disables that option and force Microsoft authenticator.
Replying to @cryptix@discuss.tchncs.de
Really?
Replying to @lemmydividebyzero@reddthat.com
I’m n+1 for this. Lucky me.
Replying to @lemmydividebyzero@reddthat.com
I got hammered with ms auth requests for weeks before I finally just changed it to a dedicated email address. Really frustrating.
Replying to @lemmydividebyzero@reddthat.com
This is why I’ve always preferred to enter the TOTP code myself instead of using the “Approve Sign-In” method.
Also the thing about the Redirect Loops and wacky login forms. Goddamn how come they ain’t fix it yet 😭
Replying to @LiveLM@lemmy.zip
Also the thing about the Redirect Loops and wacky login forms. Goddamn how come they ain’t fix it yet 😭
At this point, it’s tradition that it’s that f*cked up. Can’t change that now…
Replying to @LiveLM@lemmy.zip
Using a lot of ms services at work. If I leave 10 tabs open, I get 10 individual login popups in the morning. I like to assume there is some reason behind this I’m too dumb to understand, because it is very obviously not good UX and very annoying.
Replying to @filcuk@feddit.uk
Token expiry. Because the same login token is used across many services, it expires at the same time. Of course, because the tabs are all open, they just know you need to log in again, not whether you’ve got other services open that also use your account.
Replying to @lemmydividebyzero@reddthat.com
Teams app regularly crashes for me when memory tagging is enforced by graphine OS.
Replying to @cryptix@discuss.tchncs.de
Teams drains like 30% of my phone battery every hour. It’s crap.
I just removed it from my phone and deal with carting my work machine around.
Replying to @lemmydividebyzero@reddthat.com
I disabled t use Microsoft Authenticator, I use passkeys and aegis Authenticator.
You don’t get away from it this way either.
Instead, it manifests as needing to reset your password every, single, time you log in. Because of “too many incorrect sign in attempts”.
The bots can’t do anything bc the account is passwordless. But it doesn’t stop Microsoft’s annoying “security” features.
So I constantly have to reset a password that is never even used.
Replying to @lemmydividebyzero@reddthat.com
“No shit.” -Anyone who has used it for more than a minute.
Replying to @lemmydividebyzero@reddthat.com
Yep. I get an influx of them when I shit talk the diaperpedonazi in charge on certain platforms. Kind of funny.
Replying to @lemmydividebyzero@reddthat.com
Yeah? This has been a thing for years. We were training people at my previous place of work to ignore MFAs that did not originate from an action they took.