14 ms·
Microsoft denies data breach, theft of 30M customer accounts
- WhereIsTheTruth 3y agoLet's remember what Microsoft said in their DDoS's blog post: "We have seen no evidence that customer data has been accessed or compromised." - https://msrc.microsoft.com/blog/2023/06/microsoft-response-to-layer-7-distributed-denial-of-service-ddos-attacks/ https://msrc.microsoft.com/blog/2023/06/microsoft-response-t... There you go, this news article is the evidence of intrusion + data breach
- skilled 3y agoThat does seem like an odd thing to include in a post-mortem. I can see appeasing to the layman by saying that but it’s unusual for sure.
- Veserv 3y agoIt continues to be a travesty of breach disclosure that companys are legally allowed to claim the best possible outcome without any proof. Only definitive proof of compromise compels them to indicate any problems at all and they still get to downplay it to the minimal proven consequences. This is totally ass-backwards. There is negative incentive to do any investigation. A investigation can basically only make things worse as you get to assume no harm when you are ignorant. They should be required to disclose the worst with only a thorough investigation demonstrating a credible absence of compromise allowing a positive statement. This incentivizes investigation and properly errs on the side of the victim when assessing risks.
- pipo234 3y agoBasically, a company is only incentivized to disclose compromises that were intentional and financially motivated. That is, a hacker that intends to extort the company, sell the information or abuse it for financial gains will ultimately cause too much noise to keep it under the rug. If this is what the company anticipates they will have to investigate and disclose. It the breach is a foreign government or hush-hush data hoarder or the result of plain incompetence, the company can absolutely ignore the problem.
- Veserv 3y agoNot even then. The company is only incentivized to disclose when there is public proof. Until there is public proof or compelling proof submitted by a victim they are not liable for their calculated willful ignorance. The consequences to a company only manifest when noise is being made with proof. That is totally ridiculous.
- sokoloff 3y agoHow would it work to be required to disclose the worst, though? In most instances, you literally can't describe the worst possible case in the first hours/days of the discovery. You'd be requiring companies to speculate on the outer bounds of something that is simply not knowable.
- Veserv 3y agoThat is pretty easy: “We have been breached. Everyone may be affected. Preliminary results of our investigation to come shortly at {URL}.” Sucks to be them, but then they have a very strong incentive to quickly begin investigation and triage so that they can quickly identify who is actually at risk. It is ridiculous to sacrifice the victims by keeping them ignorant of the risks they are facing so that the company can save face. They should not be allowed to blindly speculate that everything is perfectly fine which is simply not knowable without a investigation.
- sokoloff 3y agoHow long until those become the security equivalent of Prop 65 "causes cancer" warnings? Or the shitshow that DMCA takedowns are today? What's the burden of proof to confirm that the first sentence in your quote is correct? (Can I just claim to have breached some company and have the law compel them to issue that quote?) You're frustrated that companies are issuing information-free notices today; your proposal appears to make them issue information-free notices tomorrow.
- Goronmon 3y agoCan I just claim to have breached some company and have the law compel them to issue that quote? I don't think anyone would have to claim to have breached the company in question. Just the act of asking the question would compel any company to have to respond "Yes, we have been breached."
- Veserv 3y agoEstablishing the presence of any data breach is far easier than establishing the exact scope. My proposal moves the burden of proof to just establishing the former and demanding the company prove the latter. This is a division of labor that is common in safety critical industrys with decades of proven results supporting the effectiveness of such a regime. Your complaint that the situation will just turn into everybody acknowledging that they are hopelessly insecure is a far better situation than now where everybody lies by claiming that they are secure. It results in the acknowledgement of breaches and the acceptance of liability that would be helpful for future legislation that can actually apply penaltys for delivering products that are defective with respect to security.
- SoftTalker 3y agoThey are taking advantage of the "innocent until proven guilty" that is really only applicable to criminal charges but many people seem willing to extend it more generally. The followup question to those kind of statements should always be "do you have any evidence that your accounts are not compromised?" I.e. absence of evidence is not evidence of absence.
- hulitu 3y ago> It continues to be a travesty of breach disclosure that companys are legally allowed to claim the best possible outcome without any proof > "We have seen no evidence that customer data has been accessed or compromised." I think they are sincere here. I too have seen windows machines being compromised and the system, with the latest certified antivirus, run hapilly. /s
- naikrovek 3y ago> It continues to be a travesty of breach disclosure that [companies] are legally allowed to claim the best possible outcome without any proof. what proof would you propose that you be shown? how do you prove something didn't happen?
- meandmycode 3y agoThis article is evidence? what?
- xpil 3y ago"a large database containing more than 30 million Microsoft accounts, emails, and passwords." A database containing passwords? Why would anyone store passwords in a database is beyond my comprehension.
- endisneigh 3y agoWhere else should you store the passwords?
- rolph 3y agoon a post-it, under the keyboard its safer there
- _Algernon_ 3y agoNot at all. You store a salt and the hash(pw+salt).
- charcircuit 3y agoBe warned that this makes your authentication system less secure because it caps the maximum entropy of the password to the entropy of the hash function.
- poizan42 3y agoYou need crazy long passwords for that to become the limiting factor. With random printable characters on the keyboard there are a bit less than 7 bits per character (unless a crazy amount of different accents are used). So you need passwords longer than 18 characters to surpass the entropy of even MD5.
- gpvos 3y agoWhat would you suggest instead?
- charcircuit 3y ago
- rvz 3y ago> “We have seen no evidence that our customer data has been accessed or compromised” - Microsoft spokesperson So they have been breached. Ok.
- wredue 3y agoWell. That is an annoying password to have to change. Most of the I don’t care much because I just generate a new one and away I go. The Microsoft password is one I couldn’t just copy paste from a password manager and now I have to change and relearn it. Damnit.
- koolba 3y agoIs it a thick client app that you cannot use the password manager? Or just a web page that adds "onpaste=..." handlers to make life unnecessarily difficult? The latter can be "fixed" with some JS console magic.
- 11011111 3y agoMight be the password to login to the computer itself.
- wredue 3y agoYes. It’s my gaming machine log on. It’s just easier to know this password than to always have to find it. I do not trust corporations, so I generally do not do things like biometrics and stuff. I don’t completely understand how pins are more secure than my complex password either. That could be ignorance.
- GeekyBear 3y agoThank goodness Microsoft isn't trying to force users to access their local PC through a Microsoft Account.
- throitallaway 3y agoThe amount of dark patterns on Windows nowadays is insane. If you want to go through the OOTB setup and use a local account, you'd better not connect to a network (which it's very pushy at getting you to do.) It's literally not an option to set up a local account in most cases. I've rarely touched Windows in the last decade and I'm better for it.
- cevn 3y agoIn order to get out of using the M$ft account for my dad on win11 I had to disable secure boot, use regedit, etc and it was all very dark and time consuming. Microsoft is The Worst.
- deleted 3y ago[deleted]
- Milnaurr 3y agoYou can always utilize no@thankyou.com and it will go straight into creating a local account.
- ghusbands 3y agoThere are much easier solutions than that. I've not tried the sibling's idea, but just not connecting it to wifi, pressing shift+f10 and running "oobe\BypassNRO" is enough. It's still ridiculous and shameful behaviour from Microsoft, but disabling secureboot isn't necessary.
- cevn 3y agoThat works for the initial logon attempt, but after that the computer was locked in “S mode” where it doesnt allow you to install anything. In order to get chrome running we had to do the above.
- yabones 3y agoIf this is real, $50,000 USD is a laughably small sum for the database. It reminds me of Dr. Evil's demand for 'one million dollars', you have to jack up the number to be taken seriously.
- meandmycode 3y agoAlmost like it might be a scam, odd
- lockhouse 3y agoAlso for a company the size of Microsoft, 30 million accounts seems very small. What user accounts would this database even contain? This whole thing seems a bit fishy.
- doctaj 3y agoCould be an event like Microsoft Build conference or something.
- wlesieutre 3y agoOr the 100 "sample" accounts are sourced from unrelated phishing and there is no breach. Most of the phishing emails I get lately are trying to get me to fill out a fake MS login page.
- sdflhasjd 3y agoMITM'd login services perhaps? It does seem like a small number for Microsoft. Like robbing a bank and making off with $50
- treeman79 3y agoWas at a small startup. We kept begging CEO to raise prices so customers would take us seriously and stop laughing at us. Finally he tripled the prices. We started landing new customers like crazy and in a few months got to 1,000 monthly paying customers. Same products.
- reese_john 3y ago"All rumors are false until officially denied" - Nassim Taleb
- robertlagrant 3y agoDon't make me dig out this exact quote from Yes Minister in the 1980s.
- mangamadaiyan 3y agoSir Humphrey Appleby, surely?
- elFarto 3y agoI did receive a notification from Microsoft of a suspicous login about a week ago. The password for that account was a relatively strong one (upper/lower case, numbers and some symbols I think). It was an actual login, not just an attempt. I also don't use my Microsoft account for anything (no Windows/Xbox). So I'm inclined to say that they have had a breach.
- dehrmann 3y agoUsually, breaches this size from tech companies that should know better are accounts that were part of another breach and reused their password.
- cced 3y agoWhat’s the procedure for someone that has Microsoft accounts, change passwords?
- PicassoCTs 3y agoThese huge centralized mono-system monopolies are quite the fire-hazard when it comes to security. If microsofts centralization allowed for a attack vector to take down the whole western hemispheres productivity for a week - could the resulting rage destroy the monopolies?