Earlier quoted context omitted.
I'm not gonna get hoodwinked into highbrow shenanigans. Social media doesn't need IDs to work, demanding it is a scam.
Defining a word isn't "highbrow shenanigans", although I guess it depends on how you define that.
Scammers are abusing an internal Microsoft account to send spam links
171–180 of 196 posts
Re: Scammers are abusing an internal Microsoft account to send spam links
#172Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.
Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.
Re: Scammers are abusing an internal Microsoft account to send spam links
#173On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…
Re: Scammers are abusing an internal Microsoft account to send spam links
#174Earlier quoted context omitted.
In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…
Unfortunately in the US, maybe elsewhere, pharmacies and medical offices have trained the elderly it’s okay to verify their dob when they call. Costco does that when they call and it drives me nuts.
Re: Scammers are abusing an internal Microsoft account to send spam links
#175Earlier quoted context omitted.
Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…
This is very much my experience. I generally say at some point before terminating the call "you should not train your customers to give out account access credentials to strangers" and the caller usually has no clue what I mean. Does no one in the security teams have theory of mind? This will be the way I bring up the issue with the regulator if I do. I can think of many ways round this issue that would be much safer…
The chucklefuck that wrote the script that you can get mad at won't pick up your calls.
That's how responsibility works.
Re: Scammers are abusing an internal Microsoft account to send spam links
#176Earlier quoted context omitted.
We pay for a bunch of old domains because nobody in the org can definitively say we never used it and/or don’t use it anymore. Easier to just keep paying.
Not only have you stopped using it, but did any of your customers ever allow list it in the past? Great way to attack customers of some large businesses if you ever see it happen.
Re: Scammers are abusing an internal Microsoft account to send spam links
#177On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…
Yes it is completely broken. Everyone should disable microsoft authenticator and uninstall it. It is a massive vector.
Re: Scammers are abusing an internal Microsoft account to send spam links
#178Earlier quoted context omitted.
Yes it is completely broken. Everyone should disable microsoft authenticator and uninstall it. It is a massive vector.
Yes, there are so many other 2FA authenticators, many of them even open-source. Why would you ever use the Microsoft one?
Re: Scammers are abusing an internal Microsoft account to send spam links
#179Earlier quoted context omitted.
In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…
A few UK banks detect that you're on a phone call and show a message like "we've never called you" or "we are not calling you right now" in their app, I think that's really smart.
Re: Scammers are abusing an internal Microsoft account to send spam links
#180I'm receiving daily about 20 to 30 spam mails from google servers. I'm sorting them into a separate SPAM folder for the "fun" of it. Who to contact? How to make Google stop? Where to report the abuse of their services? I can't find out. The whole service is basically a big off and "we don't want any contact." Maybe I also need to publish some article, so it can be published here on HN? Maybe that could give it some t…