Like the title says, I’ve got yesterday an email with a code to access my Microsoft account and that made me suspicious because I wasn’t trying to login to my account. When I looked at the login attempts I saw that someone else was trying to access my account, I changed my password, activated TFA. Thinking of going through and buying a physical key like yubico to further secure my account. Any tips are appreciated.

5 points

did you report it?

permalink
report
reply
11 points

Yes, support said that they can’t stop it, and my account is safe.

permalink
report
parent
reply
10 points

Same here, I have been in the same situation for years. Looks like if you email appears in a data breach every hacker in the world tries to get access to your email. Just never reuse your email password and set 2FA. That’s more than enough to prevent unauthorized access and don’t lose sleep over it.

permalink
report
parent
reply
5 points

I got a notification from my original Xbox account from 2008 saying someone had managed to crack the password and needed the 2fa code.

I went to check on sign in activity and holy shit I knew that email account had been leaked long ago but I was not prepared for dozens to hundreds of sign-in attempts EVERY SINGLE DAY, from all over the world (at least I assume places that are popular VPN outlets)

That account doesn’t have a single thing on it. No games, no cards, it was never even connected to the internet except the rare occasion when I was at a friend’s house. And I don’t re-use passwords except on throwaway accounts. So they would have been quite disappointed by it.

But just to be sure I changed the password again on all my big accounts or accounts with cards attached just in case.

permalink
report
parent
reply
1 point
6 points

Someone hacked my account using an SMS exploit from Russia last week

permalink
report
reply
2 points

I removed my phone number just in case this might happen.

permalink
report
parent
reply
5 points
Deleted by creator
permalink
report
parent
reply
2 points

I can’t even buy Minecraft with my new account

permalink
report
parent
reply
12 points

As long as you have 2Fa setup via a yubikey or phone app, and it via sms or email, you should be fine, they will give up eventually.

permalink
report
reply
18 points

Happened to me too yesterday. Gave me a big bump to my evening plans. Luckily I too have 2fa activated via 2 different systems {SMS AND second Mail address). They cracked my randomly generated password - which doesn’t surprise me that much, brute force cracker are pretty effective nowadays.

What bums me is that I used this as an argument to teach a friend but he just used the same ol’ reliable “naah, I’m too lazy”. Can’t change him, just told him to think about using 2fa everywhere money is involved. The rest is up to him.

What’s also pretty bad from MS is that yes you can use several different mailadresses but no you can’t prevent that all of them can be used as login. One is compromised but also used for mail traffic so I can’t just delete it. But also can’t prevent it from logging in to the account. Thanks MS…

permalink
report
reply
45 points

They cracked my randomly generated password - which doesn’t surprise me that much, brute force cracker are pretty effective nowadays.

I’m actually surprised that it’d be feasible to use a brute force approach to gain access to an online account. I would expect them to hit some kind of rate-limiting long before they’d find the correct password

permalink
report
parent
reply
15 points
*

Brute force attacks are usually done offline, where the attacker somehow gets a copy of a database of hashed passwords and they can take as many attempts as they want locally before they get a hit and can try it online.

permalink
report
parent
reply
3 points

Looking at my history, they’re hours or a day apart. Probably no chance of getting into any halfway decent password that way, but if they can automate it with thousands of different email addresses, eventually they’d get an account with a weak password and get in.

permalink
report
parent
reply
8 points
*

Hey so you actually can make it so an email address doesn’t log into the account, it’s how I stopped one particularly persistent hacking attempt when they finally managed to crack my password but were stopped by 2fa. Go to your profile > account info > sign in preferences, then as long as you have an alias email on the account you can deselect ones that you don’t want to be able to be used as a log-in.

permalink
report
parent
reply
3 points

With Microsoft I couldnt figure out how to enable 2fa against minecraft. Seems they do not have 2fa of any kind there and that is linked to your microsoft account. I guess the permissions there are just for minecraft, but if I was a betting man, I would venture there is a big hole there.

permalink
report
parent
reply
0 points

Oh, really?! Okay gonna try that, thanks for the Tipp!

permalink
report
parent
reply
10 points

I appreciate when commenters end their first paragraph with bullshit so you don’t have to read any farther. I’d love to hear how you think they cracked your randomly generated password via brute force against Microsoft.

permalink
report
parent
reply
4 points

What kind of randomly generated password did you have that was crackable? I usually use 30 characters completely random string. If that’s crackable, maybe I need to rethink things.

permalink
report
parent
reply
1 point

Stupidly just 12 random characters. I was too naive and hoped that’ll be it.

permalink
report
parent
reply
5 points

You should enable passwordless auth with number matching.

permalink
report
reply
2 points

I’ve ordered a few yubico keys and will look into it.

permalink
report
parent
reply
4 points

You can also use MS Authenticator. It has the code match option too.

permalink
report
parent
reply

techsupport

!techsupport@lemmy.world

Create post

The Lemmy community will help you with your tech problems and questions about anything here. Do not be shy, we will try to help you.

If something works or if you find a solution to your problem let us know it will be greatly apreciated.

Rules: instance rules + stay on topic

Partnered communities:

You Should Know

Reddit

Software gore

Recommendations

Community stats

  • 241

    Monthly active users

  • 304

    Posts

  • 1.8K

    Comments

Community moderators