Live data from Hacker News

Microsoft became incompetent in IT

mikekaganski.wordpress.com

41–50 of 160 posts

Re: Microsoft became incompetent in IT

#41

This kind of issue is absurdly common. I’ve seen basically the same thing with Microsoft, Amazon and Google—personally and with others. With Google, it’s well-documented that sometimes, even if you don’t have 2FA turned on and you know your password, they simply won’t let you log in without some sort of additional verification… which may not be possible. This hit me once while overseas, I think I managed to get in by…

These businesses are all about scale. Each user makes them a paltry amount of money, but they have an enormous number of users.

A single support incident that reaches a paid worker on their side costs them more than the profit you’ve brought them for the year. It probably costs them more than the profit you’ll bring them for your entire life.

With less scale-y businesses, it’s worth it for them to put some effort into fixing problems, as an investment in your future business. Here, the only reason would be to avoid reputational damage. And who’s going to stop using Google or Microsoft because some guy had trouble getting support?

There’s a story (no doubt apocryphal) about Bill Gates telling people working on Windows that a customer calling their support line cost as much as the profit they made selling that copy of Windows. The point was to make it so Windows users didn’t need to call support by making Windows work better. The modern equivalent of this would be to make sure that users can’t reach expensive support in the first place.

Re: Microsoft became incompetent in IT

#43
post #18

Also if you have multiple microsoft 365 accounts, switching between those in the webapp seems to be impossible for years already. There's a switch account option, you can click it and sign in to another account, except you just stay logged in as the previous account.

Firefox "Containers" are great for this. I have color-coded tabs for various customer work accounts / tenants.

Yes, they are a life-saver. I use them all the time for various AWS accounts. The guy who told me about it years ago has saved me countless hours.

Re: Microsoft became incompetent in IT

#45
post #39

I think that they just wanted your mobile phone number in order to do 2 factor logins and they don't know how to do it without breaking the day with their inept system messaging and inputs.

They rejected the number for unblocking purposes but I'm damn sure they saved it somewhere as a data point for that account to sell/use later.

Re: Microsoft became incompetent in IT

#46
post #40

> But this, once an IT tech leader, became utterly incompetent in IT. And for me, it’s a pity. The rose tint is strong in these glasses. When was their support great? Or is the author simply confused about what tech they were a lead in?

wasnt it in the vista days that ms went "let them eat forum" and basically yeeted all of their support >?

Re: Microsoft became incompetent in IT

#47

This kind of issue is absurdly common. I’ve seen basically the same thing with Microsoft, Amazon and Google—personally and with others. With Google, it’s well-documented that sometimes, even if you don’t have 2FA turned on and you know your password, they simply won’t let you log in without some sort of additional verification… which may not be possible. This hit me once while overseas, I think I managed to get in by…

These businesses are all about scale. Each user makes them a paltry amount of money, but they have an enormous number of users. A single support incident that reaches a paid worker on their side costs them more than the profit you’ve brought them for the year. It probably costs them more than the profit you’ll bring them for your entire life. With less scale-y businesses, it’s worth it for them to put some effort int…

I feel like once they've gotten everyone on the planet using their services, and then fucked them all over, maybe then there'll be a market un-fucking them over.

Re: Microsoft became incompetent in IT

#48

This kind of issue is absurdly common. I’ve seen basically the same thing with Microsoft, Amazon and Google—personally and with others. With Google, it’s well-documented that sometimes, even if you don’t have 2FA turned on and you know your password, they simply won’t let you log in without some sort of additional verification… which may not be possible. This hit me once while overseas, I think I managed to get in by…

These businesses are all about scale. Each user makes them a paltry amount of money, but they have an enormous number of users. A single support incident that reaches a paid worker on their side costs them more than the profit you’ve brought them for the year. It probably costs them more than the profit you’ll bring them for your entire life. With less scale-y businesses, it’s worth it for them to put some effort int…

With enough eyeballs all bugs are shallow.

What would be the opposite?

With enough blindfolds all bugs are unimportant?

Re: Microsoft became incompetent in IT

#49

This kind of issue is absurdly common. I’ve seen basically the same thing with Microsoft, Amazon and Google—personally and with others. With Google, it’s well-documented that sometimes, even if you don’t have 2FA turned on and you know your password, they simply won’t let you log in without some sort of additional verification… which may not be possible. This hit me once while overseas, I think I managed to get in by…

>even if you don’t have 2FA turned on

Presumably the excuse is that it happens because you don't use 2fa and your ip changed, but I heard 2fa might not save you either.

Re: Microsoft became incompetent in IT

#50
All of the tech giants have really broken account recovery flows. They've all been glomming on recovery options, single sign-on, 2FA, etc features and none of it is coherent, with lots of dead ends where the optional recovery option it suggests isn't actually supported.

Amazon has a lot of issues with accounts shared between their national storefronts. I lost a Google account that owns a YouTube channel since it wants to 2FA to a long-gone phone number. Apple has a lot of oddities when you used different emails for your Apple ID, iTunes Connect, and iTunes before they unified everything.

One great example though is Facebook

My wife's Facebook account recently got hacked, and I managed to recover it though this crazy workflow:

The hacker had removed her email address and phone number from the account, changed her password, and added their controlled Meta account as a connected account. This connected account had an email but no password, so it could not be removed without adding a password to it, which required verifying the attackers email address.

None of the account recovery tools worked (including the “this wasn’t me” link in the Facebook “did you just delete your phone number” email - what is the point of that link) - they couldn’t find her account by email or phone number, and even though the Facebook app itself was still logged in, none of the account center tools allowed us to do anything without the new password. It also did not allow us to remove the connection to the hackers Meta account or log it out from their devices because it had no password and it would become orphaned with no login.

What seems to have worked for us:

1. Open the still-logged-in FB Messenger app on her phone. It now asks to add a phone number to enhance security. We did this.

2. Now install WhatsApp and sign up using the phone number.

3. Now go into the Facebook app, change password, I forgot my password, and use WhatsApp as 2-factor authentication.

4. Now we have control of the password again! We also added a app (TOTP) 2-factor authentication and iOS passkey to her account at this point to add more options for control.

5. Go to Meta Quest website (meta dot com), and log in via Facebook. This logs us into the attackers account!

6. We could now add a 2-factor authentication to the hackers account, after which it also now let us change the password of the attackers account without knowing the old one.

7. With a password on the account, we can now log them out of all other devices (the attackers phone).

8. We could also now change the permissions so the attackers Meta account could not be used to log in to her Facebook account, but it’s still listed as a related account since it requires email confirmation to remove.

9. Managed to use the 2-factor code to reset the email address on the attackers meta account, so now we own it completely!

Post reply on HN