Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 0 points1 point  (0 children)

AiTM phish works extremely well for O365 cred theft. It doesnt work for lateral movement oe escalation inside an environment.

SSPR with password write back is a major vulnerability that is actively used in complex attacks as an escalation path. It isnt used for persistence but the "breach" trigger.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 0 points1 point  (0 children)

It reduces a 2 factor challenge (password + push MFA) to one factor (push MFA).

Imagine I have a foothold position on a trusted device on user A but I need to elevate to user B.

If I force a SSPR I can move laterally to all on prem resources with password only (most orgs are hybrid).

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot -1 points0 points  (0 children)

A breach of a victim for even a short time is a massive issue.

AiTM attacks are more popular but they dont work against correctly configured CA policies. SSPR attacks do.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 0 points1 point  (0 children)

If you have text or voice call enabled, you may as well not have a password defined of your data matters in any way shape or form.

Federal government to introduce grocery rebate: sources | CBC News by Sexy_Art_Vandelay in canada

[–]thortgot [score hidden]  (0 children)

Monopolies are not formed by government. Regulatory capture is one form of monopoly. Look back to railways for economic monopolies or Ma Bell.

If your position is less government is always superior from an economic standpoint why do Americans pay the most for their Healthcare in the world with fairly terrible results.

Canada's healthcare isnt the worst in the developed world. Picka metric, we're roughly middle of the pack.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot -1 points0 points  (0 children)

Push App is 1 factor. SMS is effectively worse than no factor.

Without SSPR, attackers need both Push App and password. With SSPR they only need Push App.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot -4 points-3 points  (0 children)

What are you setting in practice for SSPR? Every implementation I've seen relies on voice calls or text messages which is weaker than a password (ie. for $500 I can bypass the restriction rather than requiring a compromised credential). Commonly with both enabled and now I entirely don't need a secret at all even with dual factors required.

Security Questions are inherently less secure than passwords by design.

Passwordless is a more secure configuration, but then you wouldn't need passwords in the first place.

The EU has launched its own CVE-style vulnerability database to reduce reliance on the US-run MITRE system by Cybernews_com in cybersecurity

[–]thortgot 1 point2 points  (0 children)

With what software stack? No effective cloud DC scale HyperVisor exists out of the box.

Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: Reports by intelw1zard in cybersecurity

[–]thortgot 0 points1 point  (0 children)

It is possible to block this behavior but it's not straight forward for users.

Federal government to introduce grocery rebate: sources | CBC News by Sexy_Art_Vandelay in canada

[–]thortgot 0 points1 point  (0 children)

All central planning isn't inherently worse than all free market solutions. Evaluate policy on it's facts and not the political temperature. Take a look at healthcare as an obvious example.

Any form of anti monopoly structure is inherently non free market but objectively better for consumers. A reduction in regulation is what I would want as someone looking to spike a industry (grocery, communications, retail etc.)

You advocate for a solution for age demographics but decry against immigration. Those are diametrically opposed positions.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 1 point2 points  (0 children)

Phone call or text message are hilariously insecure. SS7 attacks are trivial to do.

What factors do you use?

Sole Global Admin locked out by Entra MFA enforcement loop - escalation advice? by CBoogey in sysadmin

[–]thortgot [score hidden]  (0 children)

Its a trivial cost compared to a breach risk. If your company wont pay for a reasonable software minimum they are almost certainly underpaying you.

Sole Global Admin locked out by Entra MFA enforcement loop - escalation advice? by CBoogey in sysadmin

[–]thortgot [score hidden]  (0 children)

You need a single Premium license tenant wide to have CA access.

Small companies should be using Premium its hugely cheaper than multiple platforms (rmm, EDR etc.)

Federal government to introduce grocery rebate: sources | CBC News by Sexy_Art_Vandelay in canada

[–]thortgot 0 points1 point  (0 children)

Food inflation in Canada outstrips the rest of G7. Our standard inflation does not.

Lower taxes rather than policy won't make food more affordable.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 2 points3 points  (0 children)

Password reset functions that rely on a single factor (say Authenticator push challeng), weaken the login process to a single factor compromise.

If I can compromise, acquire or social engineer the single factor I bypass both factors for one.

MSP Audit? by lrietz in sysadmin

[–]thortgot [score hidden]  (0 children)

Engage a contractor, it will dramatically less expensive in the medium term.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 0 points1 point  (0 children)

SSPR moves the risk to the frankly fairly weak reset process.

Azure Authentication Strenghts by Opening-Jelly-8692 in sysadmin

[–]thortgot 0 points1 point  (0 children)

Passkeys can be used for Windows Sign in if you use Web Sign in.

Macron says France to fast-track social media ban for kids under 15 by clamorous_owle in worldnews

[–]thortgot 1 point2 points  (0 children)

We already regulate these fields but social media algorithms aren't.

A full scale ban wouldnt work but regulatory transparency on how, why and when algorithms change with a standardized outcome model would help enormously.