this post was submitted on 03 Aug 2024
18 points (95.0% liked)

Cybersecurity

5618 readers
222 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
 

I have a question for the hive mind: what is the point of this, exactly?

I mean, I understand the attempt to gain access, and I understand why 2fa codes can be valuable to attempt to phish but that's like, not the thing here.

They just spam dozens to hundreds of these (I'm showing over 400 in my inbox right now) but like, even if I WANTED to give these codes to the attacker, I have no damn clue who the dude in China that's doing this is.

I'm confused as to what they hope to gain by trying over and over and over every couple of hours because it feels like there's no upside to whomever is running this bot, but I probably have missed a memo on some TTP around this, heh.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 9 points 3 months ago (1 children)

For the record you should probably change your password. That way they can’t even try.

[–] [email protected] 6 points 3 months ago (2 children)

Some Microsoft services don't ask for your password anymore, they just send you a code to your register email.

[–] [email protected] 1 points 2 months ago

Yeah it turns out that's what nonsense this is.

Worse, I sure as crap never opted into this, but at least you can turn it off.

What a stupid decision some product manager made.

[–] [email protected] -3 points 3 months ago (2 children)
[–] [email protected] 8 points 3 months ago

Not when that password is just an email...

[–] [email protected] 2 points 3 months ago

❤️ Passkeys.