Microsoft has discovered 44 million user accounts are using usernames and passwords that have been leaked through security breaches.
As ZDNet reports, the vulnerable account logins were discovered when Microsoft's threat research team carried out a scan of all Microsoft accounts between January and March this year. The accounts were compared to a database of over three billion sets of leaked credentials and resulted in 44 million matches.
These accounts were spread between regular user accounts used by consumers (Microsoft Services Accounts) and enterprise accounts in the form of Microsoft Azure AD logins. In response, Microsoft explained, "For the leaked credentials for which we found a match, we force a password reset. No additional action is required on the consumer side ... On the enterprise side, Microsoft will elevate the user risk and alert the administrator so that a credential reset can be enforced."
Microsoft goes on to recommend that, "Given the frequency of passwords being reused by multiple individuals, it is critical to back your password with some form of strong credential. Multi-Factor Authentication (MFA) is an important security mechanism that can dramatically improve your security posture. Our numbers show that 99.9% of identity attacks have been thwarted by turning on MFA."
SEE ALSO: Absolutely humongous data breach exposes more than a billion recordsPicking a password is always a trade-off between what's memorable and what's strong, which is why using a password manager makes so much sense. But we have another problem: security breaches expose passwords and they shouldn't be used by anyone.
While Microsoft did the right thing resetting the passwords on these account, it currently can't stop a user selecting a new password that's also been exposed as part of a past security breach. A positive next move would be to perform a check when a password is entered to see if it appears on a breach list, and if it is, to reject it and request the user pick something else.
Copyright © 2023 Powered by
Microsoft found 44 million accounts using breached passwords-风花雪夜网
sitemap
文章
81211
浏览
24744
获赞
5
WhatsApp will stop working if you don't accept the new privacy policy
A reminder to all WhatsApp users: The company's updated privacy policy will officially go into effecGoogle Duo is another Zoom alternative
Google's video chat app got new features this week. No, the other one. No, the otherother one.In a FThe 'Thanks, I hate it' subreddit is a great home for a timeless meme
Some memes are born to die. Others, like the "Thanks, I hate it" meme, can live eternally."Thanks, IApple's new credit card gets compared to Billy McFarland's credit card scam
Someone didn't watch the Fyre Festival documentaries. Apple announced its groundbreaking new pay feaIs your iPhone draining battery fast after iOS 14.2? You're not alone.
Apple's iOS 14.2 is causing battery-related headaches to a number of users. According to complaintsIRS announces May 13 deadline for direct deposit of stimulus checks
If you don't want to wait for a paper check for your federal stimulus payment, you better get onto tZoom's web address is confusing the hell out of people
If you try calling Zoom, you may be greeted with a gruff voice asking, “Are you looking for ZoTesla wins Kelley Blue Book award for 'Top Luxury Brand'
Tesla's reputation as a top car brand is still intact even as car sales drop off while most people sDemi Lovato performed at the Super Bowl a decade after tweeting about it
Demi Lovato had big plans to sing at the Super Bowl, ten years ago. Lovato's powerful rendition of tStill can’t get the IRS site working to check the status of your stimulus check? Try this.
Have you been receiving the “Payment Status Not Available” error message when trying toYouTubers Cole and Sav pranked their daughter by pretending to disown their puppy
YouTubers Cole and Sav LaBrant are in post-April Fools' Day hot water after playing a particularly hApple reportedly ready to launch new AirPods in May 2020
AirPod lovers could be in for a nice surprise.On Sunday, tech rumormonger Jon Prosser, known for hisHand sanitizer and coronavirus: Not all of it will work
Misinformation spreads faster than the coronavirus, and it's important to stay vigilant as we try toApple's new credit card gets compared to Billy McFarland's credit card scam
Someone didn't watch the Fyre Festival documentaries. Apple announced its groundbreaking new pay feaYou can transfer Facebook photos and videos to Google Photos now
If you have a treasure trove of memories on Facebook and want them to live elsewhere, today's a grea