• lnxtx (xe/xem/xyr)@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    41
    arrow-down
    1
    ·
    16 days ago

    Automated time-capsule emails: Once you finally sort out standard TOTP, Microsoft sends you an automated setup email enthusiastically asking if you need help configuring your Zune, BlackBerry, or Office 2010.

    🥹

  • lemmyvore@feddit.nl
    link
    fedilink
    English
    arrow-up
    19
    ·
    16 days ago

    My MS account is doing a thing lately where I have to enter the TOTP twice to login successfuly. It has to be two different TOTPs, too, can’t enter the same one; I have to literally wait until the first one expires and get another one.

    Didn’t experience any of the other shenanigans described in the article though, so there’s that.

    • Goun@lemmy.ml
      link
      fedilink
      English
      arrow-up
      6
      ·
      16 days ago

      TOTP is time based, I’d check the time on the device just in case. Having to enter multiple codes must be so annoying!

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        4
        ·
        16 days ago

        I have the machine synced with NTP and I’m not seeing any time issues.

        It’s such a super specific quirk, too, that I can’t believe it’s not on their side.

        Maybe they’ve decided that TOTP is less secure than passkeys and if I refuse to use passkeys with their app I should be “helped” 😃 by using twice the amount of TOTP?

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      ·
      16 days ago

      I have a few networks where I get the notice but must disconnect from the wifi to approve over my mobile connection instead

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    3
    ·
    16 days ago

    Microsoft can’t properly gate a push notification behind a password check?

    Careful now. If you put the MFA prompt after the password, it works as confirmation that you have the correct password even if you’re not able to log in. You don’t want to give that confirmation to the attacker. That’s why MFA happens before the password is validated.

    • lemmydividebyzero@reddthat.comOP
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      16 days ago

      You don’t want to give that confirmation to the attacker.

      That’s how it works on > 90% of the websites on the internet. And that’s usually not a problem, because one usually does not suddenly know the password of other people.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      16 days ago

      Just set a timer after entering the password in every single case (only stopped early by successful MFA). “authentication did not succeed, one or more factors may be incorrect or may have failed verification”

  • LiveLM@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    ·
    16 days ago

    This is why I’ve always preferred to enter the TOTP code myself instead of using the “Approve Sign-In” method.

    Also the thing about the Redirect Loops and wacky login forms. Goddamn how come they ain’t fix it yet 😭

    • lemmydividebyzero@reddthat.comOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      16 days ago

      Also the thing about the Redirect Loops and wacky login forms. Goddamn how come they ain’t fix it yet 😭

      At this point, it’s tradition that it’s that f*cked up. Can’t change that now…

    • filcuk@feddit.uk
      link
      fedilink
      English
      arrow-up
      4
      ·
      15 days ago

      Using a lot of ms services at work. If I leave 10 tabs open, I get 10 individual login popups in the morning. I like to assume there is some reason behind this I’m too dumb to understand, because it is very obviously not good UX and very annoying.

      • Flatfire@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        15 days ago

        Token expiry. Because the same login token is used across many services, it expires at the same time. Of course, because the tabs are all open, they just know you need to log in again, not whether you’ve got other services open that also use your account.

  • Shadow@lemmy.ca
    link
    fedilink
    English
    arrow-up
    4
    ·
    16 days ago

    I got hammered with ms auth requests for weeks before I finally just changed it to a dedicated email address. Really frustrating.

    • bitwolf@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      16 days ago

      Teams drains like 30% of my phone battery every hour. It’s crap.

      I just removed it from my phone and deal with carting my work machine around.

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    16 days ago

    And sure, you could also create a new alias and migrate your sign-in preference to dodge the spam, but why should I have to restructure my whole frigging identity just because Microsoft can’t properly gate a push notification behind a password check?

    Why indeed.

  • setVeryLoud(true);@lemmy.ca
    link
    fedilink
    English
    arrow-up
    3
    ·
    15 days ago

    Yeah? This has been a thing for years. We were training people at my previous place of work to ignore MFAs that did not originate from an action they took.

  • bitwolf@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    16 days ago

    I disabled t use Microsoft Authenticator, I use passkeys and aegis Authenticator.

    You don’t get away from it this way either.

    Instead, it manifests as needing to reset your password every, single, time you log in. Because of “too many incorrect sign in attempts”.

    The bots can’t do anything bc the account is passwordless. But it doesn’t stop Microsoft’s annoying “security” features.

    So I constantly have to reset a password that is never even used.

  • THE_GR8_MIKE@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    16 days ago

    Yep. I get an influx of them when I shit talk the diaperpedonazi in charge on certain platforms. Kind of funny.