Live data from Hacker News

Microsoft Live Account Credentials Leaking from Windows 8 and Above

hackaday.com

41–50 of 144 posts

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#41

Microsoft should fix this ASAP. You should enable Two-factor Authentication (2FA) on your account. https://support.microsoft.com/en-us/help/12408/microsoft-acc...

The permissions their Android 2FA app requires seems a bit much for its purpose.

The app has access to:

- Identity

- Contacts

- SMS

- Camera

- Device ID & call information

- Other

https://play.google.com/store/apps/details?id=com.microsoft....

Am I the only one who thinks that?

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#42
As a Linux user I have kept Windows 7 & 8 partitions in my laptop and workstation disks for years because there used to be time where you needed Windows in the work for some programs to work and some documents to open.

Windows 10 upgrade push made me to realize that that time passed a long time ago. Last time I booted to Windows for other reason than playing a game was seven years ago. LibreOffice works well with MS documents and you can always use them from Google drive.

Windows has lost it's grip for good.

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#43
post #40

Earlier quoted context omitted.

I'm not sure who's correct in this particular thread, but sometimes they hide the "unfavoured" approach so well that they convince people to use the new method. In one case, I unsuccessfully tried to create just a local account in Win 8, because they had hidden it behind 3+ layers of "sign in here with your live account". I was sure that there must be a way to create a local one, but just couldn't find the right path…

Local accounts were not available in Windows 8 or 8.1, they only got reintroduced in Windows 10. Call me old fashioned, but I prefer my login credentials to my physical PC to be different than for my online accounts.

That's false:

https://support.microsoft.com/en-us/help/13951/windows-creat...

(I had a Windows 8 VM for compiling some software and used a local account.)

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#44
post #29

Earlier quoted context omitted.

Nope. The started with the IE 11 source code and ripped a whole load of stuff dealing with compatibility, and previous rendering engines, out. Once they had completed this step they started adding new features in, but it's still got the legacy of Internet Explorer code in it.

I still don't understand how this myth that they wrote Edge from scratch even came to be. You don't just quickly write a browser from scratch in this day and age. And if you did, it would be so much better than Edge or the other contemporary browsers, because you could start out with a much better architecture...

> I still don't understand how this myth that they wrote Edge from scratch even came to be.

Because people confuse Microsoft marketing fluff with reality?

"Microsoft Edge is built from the ground up to improve productivity, to be more secure, and to correctly, quickly and reliably render Web pages. While Microsoft Edge is the default browser for Windows 10 and is the best fit for most users, some enterprise customers have line-of-business applications built specifically for older Web technologies, which require Internet Explorer 11." [0]

"We designed Microsoft Edge from the ground up to prioritize power efficiency and deliver more battery life" [1]

"Microsoft Edge is designed from the ground up to provide a modern, interoperable, and secure browsing experience"[2]

[0] https://blogs.microsoft.com/firehose/2016/05/19/improvements...

[1] https://blogs.windows.com/windowsexperience/2016/06/20/more-...

[2] https://blogs.windows.com/msedgedev/2016/06/07/edge-enterpri...

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#45
post #19
post #17

Earlier quoted context omitted.

You can actually have Windows logged in with a local account (normal old school account) and use the store with a different Live account. But yes, I am quite annoyed by them requiring that I use online credentials to log in to a physical computer. I prefer to separate the two authentication mechanisms.

That would be great - when I most recently tried to use it I was told by the dialog box that entering my Live credentials would convert my local account to the Live account, and I'd need to log in with the Live password not the local one.

I have seen that and it's a dark pattern, if you close the window you will still use your live credentials without changing your logon account.

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#46

Microsoft should fix this ASAP. You should enable Two-factor Authentication (2FA) on your account. https://support.microsoft.com/en-us/help/12408/microsoft-acc...

The permissions their Android 2FA app requires seems a bit much for its purpose. The app has access to: - Identity - Contacts - SMS - Camera - Device ID & call information - Other https://play.google.com/store/apps/details?id=com.microsoft.... Am I the only one who thinks that?

I can understand Identity, SMS, Camera, and Device ID/Call info.

Identity: Find or manage any Live/O365/MS account on your device

SMS: Read enrollment text message or backup texts (e.g. no network) for pushing auth requests

Camera: Enrollment via QR code

Device ID / Call info: Needed to reliably push notifications / send SMS + get phone number for verification texts whatever

Android's permission system is sort of obtuse

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#47

Microsoft should fix this ASAP. You should enable Two-factor Authentication (2FA) on your account. https://support.microsoft.com/en-us/help/12408/microsoft-acc...

The permissions their Android 2FA app requires seems a bit much for its purpose. The app has access to: - Identity - Contacts - SMS - Camera - Device ID & call information - Other https://play.google.com/store/apps/details?id=com.microsoft.... Am I the only one who thinks that?

You can use several other 2FA apps such as Google Authenticator if you do not trust the Microsoft one, they are compatible.

That said, personally I do like the Microsoft Authenticator app very much, it's just a single tap on the phone to confirm the 2FA login, which is much more convenient than retyping a code. Disadvantage is that the Android version of the Microsoft Authenticator app can only have one account, I could not connect a second 2FA service (LastPass) to it.

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#49
post #24
post #9

And people wonder why some of us haven't upgraded from Windows 7. Win10 tries really hard to make you log into your desktop with your Live Account credentials - you can't use the store without this. Whereas if it were just leaking a local login it would be much less critical.

Using windows 10 since it came out, never opened Windows Store, not even once.

I've been using Windows 10 since it came out too. I tend to have everything on default settings and deliberately allowed Windows and Cortana to do pretty much everything automatically, i even have one on my computers on the fast ring...

I have downloaded Netflix, Audible, tubecast and a whole bunch of other apps from the store

and so far, all is good. fingers cross ;)

Re: Microsoft Live Account Credentials Leaking from Windows 8 and Above

#50
post #2

tl;dr: Simply accessing a website with Edge leaks the user name and password hash to the attacker site. They mention that this is also default behaviour in Spartan, Internet Explorer, Outlook (though I do not know how effectively it can be delivered to something like Outlook). Works on up to date Windows 10 and Edge (there is an online test if you're vulnerable). If you don't use the listed software, you're probably…

I'd be interested to know, how easy is it to actually break the hash of the password-code

When it's NTLM, extremely easy. I know NTLMv1 cracks at around 25 billion attempts per second on a high-end GPU, which is MD4 based. NTMLv2 is MD5 based with a longer key, so it's slower, I'm not sure how much slower, but I'll guess 1 order of magnitude. Still, far too fast for a password hash.

[1] - http://thepasswordproject.com/oclhashcat_benchmarking

Post reply on HN