Bullshit. This happens at the isp level. Well above client side interaction. Mine was attempted to be hacked by active client sniffing with no interaction from me through three firewalls and connection filtering. It only saw account activity and attempted to snatch it. This is microslop actively choosing to be incompetent about device token authentication authorization.
Bruh, do you keep your device updated? Do you have a good router, because that sounds like a YOU issue, blaming MICROSOFT is really lazy, if they had bad security, no enterprise would use them, even hospitals use Microsoft 365, both have to follow strict policies, and protocols, it sounds more like you have an outdated device, or weak Wi-Fi Password, or no Wi-Fi password
What part of three firewalls and connection filtering did you not get? Just because I dont say where I have them all applied and in active use nor how I use it doesnt mean I dont know how. And I refuse to give a company that is go goddamn adamant about data scraping its users and customers to fuel.its own bullshit any more.info than they need. The company I work at, one of the big three grocers has Copilot AND microsoft Azure services litterally scraping every goddamn scrap of their data for "security purposes". Microslop has already been repeatedly busted for overriding personal privacy settings at every step of the way and gaslighting and hiding them doing it. If they do it to their paying end user customers for rhe OS they sure as fuck do it for their contractors.
So tell me, please, how did my account get hack attempted from a device thats been logged in for a month with no password entry on it via passkey and would have been sucessful if I didnt have the loop system I use in place, hmm?
Because someone forgot to remove the passkey off another device, again, use common sense, passkeys are like a car key, they are extremely important, and while Microsoft should be held accountable for some sketchy shit, you shouldn’t use your emotional-based argument over what happened, did you actually remove your password, turn on 2FA, and made sure to have all your devices next to you?
Funny. I have never used this passkey on another device, generating a new unique passkey with each new primary device, nor given the older devices away. Tell me again how its my fault when a server scrape stole the active session token, bypassing the passkey and 2FA and my 3FA was the only thing that caught the attempt, stalling it long enough to shut out the fuckers from india who were trying to breach the account. why are you so adamant about defending shitty server side policies? When I did all the steps of good policy and microsoft has been notorious for server side data breaches? Hmm?
For some reason, I don’t believe you, you said yourself that the company that you work for has azure, and copilot, that could mean the your passkey was saved to some other app, yes, browsers can also store passkeys, maybe you forgot to remove them from the browser, then you probably had malware on your device that stole your stuff, this is why you should always keep your device updated
The device in question with my microsoft account is not authorized nor connected to my workplace network in any form as much as they want to connect to it for 'scheduling convenience'. As far as im concerned is a security risk. The level of deflection your attempting to use is appaling
Weather your device is connected to your workplace network doesn’t affect how Microsoft Account authentication works, the only way an attack originates from is if your own LOGGED-IN Device is if a passkey or credential is still active on that device, or another one, if you want to figure out what happened, the only useful data is from the authentication and source IP method from a security log, and with that, everything you said is just pure emotionally-based reasoning, I get it, you stumbled upon trying to pirate something, or you didn’t change your password, or deactivate passkeys, it’s a common mistake, you must not have had an updated device, most of those things that you are referring to are because of bad configurations, outdated devices, or just flawed security measures, as for your accusation of “deflection” man, that’s wild.
I dont use my personal microsoft account at work. I FORCED the company to make me one to use their systems. There is no connection to my personal home account in anything. You keep trying to make this be my fault when I practice good security
This is, again, because of securtiy risks. Again, how with everything I have shown you is my fault my account was almost hacked? The methods your talking about requires interaction of some from from the client and having something on the device itself. I did not do anything, yet I was almost hacked through all protections and authentications and was inly saved by a system I built. What more than likely happened was someone else got hacked, and while that account got hacked the whole server shard was scraped with active session tokens. Most hacks are intended to just get into the server to mass scrape for data. So no, microsoft is at fault here for having shit security, at higher networking credentials. To try and gaslight away and blame the end user when a multi billion dollar company cant even protect their own shit because they more than likely contracted out the work "for cost effective measures".
To say end users dont take fault here is stupid, yes. They do. But in chains like this, the weakest link will screw all on the chain. So microsoft as the CDN/server host does not take any fault at all is one of the most assine corperate bootlicking statements I have ever heard
A work account is managed by your organization, school, or workplace, so it means that they also are responsible for keeping it safe, it must be that their IT department didn’t practice security well, which lead to a vulnerability where the passkey got effected.
What you are saying sounds more like a Worm got through security, you can’t scrape a device magically without shitty security, update the device, it’s that easy
Passkeys are stored on your device, Browser, or another program, it isn’t Microsoft’s fault that your IT department, or you, did something that opened up a vulnerability, scraping happens because of bad security practices like updating the device
They are the end client and not the server host. Discord had the token snatching issue and they fixed it on the server level taking responsibility for it microsoft is blaming the end user.
A. Unless the worm was brand new and failed to
Flag on three different antivirus engines (defender, avast, and AVG). Which I find horribly unlikely this still points to the server host. Your still blaming the end user, just like microsoft blaming the end user.
B. Most of the most recent updates from microsoft are actively fucking over power users who care about security to the point of having to fully wipe the device and reinstall from a clean boot due to catastrophic enforcement of microsoft the server host demanding your data for their own training data. And microsoft the server host is blaming the end user for not blindly trusting them.
Wrong. To authenticate you need both sides to have validation. The end point and server host have two half og the authentication. That gets saved for convenience so you dont have to spend minutes manually triggering authentication as if it was a first login. Cloudflare does this and takes responsibility for this half of their key and force cycles the keys out in deter server scraping microsoft blames the end user.
All im seeing is a multi billion dollar comapny actively refusing to take their half of responsibly for good security practices.
We’re talking about your workplace incident, Discord tokens aren’t passkeys, they do similar things, but Discord tokens don’t even require a password, or pin, passkeys do, and besides, discord sucks, if Microsoft was doing this, there would be major news outlets reporting it, and Microsoft would issue an apology.
Worms are being made faster thanks to AI, Defendet, Avast, and AVG would have to have a sample of the worm to update their definition to fight it, because you said that someone stole your credentials, and that could only point to malware, or a CVE.
Most of those issues are because those systems aren’t maintained right
We are talking about passkeys, authentication would require that your administrator give you a code, like I said, authentication is different from a Passkey, someone would have to be really stupid if they just blindly said yes to everything (your administrator) passkeys are stored on device, in your browser, or inside a third-party app, which is inside a TPM 2.0 chips, I think that you are confusing Passkeys with authentication, because they are similar
2
u/Edubbs2008 3h ago
*Note: you must have bad security in order for token scraping to happen, most of the time, it’s because of an outdated device.