Hackers could read non-corporate Outlook.com, Hotmail for six months
31–40 of 59 posts
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#32Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#33I am sure glad I switched to ProtonMail.
Protonmail stores all your emails encrypted, with the encryption dependent on your password, so something like this couldn't happen there.
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#34Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#35Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#36Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#37Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…
Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#38Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#39Re: Hackers could read non-corporate Outlook.com, Hotmail for six months
#40Let me get this straight: They were able to use a single helpdesk account password for six months to read arbitrary emails from arbitrary user accounts. There was no 2fa. There was no auditing. There was no integration with any sort of ticketing system ("you can only access an account if you're working on that specific user's ticket") or paperwork ("reason for access:"). There wasn't a single piece of automated monit…
It's a little depressing to go to work and try to deal with the atrocious stuff I have to deal with, and then think how much of my life is online at companies probably just as bad as my own.