News: 1631771887

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

It's time to delete that hunter2 password from your Microsoft account, says IT giant

(2021/09/16)


From this week, Microsoft won't require you, or your password manager, to come up with strings of letters, numbers, and special characters forming a silly sentence or a reconfiguration of an ex’s name and birthday to access the Windows giant's services.

That is to say, you can delete the password from your Microsoft account, and login using the Microsoft Authenticator app, Windows Hello, a security key, or a verification code sent to your cellphone or email inbox. When you set it up, you'll be rewarded with this chirpy dialog box...

But isn't this going down to single-factor authentication, you might be thinking. Well, the argument is that, for example, you need to not only have your phone in your hand but you must also be able to unlock it to run the [1]authenticator app , and then use your fingerprint or PIN to get into your account – and there's your multi-factor authentication.

The IT goliath has been building up to this for ages – in 2004, Bill Gates [2]predicted the death of passwords – and as recently as March it [3]made passwordless authentication in Azure Active Directory generally available. Now it's coming to Microsoft accounts and associated apps and services, plus or minus some caveats.

The rationale given for this is that humans forget passwords, assign obvious ones, and reuse their favorites, which leads to folks being locked out or preyed upon by miscreants who use weak, leaked, or reused passwords to break into people's accounts.

[4]

“Weak passwords are the entry point for the majority of attacks across enterprise and consumer accounts. There are a whopping 579 password attacks every second — that’s 18 billion every year,” Redmond veep Vasu Jakkal [5]claimed in announcing the news on Wednesday.

[6]

[7]

Jakkal had more numbers. From a survey, 15 per cent of people polled used their pets’ names as a password, 40 per cent say they’ve used a formula to create their passwords, and 10 per cent admitted they reused passwords. In a Twitter poll, 20 per cent of respondents said they would rather accidentally and embarrassingly “reply all” to a message than go through the hassle of resetting a password.

Additionally, the tech giant said nearly 100 per cent of its employees are passwordless when it comes to their corporate accounts.

[8]Log right in, the water's fine, whispers Microsoft as it adds autofill to Authenticator app

[9]We can't believe people use browsers to manage their passwords, says maker of password management tools

[10]GitHub picks Friday 13th to kill off password-based Git authentication

[11]The Microsoft Authenticator extension in the Chrome store wasn't actually made by Microsoft. Oops, Google

This password-free login approach isn't available right across Microsoft's vast empire, though it can be used with "apps and services like Microsoft 365, Microsoft Teams, Outlook, OneDrive, Family Safety, Microsoft Edge and more," we're [12]told . Office 2010 or older, Remote Desktop, and Xbox 360 will require a password. And for signing into Windows, you need to be on version 10 or 11.

The reversible process for ditching a password involves downloading and linking the Microsoft Authenticator App to your personal Microsoft account, going to your account settings, navigating to Advanced Security Options and then Additional Security Options, and turning on Passwordless Account.

[13]

Now all you have to do is keep your other authentication methods safe and secure. ®

Get our [14]Tech Resources



[1] https://support.microsoft.com/en-us/account-billing/how-to-use-the-microsoft-authenticator-app-9783c865-0308-42fb-a519-8cf666fe0acc

[2] https://www.theregister.com/2019/03/05/web_authentication/

[3] https://www.theregister.com/2021/03/03/microsoft_ups_security/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUMV38S39eZwnEKWa64BmgAAAYg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.microsoft.com/security/blog/2021/09/15/the-passwordless-future-is-here-for-your-microsoft-account/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUMV38S39eZwnEKWa64BmgAAAYg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUMV38S39eZwnEKWa64BmgAAAYg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2020/12/16/authenticator_autofill/

[9] https://www.theregister.com/2021/07/30/infosec_risky_behaviours_study/

[10] https://www.theregister.com/2021/08/12/git_proxyshell_gigabyte/

[11] https://www.theregister.com/2021/05/19/chrome_extension_microsoft_authenticator_fake/

[12] https://blogs.windows.com/windowsexperience/2021/09/15/microsoft-announces-passwordless-future-available-across-microsoft-edge-and-microsoft-365-apps/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUMV38S39eZwnEKWa64BmgAAAYg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Potemkine!

What a nice move: It associates your windows installation with a device linked to a physical, nominative person and which tracks user' moves by GPS. Privacy is so 20th century....

Connecting anything with a phone is such a brilliant idea: loose it, break it or may the phone be stolen, and then you cannot log to your PC anymore.

Exactly...

ShadowSystems

What if you use a physical UbiKey to authenticate yourself, but then misplace the danged thing 'cuz yer gettin' old 'n forgetful? Like when you turn the house upside down to find your glasses only to scratch your head in confusion & realize they've been sitting atop your skull the entire time. Only the device is much smaller & easier to misplace. You'll spend hours tearing the house apart, finally give up in frustration, go to get some ice out of the freezer to apply to your throbbing forehead and find the fekkin' thing sitting atop the frozen peas. It's almost like MS is *taunting* Loki & chortling "Do yer worst, ChaosBoy!" What could possibly go wrong? Don't bother answering that one, we all know the favorite reply of Murphy is "Here, let me show you!"

Re: Exactly...

jonathan keith

If you're using YubiKey, the advice is that you have two keys, and to keep the second in a safe place as a fallback if you lose your principal key.

"in a safe place"

Mishak

I know someone who tried that. Had the keys for years, lost the one in daily use and couldn't remember where the "safe place" used for the other was...

Re: "in a safe place"

Anonymous Coward

There's no cure for "stupid" ;)

chuBb.

No less privacy than logging in to whatever service you need in the first place.

If your really concerned about privacy get proactive, old phone in drawer root it, install a hardened droid os, keep it in flight mode, only connect to trusted WiFi and only install the authenticator app of choice (preferably side loaded and app store is neutered)

By and large this is a good thing for Corp it (phishing and rat attacks will be less effective), and power users will bother for personal accounts, aunty Doris will still rely on rover1966 for everything and be shocked and horrified that the nice African Prince she's been emailing is in fact a scam

No MS account

LenG

Are we approaching a point where I will have to have a M$ account just to log into my Windoze desktop machine? Time to start migrating my games to linux ... after all, games are the only good reason to have windoze to start with.

Re: No MS account

chuBb.

Bad news that happened with the win 10 creators update 2 years ago, have to jump through quite a few hoops on a fresh win 10 install to create a "limited" local account and not use one linked to azure ad...

Re: No MS account

LenG

Last time I installed a fresh WIn 10 (pro), last year, it was easy enough to bypass the M$ account restriction by disconnecting from the internet at the right point. When it cannot reach the M$ servers it allows you to continue with a local account and doesn't demand any change after you reconnect.

Re: No MS account

Charlie Clark

Already there and beyond. It's no longer possible to set up Outlook manually for an on premise Exchange – I hate Outlook but need to be able to use it to help the users better.

Re: No MS account

Anonymous Coward

run: outlook.exe /manageprofiles

Paul Crawford

So this app is on your phone, which many also use to access their services (yes, even though MS stuff sucks on phones even more than Windows desktop...) so other log-in details are probably saved. So if you have the phone you are probably a 4 digit code, partly smudged on the screen already, away from full access to all MS services?

And if your phone is lost/stolen, how do you authenticate yourself to assign a new one?

Chris G

The only windows thing that goes through my phone is Outlook and I intend to keep it that way, I also have a minimum of apps and thode I do have only get the permissions that are absolutely necessary.

What permissions does the authentification app want on your phone as a matter of interest?

If this is forced on us, it will be yet another reason to jump ship, why should I need to fire up one device in order to fire up another?

Doesn't sound much like progress to me.

Anonymous Coward

"And if your phone is lost/stolen, how do you authenticate yourself to assign a new one?"

1) Multiple devices, synced (*). This is easy, I've been doing it for years with the right authenticator app. In the case of Microsoft, you just put Authenticator on your iPad or spare phone or whatever as well as your main phone - they all then beep when you try to sign in anywhere.

2) Recovery codes. Bit of a pain as you need to store them securely somewhere - either on paper in a safe or in an app that securely syncs (*) or is accessible (*) on different devices. User education ('do not panic!') is quite tricky here.

3) Rely on your IT admin to be able to reset the access on your account for you. Obvs no cop for personal accounts.

(* avoiding the subject of how secure, or not, syncing devices across the 'cloud' is etc).

Pseudononymous Coward

So I've got to buy a spare phone now. And figure out where to keep it where it can never be stolen.

Or a safe.

Thanks for nothing.

There and back again

Shak

So after pushing 2FA for yonks, the advice is to go back to a single factor again?

Or is this just a fancy system generated password in disguise?

Re: There and back again

Geoff Campbell

No, this is still 2FA. You need the device with the authenticator App installed, plus a biometric confirmation.

GJC

A pain in the rear end

Anonymous Coward

We have this on our work phones.

Notification comes in.

Unlock work phone with PIN because it is a Samsung and the fingerprint sensor sucks.

Enter same PIN used to unlock phone.

So I end up entering the same PIN twice.

Re: A pain in the rear end

Anonymous Coward

You're holding the phone (first factor: the phone)

Only you can unlock it (second factor: you)

= Two factor authentication. Both must be present.

Re: A pain in the rear end

tonique

At $work, we are required to use a six-number pin so I have to enter that twice. No, you can't use the fingerprint reader.

Hubert Cumberdale

What stood out to me from this was the idea of logging in to MS Edge. Two questions: (1) There's little enough privacy on the internet as it is, so why would I ever do that? (2) Who actually intentionally uses Edge (as in, you know, anyone who hasn't been tricked into it by MS because they simply don't know any better)?

Chris G

Looks like one of the developers is reading the comments!

Microsoft is dogfooding their own advice on Azure VM...

pklausner

become root w/o any authentication whatsoever

https://twitter.com/amiluttwak/status/1437898746747097090

Bonkers

Mage

The problem isn't passwords, but bad password management.

Famous last words:
(1) Don't unplug it, it will just take a moment to fix.
(2) Let's take the shortcut, he can't see us from there.
(3) What happens if you touch these two wires tog--
(4) We won't need reservations.
(5) It's always sunny there this time of the year.
(6) Don't worry, it's not loaded.
(7) They'd never (be stupid enough to) make him a manager.
(8) Don't worry! Women love it!