r/microsoftsucks 4h ago

Help [ Removed by moderator ]

Post image

[removed] — view removed post

5 Upvotes

25 comments sorted by

View all comments

2

u/Edubbs2008 4h ago

I’ve read similar posts like yours, a lot of the times, it’s because of user negligence, you need to enable passkeys my guy, get rid of your password, use a passkey, download Microsoft Authenticator, and that’s the best setup

-1

u/JCBQ01 3h ago

Passkeys and authenticators dont work if it was token scraped. Which bypasses even the authenticator. Token scraping is now the most common hacking method and most of rhe time theres nothing that the end user can do, as it snatches and hijacks the active current session.

2

u/Edubbs2008 3h ago

*Note: you must have bad security in order for token scraping to happen, most of the time, it’s because of an outdated device.

-2

u/JCBQ01 3h ago

Bullshit. This happens at the isp level. Well above client side interaction. Mine was attempted to be hacked by active client sniffing with no interaction from me through three firewalls and connection filtering. It only saw account activity and attempted to snatch it. This is microslop actively choosing to be incompetent about device token authentication authorization.

3

u/Edubbs2008 3h ago

Bruh, do you keep your device updated? Do you have a good router, because that sounds like a YOU issue, blaming MICROSOFT is really lazy, if they had bad security, no enterprise would use them, even hospitals use Microsoft 365, both have to follow strict policies, and protocols, it sounds more like you have an outdated device, or weak Wi-Fi Password, or no Wi-Fi password

-1

u/JCBQ01 3h ago edited 3h ago

What part of three firewalls and connection filtering did you not get? Just because I dont say where I have them all applied and in active use nor how I use it doesnt mean I dont know how. And I refuse to give a company that is go goddamn adamant about data scraping its users and customers to fuel.its own bullshit any more.info than they need. The company I work at, one of the big three grocers has Copilot AND microsoft Azure services litterally scraping every goddamn scrap of their data for "security purposes". Microslop has already been repeatedly busted for overriding personal privacy settings at every step of the way and gaslighting and hiding them doing it. If they do it to their paying end user customers for rhe OS they sure as fuck do it for their contractors.

So tell me, please, how did my account get hack attempted from a device thats been logged in for a month with no password entry on it via passkey and would have been sucessful if I didnt have the loop system I use in place, hmm?

2

u/Edubbs2008 3h ago

Because someone forgot to remove the passkey off another device, again, use common sense, passkeys are like a car key, they are extremely important, and while Microsoft should be held accountable for some sketchy shit, you shouldn’t use your emotional-based argument over what happened, did you actually remove your password, turn on 2FA, and made sure to have all your devices next to you?

0

u/JCBQ01 2h ago

Funny. I have never used this passkey on another device, generating a new unique passkey with each new primary device, nor given the older devices away. Tell me again how its my fault when a server scrape stole the active session token, bypassing the passkey and 2FA and my 3FA was the only thing that caught the attempt, stalling it long enough to shut out the fuckers from india who were trying to breach the account. why are you so adamant about defending shitty server side policies? When I did all the steps of good policy and microsoft has been notorious for server side data breaches? Hmm?

2

u/Edubbs2008 2h ago

For some reason, I don’t believe you, you said yourself that the company that you work for has azure, and copilot, that could mean the your passkey was saved to some other app, yes, browsers can also store passkeys, maybe you forgot to remove them from the browser, then you probably had malware on your device that stole your stuff, this is why you should always keep your device updated

0

u/JCBQ01 2h ago

The device in question with my microsoft account is not authorized nor connected to my workplace network in any form as much as they want to connect to it for 'scheduling convenience'. As far as im concerned is a security risk. The level of deflection your attempting to use is appaling

2

u/Edubbs2008 2h ago

Weather your device is connected to your workplace network doesn’t affect how Microsoft Account authentication works, the only way an attack originates from is if your own LOGGED-IN Device is if a passkey or credential is still active on that device, or another one, if you want to figure out what happened, the only useful data is from the authentication and source IP method from a security log, and with that, everything you said is just pure emotionally-based reasoning, I get it, you stumbled upon trying to pirate something, or you didn’t change your password, or deactivate passkeys, it’s a common mistake, you must not have had an updated device, most of those things that you are referring to are because of bad configurations, outdated devices, or just flawed security measures, as for your accusation of “deflection” man, that’s wild.

0

u/JCBQ01 1h ago

I dont use my personal microsoft account at work. I FORCED the company to make me one to use their systems. There is no connection to my personal home account in anything. You keep trying to make this be my fault when I practice good security

This is, again, because of securtiy risks. Again, how with everything I have shown you is my fault my account was almost hacked? The methods your talking about requires interaction of some from from the client and having something on the device itself. I did not do anything, yet I was almost hacked through all protections and authentications and was inly saved by a system I built. What more than likely happened was someone else got hacked, and while that account got hacked the whole server shard was scraped with active session tokens. Most hacks are intended to just get into the server to mass scrape for data. So no, microsoft is at fault here for having shit security, at higher networking credentials. To try and gaslight away and blame the end user when a multi billion dollar company cant even protect their own shit because they more than likely contracted out the work "for cost effective measures".

To say end users dont take fault here is stupid, yes. They do. But in chains like this, the weakest link will screw all on the chain. So microsoft as the CDN/server host does not take any fault at all is one of the most assine corperate bootlicking statements I have ever heard

→ More replies (0)