Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

21–30 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#21

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Microsoft is the 4th largest company in the world.

There should be a long list of companies whose policies are worse than theirs.

Re: Scammers are abusing an internal Microsoft account to send spam links

#22
post #12

Earlier quoted context omitted.

Such a list will never exist in an organisation of this size, with the amount of delegated management and operations required for these functions. In fact, it’s unlikely such a list is even _allowed_ to exist given the sensitive nature of some areas of the business, being a publicly traded company which works directly with regulated entities and governments. It’d be interesting to hear a senior old-timer from MS to w…

> In fact, it’s unlikely such a list is even _allowed_ to exist given the sensitive nature of some areas of the business, being a publicly traded company which works directly with regulated entities and governments. If the existence of a domain/subdomain is considered sensitive information, then something has gone very wrong.

Companies do register domains before launching products and don't want to leak them. Now, I still support Microsoft and other companies to list the domains they send official emails from.

Re: Scammers are abusing an internal Microsoft account to send spam links

#24

Earlier quoted context omitted.

> In fact, it’s unlikely such a list is even _allowed_ to exist given the sensitive nature of some areas of the business, being a publicly traded company which works directly with regulated entities and governments. If the existence of a domain/subdomain is considered sensitive information, then something has gone very wrong.

Companies do register domains before launching products and don't want to leak them. Now, I still support Microsoft and other companies to list the domains they send official emails from.

Why would that not be possible? You can still do that and then once the rabbit is out add it to the main list. Come on, don't let the good be the enemy of the perfect. I'm sure there are several ways to find and list all domains. What bothers me more is that they allowed to have different domains in the first place. Why not sub domains to make it clear.

Re: Scammers are abusing an internal Microsoft account to send spam links

#25

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

Re: Scammers are abusing an internal Microsoft account to send spam links

#26

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

> Who even can be sure microsoftonline.com is legit.

Yeah. I queried the 1st thing that came to mind and internalmicrosoft.com and microsoftinternal.com are available. With that much potential out there, I'd want to keep my official domain group tight.

Re: Scammers are abusing an internal Microsoft account to send spam links

#27

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

> Who even can be sure microsoftonline.com is legit

Spam filters.

Re: Scammers are abusing an internal Microsoft account to send spam links

#28

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

> unable publish a list with all domains they officially use to send mail That's because people report them as spam, so they hop domains to avoid that.

Okay, so then they should stop doing stuff like trying to push people to log into Windows with Microsoft accounts instead of offline credentials and then using that as an excuse to send out inane marketing emails that no one wants. "We're doing something shitty as a workaround for the consequences of other shitty things we do" isn't a particularly good reason for not acting so shitty.

Re: Scammers are abusing an internal Microsoft account to send spam links

#29
post #27

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

> Who even can be sure microsoftonline.com is legit Spam filters.

I'm either impressed by whatever spam filter you having literally zero false positives or negatives, or I'm confused about what you think it means to "be sure".

Re: Scammers are abusing an internal Microsoft account to send spam links

#30

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

That would take nothing to implement. Services like Truecaller already do live caller ID against databases on iOS / Android. All it would take is a sensible register of verified numbers
Post reply on HN