#microsoftauthenticator — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #microsoftauthenticator, aggregated by home.social.
-
Critical Microsoft Authenticator Flaw Puts Accounts At Risk #apps #microsoft #microsoftauthenticator
https://www.lowyat.net/2026/393331/critical-microsoft-authenticator-flaw-puts-accounts-at-risk/
-
Critical Microsoft Authenticator Flaw Puts Accounts At Risk #apps #microsoft #microsoftauthenticator
https://www.lowyat.net/2026/393331/critical-microsoft-authenticator-flaw-puts-accounts-at-risk/
-
Critical Microsoft Authenticator Flaw Puts Accounts At Risk #apps #microsoft #microsoftauthenticator
https://www.lowyat.net/2026/393331/critical-microsoft-authenticator-flaw-puts-accounts-at-risk/
-
Critical Microsoft Authenticator Flaw Puts Accounts At Risk #apps #microsoft #microsoftauthenticator
https://www.lowyat.net/2026/393331/critical-microsoft-authenticator-flaw-puts-accounts-at-risk/
-
Critical Microsoft Authenticator Flaw Puts Accounts At Risk #apps #microsoft #microsoftauthenticator
https://www.lowyat.net/2026/393331/critical-microsoft-authenticator-flaw-puts-accounts-at-risk/
-
Microsoft deixará de usar SMS para enviar códigos de autenticação
-
@emilion in https://infosec.exchange/@emilion/116595960854703567: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.
I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.
A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's https://www.heise.de/en/news/Microsoft-Authenticator-Critical-vulnerability-allows-token-theft-11296758.html).
Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: https://techcommunity.microsoft.com/blog/microsoft-entra-blog/all-your-creds-are-belong-to-us/855124).
People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.
#Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator
-
@emilion in https://infosec.exchange/@emilion/116595960854703567: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.
I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.
A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's https://www.heise.de/en/news/Microsoft-Authenticator-Critical-vulnerability-allows-token-theft-11296758.html).
Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: https://techcommunity.microsoft.com/blog/microsoft-entra-blog/all-your-creds-are-belong-to-us/855124).
People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.
#Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator
-
@emilion in https://infosec.exchange/@emilion/116595960854703567: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.
I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.
A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's https://www.heise.de/en/news/Microsoft-Authenticator-Critical-vulnerability-allows-token-theft-11296758.html).
Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: https://techcommunity.microsoft.com/blog/microsoft-entra-blog/all-your-creds-are-belong-to-us/855124).
People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.
#Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator
-
@emilion in https://infosec.exchange/@emilion/116595960854703567: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.
I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.
A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's https://www.heise.de/en/news/Microsoft-Authenticator-Critical-vulnerability-allows-token-theft-11296758.html).
Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: https://techcommunity.microsoft.com/blog/microsoft-entra-blog/all-your-creds-are-belong-to-us/855124).
People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.
#Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator
-
#MicrosoftAuthenticator: Kritische #Sicherheitslücke ermöglicht Token-Diebstahl
https://www.heise.de/news/Microsoft-Authenticator-Kritische-Sicherheitsluecke-ermoeglicht-Token-Diebstahl-11296717.htmlIch habe das auch mal auf meinem Artikel "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" https://karl-voit.at/2023/03/05/TOTP-Auswahl/ dazugenommen.
Wenn man von dem Vorfall Generelles ableiten möchte, bleiben eigentlich nur noch Hardware-Tokens für #FIDO2 übrig, wenn man #Phishing ausschließen möchte.
Sogar #Passkeys helfen leider nicht (mehr): https://karl-voit.at/FIDO2-vs-Passkeys/
#Authenticator #TOTP #FIDO2 #publicvoit #20230304_TOTPAuswahl #MFA #2FA #20241005_FIDO2VsPasskeys #Authentifizierung #Sicherheit
-
#MicrosoftAuthenticator: Kritische #Sicherheitslücke ermöglicht Token-Diebstahl
https://www.heise.de/news/Microsoft-Authenticator-Kritische-Sicherheitsluecke-ermoeglicht-Token-Diebstahl-11296717.htmlIch habe das auch mal auf meinem Artikel "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" https://karl-voit.at/2023/03/05/TOTP-Auswahl/ dazugenommen.
Wenn man von dem Vorfall Generelles ableiten möchte, bleiben eigentlich nur noch Hardware-Tokens für #FIDO2 übrig, wenn man #Phishing ausschließen möchte.
Sogar #Passkeys helfen leider nicht (mehr): https://karl-voit.at/FIDO2-vs-Passkeys/
#Authenticator #TOTP #FIDO2 #publicvoit #20230304_TOTPAuswahl #MFA #2FA #20241005_FIDO2VsPasskeys #Authentifizierung #Sicherheit
-
#MicrosoftAuthenticator: Kritische #Sicherheitslücke ermöglicht Token-Diebstahl
https://www.heise.de/news/Microsoft-Authenticator-Kritische-Sicherheitsluecke-ermoeglicht-Token-Diebstahl-11296717.htmlIch habe das auch mal auf meinem Artikel "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" https://karl-voit.at/2023/03/05/TOTP-Auswahl/ dazugenommen.
Wenn man von dem Vorfall Generelles ableiten möchte, bleiben eigentlich nur noch Hardware-Tokens für #FIDO2 übrig, wenn man #Phishing ausschließen möchte.
Sogar #Passkeys helfen leider nicht (mehr): https://karl-voit.at/FIDO2-vs-Passkeys/
#Authenticator #TOTP #FIDO2 #publicvoit #20230304_TOTPAuswahl #MFA #2FA #20241005_FIDO2VsPasskeys #Authentifizierung #Sicherheit
-
#MicrosoftAuthenticator: Kritische #Sicherheitslücke ermöglicht Token-Diebstahl
https://www.heise.de/news/Microsoft-Authenticator-Kritische-Sicherheitsluecke-ermoeglicht-Token-Diebstahl-11296717.htmlIch habe das auch mal auf meinem Artikel "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" https://karl-voit.at/2023/03/05/TOTP-Auswahl/ dazugenommen.
Wenn man von dem Vorfall Generelles ableiten möchte, bleiben eigentlich nur noch Hardware-Tokens für #FIDO2 übrig, wenn man #Phishing ausschließen möchte.
Sogar #Passkeys helfen leider nicht (mehr): https://karl-voit.at/FIDO2-vs-Passkeys/
#Authenticator #TOTP #FIDO2 #publicvoit #20230304_TOTPAuswahl #MFA #2FA #20241005_FIDO2VsPasskeys #Authentifizierung #Sicherheit
-
#MicrosoftAuthenticator: Kritische #Sicherheitslücke ermöglicht Token-Diebstahl
https://www.heise.de/news/Microsoft-Authenticator-Kritische-Sicherheitsluecke-ermoeglicht-Token-Diebstahl-11296717.htmlIch habe das auch mal auf meinem Artikel "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" https://karl-voit.at/2023/03/05/TOTP-Auswahl/ dazugenommen.
Wenn man von dem Vorfall Generelles ableiten möchte, bleiben eigentlich nur noch Hardware-Tokens für #FIDO2 übrig, wenn man #Phishing ausschließen möchte.
Sogar #Passkeys helfen leider nicht (mehr): https://karl-voit.at/FIDO2-vs-Passkeys/
#Authenticator #TOTP #FIDO2 #publicvoit #20230304_TOTPAuswahl #MFA #2FA #20241005_FIDO2VsPasskeys #Authentifizierung #Sicherheit
-
Why do I have three #FIDO2 keys added to my #MicrosoftAccount if #Microsoft is only willing to send me notifications using the #MicrosoftAuthenticator App?
-
Why do I have three #FIDO2 keys added to my #MicrosoftAccount if #Microsoft is only willing to send me notifications using the #MicrosoftAuthenticator App?
-
Why do I have three #FIDO2 keys added to my #MicrosoftAccount if #Microsoft is only willing to send me notifications using the #MicrosoftAuthenticator App?
-
Why do I have three #FIDO2 keys added to my #MicrosoftAccount if #Microsoft is only willing to send me notifications using the #MicrosoftAuthenticator App?
-
Why do I have three #FIDO2 keys added to my #MicrosoftAccount if #Microsoft is only willing to send me notifications using the #MicrosoftAuthenticator App?
-
Imagine being prompted to sign in with #microsoftauthenticator from here .. https://sparkyscout.tumblr.com/post/812905530670678017
-
Microsoft Authenticator .. jag tror jag har gjort MFA säkert 100+ gånger idag .. en del sessioner verkar självdö väldigt snabbt .. eller så är det något annat fel som är trasigt.
-
Microsoft Authenticator could leak login codes—update your app now
#CVE_2026_26123 #MicrosoftAuthenticator
https://www.malwarebytes.com/blog/news/2026/03/microsoft-authenticator-could-leak-login-codes-update-your-app-now -
RE: https://infosec.exchange/@merill/116188307859736132
Android Authenticator
Root Detection
🚨⚠️🚨⚠️🚨⚠️🚨⚠️
#MicrosoftAuthenticator on #Android
strictly blocks usage on rooted or
jailbroken devices.Relies on Google
Play Services;privacy-focused OS
distributions (e.g., #GrapheneOS)
lacking Play Services will be
completely blocked.THIS WONT MAKE EVERYONE HAPPY
-
#GrapheneOS: #MicrosoftAuthenticator unterstützt sicheres #Android :android: -OS nicht | Security https://www.heise.de/news/GrapheneOS-Microsoft-Authenticator-unterstuetzt-sicheres-Android-OS-nicht-11200269.html #Microsoft
-
#MicrosoftAuthenticator stellt Funktion bei erkanntem Jailbreak/Root-Zugriff ein | Security https://www.heise.de/news/Microsoft-Authenticator-bekommt-Jailbreak-und-Root-Erkennung-11190598.html #Microsoft
-
Töiden hoitaminen vielä sen jälkeen, kun tieto niiden päättymisestä on jo tullut, on paitsi kiusallista myös aidosti vaikeaa. Luovutin eilen työnantajalle kaikki heidän välineensä, mm. työpuhelimen. Tästä seurasi, että oli todellisia vaikeuksia päästä #Wilma'an, joka joka koneella vaatii aina silloin tällöin #MicrosoftAuthenticator'ilta luetun koodin, johon siis minulla ei enää ole pääsyä! #työjuttuja #perkele
-
Töiden hoitaminen vielä sen jälkeen, kun tieto niiden päättymisestä on jo tullut, on paitsi kiusallista myös aidosti vaikeaa. Luovutin eilen työnantajalle kaikki heidän välineensä, mm. työpuhelimen. Tästä seurasi, että oli todellisia vaikeuksia päästä #Wilma'an, joka joka koneella vaatii aina silloin tällöin #MicrosoftAuthenticator'ilta luetun koodin, johon siis minulla ei enää ole pääsyä! #työjuttuja #perkele
-
Töiden hoitaminen vielä sen jälkeen, kun tieto niiden päättymisestä on jo tullut, on paitsi kiusallista myös aidosti vaikeaa. Luovutin eilen työnantajalle kaikki heidän välineensä, mm. työpuhelimen. Tästä seurasi, että oli todellisia vaikeuksia päästä #Wilma'an, joka joka koneella vaatii aina silloin tällöin #MicrosoftAuthenticator'ilta luetun koodin, johon siis minulla ei enää ole pääsyä! #työjuttuja #perkele
-
Töiden hoitaminen vielä sen jälkeen, kun tieto niiden päättymisestä on jo tullut, on paitsi kiusallista myös aidosti vaikeaa. Luovutin eilen työnantajalle kaikki heidän välineensä, mm. työpuhelimen. Tästä seurasi, että oli todellisia vaikeuksia päästä #Wilma'an, joka joka koneella vaatii aina silloin tällöin #MicrosoftAuthenticator'ilta luetun koodin, johon siis minulla ei enää ole pääsyä! #työjuttuja #perkele
-
Töiden hoitaminen vielä sen jälkeen, kun tieto niiden päättymisestä on jo tullut, on paitsi kiusallista myös aidosti vaikeaa. Luovutin eilen työnantajalle kaikki heidän välineensä, mm. työpuhelimen. Tästä seurasi, että oli todellisia vaikeuksia päästä #Wilma'an, joka joka koneella vaatii aina silloin tällöin #MicrosoftAuthenticator'ilta luetun koodin, johon siis minulla ei enää ole pääsyä! #työjuttuja #perkele
-
Zwakke 2FA/MFA werkt AVERECHTS
In https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912477 schreef ik eerder deze week:
❝
2FA (MFA) is ruk.Laat de overheid een wachtwoordmanager adviseren die wél op domeinnamen checkt.
❞
(Dat laatste kan standaard onder Android, iOS en iPadOS - middels "AutoFill").Op veler "verzoek" onderbouwde ik die stelling (niet voor de eerste keer) in https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912530.
En in https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912733 legde ik uit waarom online inloggen *lastig* veilig te krijgen is - wat je ook verzint (het blijven shared secrets).
Vandaag heb ik Microsoft Authenticator ook maar weer eens getest (onder Android). Mijn bevindingen leest u in (de tweede helft van) https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912864 - hieronder een stukje daaruit.
#ZwakkeMFA #SMS #AuthenticatorApps #Zwakke2FA #Weak2FA #WeakMFA #MicrosoftAuthenticator #2FAsucks #MFAsucks #Phishing #NepWebsites #PhaaS #Evilginx2 #SIMswap #SS7 #AcountTakeOver #CookieTheft #AccountLockout
-
Zwakke 2FA/MFA werkt AVERECHTS
In https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912477 schreef ik eerder deze week:
❝
2FA (MFA) is ruk.Laat de overheid een wachtwoordmanager adviseren die wél op domeinnamen checkt.
❞
(Dat laatste kan standaard onder Android, iOS en iPadOS - middels "AutoFill").Op veler "verzoek" onderbouwde ik die stelling (niet voor de eerste keer) in https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912530.
En in https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912733 legde ik uit waarom online inloggen *lastig* veilig te krijgen is - wat je ook verzint (het blijven shared secrets).
Vandaag heb ik Microsoft Authenticator ook maar weer eens getest (onder Android). Mijn bevindingen leest u in (de tweede helft van) https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912864 - hieronder een stukje daaruit.
#ZwakkeMFA #SMS #AuthenticatorApps #Zwakke2FA #Weak2FA #WeakMFA #MicrosoftAuthenticator #2FAsucks #MFAsucks #Phishing #NepWebsites #PhaaS #Evilginx2 #SIMswap #SS7 #AcountTakeOver #CookieTheft #AccountLockout
-
En ole kahteen päivään päässyt mobiili-#Wilma'an: käyttäjätunnus ja salasana ovat OK, mutta #2FA #MicrosoftAuthenticator'illa päätyy aina ilmoitukseen ”Tapahtui jokin virhe: yritä myöhemmin uudestaan”. Koodi siis ei ole *väärin* — senhän sovellus kertoisi — vaan se ei vain toimi. Joudun joka kerta kaivamaan kannettavan ja kirjautumaan sille saadakseni selville, minne luokkaan on suunnistettava 🤬 #työjuttuja #atkjuttuja
-
Heads-up for anyone stuck using the Microsoft Authenticator app for work/school access on a jailbroken/rooted phone, MS is going to block your access in early 2026 and delete the credentials
#Microsoft365 #MicrosoftAuthenticator #EntraID #Root #Jailbreak #Android #iOS
-
Proton Authenticator
As more and more of our important personal data is stored online and more and more hacks of corporate databases make that data available to the worst people, the need for added security on our online accounts has grown considerably. It’s no longer enough to have a secure, hard to crack password. We now need to enable two-factor/multi-factor authentication (2FA/MFA). These services allow you to use something you have, such as your smartphone, along with something you know, in this case your […]
-
Proton Authenticator
As more and more of our important personal data is stored online and more and more hacks of corporate databases make that data available to the worst people, the need for added security on our online accounts has grown considerably. It’s no longer enough to have a secure, hard to crack password. We now need to enable two-factor/multi-factor authentication (2FA/MFA). These services allow you to use something you have, such as your smartphone, along with something you know, in this case your […]
-
Proton Authenticator
As more and more of our important personal data is stored online and more and more hacks of corporate databases make that data available to the worst people, the need for added security on our online accounts has grown considerably. It’s no longer enough to have a secure, hard to crack password. We now need to enable two-factor/multi-factor authentication (2FA/MFA). These services allow you to use something you have, such as your smartphone, along with something you know, in this case your […]
-
Proton Authenticator
As more and more of our important personal data is stored online and more and more hacks of corporate databases make that data available to the worst people, the need for added security on our online accounts has grown considerably. It’s no longer enough to have a secure, hard to crack password. We now need to enable two-factor/multi-factor authentication (2FA/MFA). These services allow you to use something you have, such as your smartphone, along with something you know, in this case your […]
-
Proton Authenticator
As more and more of our important personal data is stored online and more and more hacks of corporate databases make that data available to the worst people, the need for added security on our online accounts has grown considerably. It’s no longer enough to have a secure, hard to crack password. We now need to enable two-factor/multi-factor authentication (2FA/MFA). These services allow you to use something you have, such as your smartphone, along with something you know, in this case your […]
-
Ich brauche Hilfe. Kunde nutzt #Microsoft für Authentifizierung aller Dinge, auf die ich (Softwareingenieur) Zugriff haben muss. Bisher ging #2FA mit normalen OTP-Generatoren (z.B. Yubikey). Jetzt stellen sie um, es geht nur noch der #MicrosoftAuthenticator. Den kan ich auf privatem Smartphone nicht installieren (kein PlayStore auf dem Gerät). Arbeitgeber will mir kein Phone stellen. Android-Emulator aus Sicherheitsgründen abgelehnt. Was mache ich?
-
Engadget: If you’re using Microsoft Authenticator to store your passwords, don’t . “Microsoft Authenticator is sunsetting its ability to store your passwords. This month, the service stopped allowing users to add or import new passwords. Beginning in July 2025, users will no longer be able to use autofill with Authenticator, and in August 2025, passwords will no longer be available at all.”
-
Microsoft Authenticator abandonne la gestion des mots de passe : que faire avant août ?
https://mac4ever.com/190342
#Mac4Ever #MicrosoftAuthenticator -
Und wieder einmal zeigt es sich, dass man nahezu schutzlos den Giganten ausgesetzt ist. Daher mein Tipp: KeePass @keepassxc
#MicrosoftAuthenticator: Zurück vom Passwort-Manager zum Authenticator | Security https://www.heise.de/news/Microsoft-Authenticator-Zurueck-vom-Passwort-Manager-zum-Authenticator-10371450.html #Microsoft
-
Duo vs Microsoft Authenticator: Which Tool Is Better? – Source: www.techrepublic.com https://ciso2ciso.com/duo-vs-microsoft-authenticator-which-tool-is-better-source-www-techrepublic-com/ #rssfeedpostgeneratorecho #twofactorauthentication #microsoftauthenticator #SecurityonTechRepublic #SecurityTechRepublic #CyberSecurityNews #Authenticator #CloudSecurity #Security #duo
-
Passkeys are now generally available in Microsoft Authenticator!
I have updated my blog post about Microsoft Entra ID passkeys in Microsoft Authenticator to reflect the current state and configuration options. More updates in January 2025 🙏
https://www.cswrld.com/2024/11/how-to-enable-microsoft-authenticator-passkeys-in-entra-id/
-
#MicrosoftAuthenticator for #Android is the first application I've personally used where the error message is a picture and screenshots are generated blank to ensure you've having a hard time googling or asking someone. Kudos for #Microsoft, you're struggling hard to be the #Boeing of Big Tech.
-
Will the new #Nokia3210 run the #MicrosoftAuthenticator ?👀