Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…
I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…
Hackers could read non-corporate Outlook.com, Hotmail for six months
11–20 of 59 posts
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#12Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…
By "this" you mean "Someone had access to that particular help desk account", not the whole system ?
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#13Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…
Microsoft claims it was just 3 months. Otherwise, on point.
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#14(naturally finding a politician or celebrity once in a while)
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#15Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#16Why would a customer support person need access to people's email without even seeking the customer's password ?
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#17Earlier quoted context omitted.
I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…
Yes, I wouldn't expect to find much rigor at Cousin Ricky's house of email. This is Hotmail. They don't have any excuses. They handle a ton of email for a lot of people, people depend on them, and they are a big target. If this was a specially privileged superuser account, it should have had more attention paid to it. Yes, it's hard to scale audits or monitoring to the entire customer support org. But if you only hav…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#18Earlier quoted context omitted.
I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…
>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#19Earlier quoted context omitted.
I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…
>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…
So in your system the bad guy can't read my email because he only has the ability to access and update account metadata such as my password and the helpdesk system doesn't give him access to the actual email?
That would work, unless any of the bad guys is smarter than you and realises that they can use this metadata to... log into my account and read my email.
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#20Why would a customer support person need access to people's email without even seeking the customer's password ?
For example, they can get access to basic information and option to reset password, if user forgets the password. For anything else, they should get explicit permission (or it can be granted automatically when user opens a support ticket when he/she is logged in, if that's properly specified when creating a ticket).