I'm imagining a future cottage industry with companies holding offices in India/Russia/China/ with a full staff reading emails for blackmail material (naturally finding a politician or celebrity once in a while)
Hackers could read non-corporate Outlook.com, Hotmail for six months
21–30 of 59 posts
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#22Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#23Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…
Surely gmail doesn't have something this terrible, right?
> There is also a user “legal-discovery@prod.google.com” that has permission “auth.impersonation.impersonateNormalUser”
So it exists, but hopefully Google doesn't have the same issues with giving helpdesk employees access to impersonation.
0: https://opnsec.com/2018/07/into-the-borg-ssrf-inside-google-...
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#24Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…
What's an EQ account?
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#25Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…
PII is personally identifiable info? What's an EQ account?
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#26Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…
PII is personally identifiable info? What's an EQ account?
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#27Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…
PII is personally identifiable info? What's an EQ account?
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#28Earlier quoted context omitted.
>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…
> I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at all to the helpdesk operators having access to the account itself. They need to be able to access and update account metadata, not the account itself. So in your system the bad guy can't read my email because he only has the ability to access and update account metadata such as my password and the helpdesk…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#29Earlier quoted context omitted.
>Now, you can build systems where it's just impossible for even your own people to get access. But that has a high cost, as you will see in every thread where people castigate Google because they got locked out of something. Why can't Google just hire helpdesk people who have super-user access, they ask... I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at a…
> I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at all to the helpdesk operators having access to the account itself. They need to be able to access and update account metadata, not the account itself. So in your system the bad guy can't read my email because he only has the ability to access and update account metadata such as my password and the helpdesk…
No need to be so rude and disrespectful.
Obviously there needs to be a password reset mechanism. That mechanism can absolutely be designed in a way that does not involve the helpdesk operator having access to the password or the account.
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#30Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…