• setVeryLoud(true);@lemmy.ca
    link
    fedilink
    English
    arrow-up
    3
    ·
    15 hours ago

    Yeah? This has been a thing for years. We were training people at my previous place of work to ignore MFAs that did not originate from an action they took.

  • lnxtx (xe/xem/xyr)@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    54
    arrow-down
    1
    ·
    1 day ago

    Automated time-capsule emails: Once you finally sort out standard TOTP, Microsoft sends you an automated setup email enthusiastically asking if you need help configuring your Zune, BlackBerry, or Office 2010.

    🥹

  • Wildmimic@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    30
    ·
    1 day ago

    Everything about authentication and Microsoft is nightmare fuel. I am sure that noone over there has any idea what is going on, and that is the reason why every new thing from microsoft builds their own - soon to be legacy code anyway - authentication portal and ties it to the existing kowloon walled city of authentication with chewing gum and zip ties.

    • ExcessShiv@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      18
      ·
      1 day ago

      I recently had to install MS authenticator on my work phone, to do so I needed to use the code from MS authenticator. To bypass that I needed to log on to MS to change access option, which wanted the code from MS authenticator to log in.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      9
      ·
      1 day ago

      Try supporting Onedrive for business when Onedrive often fails SSO and people use their work email address to create a personal account because by default Microsoft encourages that unless you aggressively lock that down, and then people will have sensitive work data on an account you can’t control, and if they switch computers it gets worse because if they don’t know that password and if the old computer is broken there’s nothing the business can do to get the data.

      Oh, and Adobe does the same thing. Neither tell you upfront that you should disable creation of personal accounts using the work email address/domain. The user won’t notice because it doesn’t occur to them to select “organization account” and they just click the first option.

      Which is also both a security nightmare and GDPR nightmare.

      • myyass@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        14 hours ago

        Something like this happened to me and I’m not very well tech versed anymore. But I’ll put it this way, somehow confidential government files (nothing too serious) from 2015 ended up on my computer that I built a few years ago. I honestly I’m still baffled and yes, I used my old email because I was lazy and was going to use this for gaming anyway.

    • schipelblorp@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      4
      ·
      edit-2
      1 day ago

      Kowloon Walled City (Chinese: 九龍城寨)[a] was an ungoverned and densely populated de jure Chinese enclave within the boundaries of British Hong Kong.

      spoiler

      Originally a Chinese military fort, it became an enclave after the New Territories were leased to Britain in 1898. The Walled City’s population increased dramatically following World War II, and by 1987 it had an estimated 33,000 residents within its 2.6-hectare (6+1⁄2-acre) borders, making it one of the most densely populated places on Earth at approximately 1.2 million inhabitants per square kilometre (3 million per square mile). The city was demolished between 1993 and 1994; the Kowloon Walled City Park was built in its place and opened in December 1995.

      https://en.wikipedia.org/wiki/Kowloon_Walled_City

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    3
    ·
    1 day ago

    Microsoft can’t properly gate a push notification behind a password check?

    Careful now. If you put the MFA prompt after the password, it works as confirmation that you have the correct password even if you’re not able to log in. You don’t want to give that confirmation to the attacker. That’s why MFA happens before the password is validated.

    • lemmydividebyzero@reddthat.comOP
      link
      fedilink
      English
      arrow-up
      7
      ·
      23 hours ago

      You don’t want to give that confirmation to the attacker.

      That’s how it works on > 90% of the websites on the internet. And that’s usually not a problem, because one usually does not suddenly know the password of other people.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      1 day ago

      Just set a timer after entering the password in every single case (only stopped early by successful MFA). “authentication did not succeed, one or more factors may be incorrect or may have failed verification”

  • LiveLM@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 day ago

    This is why I’ve always preferred to enter the TOTP code myself instead of using the “Approve Sign-In” method.

    Also the thing about the Redirect Loops and wacky login forms. Goddamn how come they ain’t fix it yet 😭

    • filcuk@feddit.uk
      link
      fedilink
      English
      arrow-up
      3
      ·
      12 hours ago

      Using a lot of ms services at work. If I leave 10 tabs open, I get 10 individual login popups in the morning. I like to assume there is some reason behind this I’m too dumb to understand, because it is very obviously not good UX and very annoying.

      • Flatfire@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 hours ago

        Token expiry. Because the same login token is used across many services, it expires at the same time. Of course, because the tabs are all open, they just know you need to log in again, not whether you’ve got other services open that also use your account.

    • lemmydividebyzero@reddthat.comOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      23 hours ago

      Also the thing about the Redirect Loops and wacky login forms. Goddamn how come they ain’t fix it yet 😭

      At this point, it’s tradition that it’s that f*cked up. Can’t change that now…

  • lemmyvore@feddit.nl
    link
    fedilink
    English
    arrow-up
    23
    ·
    1 day ago

    My MS account is doing a thing lately where I have to enter the TOTP twice to login successfuly. It has to be two different TOTPs, too, can’t enter the same one; I have to literally wait until the first one expires and get another one.

    Didn’t experience any of the other shenanigans described in the article though, so there’s that.

    • Goun@lemmy.ml
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      TOTP is time based, I’d check the time on the device just in case. Having to enter multiple codes must be so annoying!

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        I have the machine synced with NTP and I’m not seeing any time issues.

        It’s such a super specific quirk, too, that I can’t believe it’s not on their side.

        Maybe they’ve decided that TOTP is less secure than passkeys and if I refuse to use passkeys with their app I should be “helped” 😃 by using twice the amount of TOTP?

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      I have a few networks where I get the notice but must disconnect from the wifi to approve over my mobile connection instead

    • bitwolf@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Teams drains like 30% of my phone battery every hour. It’s crap.

      I just removed it from my phone and deal with carting my work machine around.

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    1 day ago

    And sure, you could also create a new alias and migrate your sign-in preference to dodge the spam, but why should I have to restructure my whole frigging identity just because Microsoft can’t properly gate a push notification behind a password check?

    Why indeed.

  • Shadow@lemmy.ca
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    I got hammered with ms auth requests for weeks before I finally just changed it to a dedicated email address. Really frustrating.

  • bitwolf@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    I disabled t use Microsoft Authenticator, I use passkeys and aegis Authenticator.

    You don’t get away from it this way either.

    Instead, it manifests as needing to reset your password every, single, time you log in. Because of “too many incorrect sign in attempts”.

    The bots can’t do anything bc the account is passwordless. But it doesn’t stop Microsoft’s annoying “security” features.

    So I constantly have to reset a password that is never even used.

  • THE_GR8_MIKE@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    22 hours ago

    Yep. I get an influx of them when I shit talk the diaperpedonazi in charge on certain platforms. Kind of funny.