Live data from Hacker News

Hackers could read non-corporate Outlook.com, Hotmail for six months

arstechnica.com

11–20 of 59 posts

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#11
post #3

Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…

I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…

I wonder how fastmail is in this regard. Makes me want to reopen my protonmail account honestly

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#12
post #3

Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…

>And this went on for six months

By "this" you mean "Someone had access to that particular help desk account", not the whole system ?

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#13
post #6
post #3

Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…

Microsoft claims it was just 3 months. Otherwise, on point.

90 days is a pretty typical rotation period for credentials. They probably noticed this when they rotated the password and the account got locked from wrong password attempts in short order.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#17
post #9

Earlier quoted context omitted.

I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…

Yes, I wouldn't expect to find much rigor at Cousin Ricky's house of email. This is Hotmail. They don't have any excuses. They handle a ton of email for a lot of people, people depend on them, and they are a big target. If this was a specially privileged superuser account, it should have had more attention paid to it. Yes, it's hard to scale audits or monitoring to the entire customer support org. But if you only hav…

Arcbyte@cousinrickeyshouseofemail.com has a nice ring to it

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#18
post #7

Earlier quoted context omitted.

I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…

>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…

[deleted]

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#19
post #7

Earlier quoted context omitted.

I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…

>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…

> I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at all to the helpdesk operators having access to the account itself. They need to be able to access and update account metadata, not the account itself.

So in your system the bad guy can't read my email because he only has the ability to access and update account metadata such as my password and the helpdesk system doesn't give him access to the actual email?

That would work, unless any of the bad guys is smarter than you and realises that they can use this metadata to... log into my account and read my email.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#20
post #15

Why would a customer support person need access to people's email without even seeking the customer's password ?

Support people should never require customer's password, and they should have to get explicit permission to access their account.

For example, they can get access to basic information and option to reset password, if user forgets the password. For anything else, they should get explicit permission (or it can be granted automatically when user opens a support ticket when he/she is logged in, if that's properly specified when creating a ticket).

Post reply on HN