posted in Technology
Microsoft Authenticator Spams Sign-In Requests Without Even Needing Your Password - André Klein Dot Net
andreklein.net/microsoft-authenticator-spams-sign-in-requests-without-even-needing-your-password/posted in Technology
Microsoft Authenticator Spams Sign-In Requests Without Even Needing Your Password - André Klein Dot Net
andreklein.net/microsoft-authenticator-spams-sign-in-requests-without-even-needing-your-password/Everything about authentication and Microsoft is nightmare fuel. I am sure that noone over there has any idea what is going on, and that is the reason why every new thing from microsoft builds their own - soon to be legacy code anyway - authentication portal and ties it to the existing kowloon walled city of authentication with chewing gum and zip ties.
Replying to @schipelblorp@sh.itjust.works
Man, really wondering why you guys hate information so much.
Replying to @Wildmimic@anarchist.nexus
I recently had to install MS authenticator on my work phone, to do so I needed to use the code from MS authenticator. To bypass that I needed to log on to MS to change access option, which wanted the code from MS authenticator to log in.
Replying to @Wildmimic@anarchist.nexus
Kowloon Walled City (Chinese: 九龍城寨)[a] was an ungoverned and densely populated de jure Chinese enclave within the boundaries of British Hong Kong.
spoilerOriginally a Chinese military fort, it became an enclave after the New Territories were leased to Britain in 1898. The Walled City’s population increased dramatically following World War II, and by 1987 it had an estimated 33,000 residents within its 2.6-hectare (6+1⁄2-acre) borders, making it one of the most densely populated places on Earth at approximately 1.2 million inhabitants per square kilometre (3 million per square mile). The city was demolished between 1993 and 1994; the Kowloon Walled City Park was built in its place and opened in December 1995. en.wikipedia.org/wiki/Kowloon_Walled_City
Replying to @Wildmimic@anarchist.nexus
Try supporting Onedrive for business when Onedrive often fails SSO and people use their work email address to create a personal account because by default Microsoft encourages that unless you aggressively lock that down, and then people will have sensitive work data on an account you can’t control, and if they switch computers it gets worse because if they don’t know that password and the old computer is broken there’s nothing the business can do to get the data.
Oh, and Adobe does the same thing. Neither tell you upfront that you should disable creation of personal accounts using the work email address. The user won’t notice because it doesn’t occur to them to select “organization account” and they just click the first option.
Which is also both a security nightmare and GDPR nightmare.
Replying to @Natanael@infosec.pub
Something like this happened to me and I’m not very well tech versed anymore. But I’ll put it this way, somehow confidential government files (nothing too serious) from 2015 ended up on my computer that I built a few years ago. I honestly I’m still baffled and yes, I used my old email because I was lazy and was going to use this for gaming anyway.