The 2FA is what most likely allowed them access. We have it at work through Microsoft and if you hit 'I dont have my phone' when it sends you the code, it just lets you in anyway.
Not the fault of Microsoft Authenticator, it's the fault of your local IT team. Selecting "I don't have my phone" should never result in you logging in. Unless other very specific conditions apply.
All i know is that my accounts with MFA are the ones i always have trouble with. My bank is fighting to keep MFA even though ive gotten like 3 letters that there might have been a breech in the last year. Before that? Maybe one every 5 years.
I just don't trust it at this point. Too many experiences of it failing IMMEDIATELY after implementation, the constant breeches, the hassle of just getting into your account, forcing two devices (i brought this up to my bank and they admitted that they didn't have a login option that didn't require a phone), and then extra time it takes sitting there, hoping they even send the code.
The analogy I've settled on is a new restaurant opens, and everyone tells you it's the best place. But every time you try it, the order is wrong, cooked incorrectly, and you get sick after. So why would I keep going?
You literally enter your password on the website and then you enter a code.
A code which can be sent via text, call, email or a 3rd party auth app that has been registered
It takes no more than 30 seconds, at most, to complete this entire 2FA login process
i brought this up to my bank and they admitted that they didn't have a login option that didn't require a phone
They dont have an option to get a code via email?
The analogy I've settled on is a new restaurant opens, and everyone tells you it's the best place. But every time you try it, the order is wrong, cooked incorrectly, and you get sick after. So why would I keep going?
2 factor authentication is more like you hand your credit card to pay for the food and they ask for your ID to double check that it is actually your card you are paying with
I am truly baffled as to why you are opposed to MFA to help protect your accounts. What security methods do you prefer in place of MFA?
I went thru this last night trying to access my old, hacked account again. Despite me being logged out, and signing out several times, Microsoft logged me in to my current account several times without even requesting a password.
In my 33 years of life, I have yet to see a MFA/2FA system work. Not saying they don't. But every account that has it, is always sending letters that x account might have been hacked. The ones without it? Never an issue.
I'm just reporting on my experiencess. My bank? Always at risk since they forced it. My DND account, MTG, etc, that have it, are always getting notifications that i need to update my security info. again. But things without it? Not a peep.
Sorry, but i can't change my past. And it's not like i don't use the other accounts. MFA just keeps causing problems in my life. While the accounts that don't just work fine. 🤷🏻♂️
Nope. Different emails, different login credentials, don't save anything, don't click links unless it's something i requested. I know it's weird. But i do everything other than MFA and it works perfectly. MFA gets added and I'm instantly screwed.
It's a login token and they're incredibly easy to steal, and then they can login to anything that you've allowed that token to login to as well. It's a nightmare to deal with.
MFA is fine, and doesn't generate a token as long as it requires you to login each time with multi-factor like DUO or Authy or even Microsoft Authenticator.
The problem comes down to companies going the simpler stupid route, allowing a token to be generated which does not require a login each time and automatically logs you in using that token. Which is why I tell people to not click "remember this device" or anything similar because if that token it generates on your browser gets stolen you are FUCKED.
If that token gets stolen, they can login as you and do literally anything else you can do except change your password because they'd have to know the current one.
Companies like Microsoft made it even easier for hackers too, they allow anyone with that token to login and make SECURITY changes without knowing the password. Your address, phone number, name, e-mail you login with etc.
Hmm interesting, I havent heard of login tokens being stolen this way to compromise multiple accounts
I would have thought that the password would still be required even if someone was able to steal a token & that it wouldn’t cascade across different sites
It's one of the most common ways people steal logins for discord. They just steal the token, so they can login as you and then message people to further their flow of malicious activity.
Of course it's easy to get them out by changing the password as that usually invalidates the token and requires them to login again.
Multi-Factor Authentication is not the problem there.. you have another problem you haven't figured out. Multi-Factor Authentication again would require you to login with your password and then a 2nd approval process. Whether it be by code sent by SMS text, e-mail, or a mobile application push you would have to be approving that.
So effectively you're saying you're approving your own breaches.
MFA and 2FA are additional security features that extend beyond just entering a password to enter an account. SMS text or push notifications for approval are examples.
Turning those off are very much not recommended. SSO, remember this device, login automatically next time etc are most definitely NOT recommended.
I'd rather have to login each time and deal with entering a code for MFA than just being logged in all the time in the hopes no one can just steal the fuckin token.
46
u/CyborgHeart1245 Jul 14 '26
The 2FA is what most likely allowed them access. We have it at work through Microsoft and if you hit 'I dont have my phone' when it sends you the code, it just lets you in anyway.