this post was submitted on 17 Feb 2024
137 points (96.6% liked)
techsupport
2944 readers
1 users here now
The Lemmy community will help you with your tech problems and questions about anything here. Do not be shy, we will try to help you.
If something works or if you find a solution to your problem let us know it will be greatly apreciated.
Rules: instance rules + stay on topic
Partnered communities:
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Happened to me too yesterday. Gave me a big bump to my evening plans. Luckily I too have 2fa activated via 2 different systems {SMS AND second Mail address). They cracked my randomly generated password - which doesn't surprise me that much, brute force cracker are pretty effective nowadays.
What bums me is that I used this as an argument to teach a friend but he just used the same ol' reliable "naah, I'm too lazy". Can't change him, just told him to think about using 2fa everywhere money is involved. The rest is up to him.
What's also pretty bad from MS is that yes you can use several different mailadresses but no you can't prevent that all of them can be used as login. One is compromised but also used for mail traffic so I can't just delete it. But also can't prevent it from logging in to the account. Thanks MS..
I'm actually surprised that it'd be feasible to use a brute force approach to gain access to an online account. I would expect them to hit some kind of rate-limiting long before they'd find the correct password
Looking at my history, they're hours or a day apart. Probably no chance of getting into any halfway decent password that way, but if they can automate it with thousands of different email addresses, eventually they'd get an account with a weak password and get in.