Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

171–180 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#171
post #56
post #52

Earlier quoted context omitted.

I'm not gonna get hoodwinked into highbrow shenanigans. Social media doesn't need IDs to work, demanding it is a scam.

Defining a word isn't "highbrow shenanigans", although I guess it depends on how you define that.

If you think social media needs your ID for any reasonable cause, we're free to disagree on that. My point was clear, bullshit technicalities on the word scam are meaningless when you understand the meaning.

Re: Scammers are abusing an internal Microsoft account to send spam links

#172

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

Isn’t that really easy to spoof?

Re: Scammers are abusing an internal Microsoft account to send spam links

#173
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

Yes it is completely broken. Everyone should disable microsoft authenticator and uninstall it. It is a massive vector.

Re: Scammers are abusing an internal Microsoft account to send spam links

#174
post #104

Earlier quoted context omitted.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…

Unfortunately in the US, maybe elsewhere, pharmacies and medical offices have trained the elderly it’s okay to verify their dob when they call. Costco does that when they call and it drives me nuts.

US insurers expect you to click on sms links and log in with your username, password, and 2fa all so you can receive a fucking marketing message.

Re: Scammers are abusing an internal Microsoft account to send spam links

#175

Earlier quoted context omitted.

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…

This is very much my experience. I generally say at some point before terminating the call "you should not train your customers to give out account access credentials to strangers" and the caller usually has no clue what I mean. Does no one in the security teams have theory of mind? This will be the way I bring up the issue with the regulator if I do. I can think of many ways round this issue that would be much safer…

The caller is a minimal wagie following a script, you can't get mad at them.

The chucklefuck that wrote the script that you can get mad at won't pick up your calls.

That's how responsibility works.

Re: Scammers are abusing an internal Microsoft account to send spam links

#176
post #125

Earlier quoted context omitted.

We pay for a bunch of old domains because nobody in the org can definitively say we never used it and/or don’t use it anymore. Easier to just keep paying.

Not only have you stopped using it, but did any of your customers ever allow list it in the past? Great way to attack customers of some large businesses if you ever see it happen.

And if you don't squat some domains phishing could be a bit easier than otherwise.

Re: Scammers are abusing an internal Microsoft account to send spam links

#177
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

Yes it is completely broken. Everyone should disable microsoft authenticator and uninstall it. It is a massive vector.

Yes, there are so many other 2FA authenticators, many of them even open-source. Why would you ever use the Microsoft one?

Re: Scammers are abusing an internal Microsoft account to send spam links

#178

Earlier quoted context omitted.

Yes it is completely broken. Everyone should disable microsoft authenticator and uninstall it. It is a massive vector.

Yes, there are so many other 2FA authenticators, many of them even open-source. Why would you ever use the Microsoft one?

It is doing something different than RFC 6238, which theoretically is more secure. The way they have it implemented is worse than if they did nothing though. If they cared at all about security they would have pulled it down years ago when this vector being abused was first being reported by users. But nope admitting a mistake isn't in the vocabulary of. The leaders definitely know what they're doing.

Re: Scammers are abusing an internal Microsoft account to send spam links

#179
post #104

Earlier quoted context omitted.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…

A few UK banks detect that you're on a phone call and show a message like "we've never called you" or "we are not calling you right now" in their app, I think that's really smart.

The amount of behind the scenes work to get that set up seems impressive.

Re: Scammers are abusing an internal Microsoft account to send spam links

#180

I'm receiving daily about 20 to 30 spam mails from google servers. I'm sorting them into a separate SPAM folder for the "fun" of it. Who to contact? How to make Google stop? Where to report the abuse of their services? I can't find out. The whole service is basically a big off and "we don't want any contact." Maybe I also need to publish some article, so it can be published here on HN? Maybe that could give it some t…

[dead]
Post reply on HN