Live data from Hacker News

Hackers could read non-corporate Outlook.com, Hotmail for six months

arstechnica.com

21–30 of 59 posts

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#21

I'm imagining a future cottage industry with companies holding offices in India/Russia/China/ with a full staff reading emails for blackmail material (naturally finding a politician or celebrity once in a while)

"Future."

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#22
post #3

Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…

Surely gmail doesn't have something this terrible, right?

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#23
post #22
post #3

Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…

Surely gmail doesn't have something this terrible, right?

There's a blog post titled Into The Borg[0] that states:

> There is also a user “legal-discovery@prod.google.com” that has permission “auth.impersonation.impersonateNormalUser”

So it exists, but hopefully Google doesn't have the same issues with giving helpdesk employees access to impersonation.

0: https://opnsec.com/2018/07/into-the-borg-ssrf-inside-google-...

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#24
post #8

Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…

PII is personally identifiable info?

What's an EQ account?

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#25
post #8

Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…

PII is personally identifiable info? What's an EQ account?

I'm guessing EverQuest, which was pretty popular at that time.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#26
post #8

Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…

PII is personally identifiable info? What's an EQ account?

Probably EverQuest

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#27
post #8

Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…

PII is personally identifiable info? What's an EQ account?

EverQuest, I assume, which was a popular MMORPG prior to World of Warcraft

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#28
post #7

Earlier quoted context omitted.

>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…

> I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at all to the helpdesk operators having access to the account itself. They need to be able to access and update account metadata, not the account itself. So in your system the bad guy can't read my email because he only has the ability to access and update account metadata such as my password and the helpdesk…

If the password is stored in plaintext or can be changed by an admin(in a method other than a reset where the user still sets the new password), we've got other problems.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#29
post #7

Earlier quoted context omitted.

>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…

> I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at all to the helpdesk operators having access to the account itself. They need to be able to access and update account metadata, not the account itself. So in your system the bad guy can't read my email because he only has the ability to access and update account metadata such as my password and the helpdesk…

>That would work, unless any of the bad guys is smarter than you and realises that they can use this metadata to... log into my account and read my email.

No need to be so rude and disrespectful.

Obviously there needs to be a password reset mechanism. That mechanism can absolutely be designed in a way that does not involve the helpdesk operator having access to the password or the account.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#30
post #8

Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…

Just prior to your mentioned timeline Hotmail was vulnerable via query string params. A rather non-technical friend of mine brought this up in conversation and I didn't believe him, so he told me to log in to my account. He took a quick look at the URL and wrote down a param, then logged into my account on his machine. IIRC it was patched about month later but still, those early days of the web were pretty wild.
Post reply on HN