4 ms·
It’s a satiation attack (my term). The hope is you’ll get so frustrated at the frequency of the emails that you’ll eventually just press yes or ok or whatever i
by borbulon 3y ago
It’s a satiation attack (my term). The hope is you’ll get so frustrated at the frequency of the emails that you’ll eventually just press yes or ok or whatever it is that allows the reset.
- xenophonf 3y agoThis is how I'm going to describe that attack where you get a zillion authenticator push notifications because Microsoft has designed the damn thing to authenticate you to them but not them to you. Like, how freaking difficult would it be to put a transaction code in there like Apple so that you can match the notification on your phone with the session you're starting on some other device or service?!
- TheFreim 3y agoI thought they already have that? When trying to sign in to a Microsoft service it displays a number which I have to type in to the Microsoft Authenticator before I am able to confirm the sign in attempt.
- xenophonf 3y agoYou only get the push notification, no session binding, when using Microsoft Authenticator in other scenarios. That's if you get the push notification. It's variable in my experience. (I use it as a backup MFA method when I don't have my badge reader handy.)
- will4274 3y ago> It's variable in my experience It shows you a code when the initiator is an unfamiliar device, but doesn't show you the code when the initiator is a familiar device. You can reproduce this fairly easily - open a private tab and try to login - you'll see the code in your app. Then logout and login again without closing the tab - you won't see the code. Which actually makes sense, if not well-explained to users.
- pc86 3y agoI just wish Microsoft would let me use any other authenticator app instead of their garbage one. So now I've got one from Google with 99% of my accounts on it, one for Microsoft for one of 4 MS accounts, and one for the USG for IRS/etc. Waste of space and poorly-duplicated functionality.
- delecti 3y agoMicrosoft does let you use other authenticators. My non-MS authenticator app has 3 MS accounts on it.
- pc86 3y agoThe funny thing is I have other MS accounts in my Google authenticator, but for one of my accounts specifically (maybe because it's the only one with Azure spend every month?) even though I have it in Google, I kept getting told on login I needed to set up MS Authenticator or SMS - no options for a different Auth app.
- delecti 3y agoI'd attribute this to MS flakiness, or possibly AD policies. I've got work MS accounts, each connected to a multi-million dollar azure account, and each connected to a non-MS authenticator.
- deleted 3y ago[deleted]
- Mordisquitos 3y agoThis kind of attack is already called an MFA fatigue attack: https://en.wikipedia.org/wiki/Multi-factor_authentication_fatigue_attack https://en.wikipedia.org/wiki/Multi-factor_authentication_fa...
- hathchip 3y agoThe email allows you to enter a new password, it doesn't validate some other access to your account by clicking yes.
- qwerty456127 3y agoThey will just wait for you to get used to this, then stop triggering Facebook to send you legitimate emails and start sending you similarly-looking phishing emails similarly often. It may happen to be enough to view a phishing email, let alone click anything in it to get pwned.
- hathchip 3y agosurely the more of these they send, the less likely you are to click on them
- fetzu 3y agoMaybe they would at some point send an email offering to turn off these annoying notifications with a malicious URL?
- qwerty456127 3y agoVery questionable. Some people will come to completely ingoring them (which isn't good either), some will click anything out of being too annoyed. Whatever, people can be manipulated into doing some statistically predictable actions with decreased awareness this way and this is a vulnerability.
- Cthulhu_ 3y agoWhat if they send you dozens of these, then one that actually looks legitimate, saying something like "We have detected 24 login attempts to your account in the past 30 days coming from this location, click here to see additional details and / or improve your account security", containing a phisher's login form.
- q1w2 3y agoNo, because the attacker needs to enter the recovery code sent by email. My assumption is that they're just guessing over millions of accounts and are expect 1-2 to hit so they can take over those accounts.