Microsoft has discovered 44 million user accounts are using usernames and passwords that have been leaked through security breaches.
As ZDNet reports, the vulnerable account logins were discovered when Microsoft's threat research team carried out a scan of all Microsoft accounts between January and March this year. The accounts were compared to a database of over three billion sets of leaked credentials and resulted in 44 million matches.
These accounts were spread between regular user accounts used by consumers (Microsoft Services Accounts) and enterprise accounts in the form of Microsoft Azure AD logins. In response, Microsoft explained, "For the leaked credentials for which we found a match, we force a password reset. No additional action is required on the consumer side ... On the enterprise side, Microsoft will elevate the user risk and alert the administrator so that a credential reset can be enforced."
Microsoft goes on to recommend that, "Given the frequency of passwords being reused by multiple individuals, it is critical to back your password with some form of strong credential. Multi-Factor Authentication (MFA) is an important security mechanism that can dramatically improve your security posture. Our numbers show that 99.9% of identity attacks have been thwarted by turning on MFA."
SEE ALSO: Absolutely humongous data breach exposes more than a billion recordsPicking a password is always a trade-off between what's memorable and what's strong, which is why using a password manager makes so much sense. But we have another problem: security breaches expose passwords and they shouldn't be used by anyone.
While Microsoft did the right thing resetting the passwords on these account, it currently can't stop a user selecting a new password that's also been exposed as part of a past security breach. A positive next move would be to perform a check when a password is entered to see if it appears on a breach list, and if it is, to reject it and request the user pick something else.
Copyright © 2023 Powered by
Microsoft found 44 million accounts using breached passwords-寸地尺天网
sitemap
文章
97664
浏览
325
获赞
22
Watch Kathryn Hahn stare longingly at Rachel Weisz set to the 'Carol' score
Kathryn Hahn and Rachel Weisz are made to be together, forever -- at least in queer fanfiction on TuClubhouse payments let you send money to creators
Clubhouse has introduced a new feature called payments, allowing users to send money directly to creShakira's halftime Super Bowl tongue is now a wonderful meme
Shakira blessed us with the first meme of the Super Bowl LIV. Jennifer Lopez and Shakira's halftime2019 was the year we were supposed to love our acne
To celebrate reaching the end of this year, we asked our reporters to look back on 2019 and pick oneACLU warns that 'no replies' on Twitter could violate the constitution
Trump was basically Obama's reply guy throughout the 2010s, so it's only fitting that he won't be abSamsung's new Galaxy A series phones offer options for all budgets
If you've been holding off on buying one of Samsung's pricey flagship phones, I don't blame you &mdaOculus Quest 2 doesn't need a wire to play on PCs anymore
Facebook's Oculus Quest 2 is the best value in VR, thanks to hardware that eliminates the need for aGlossier skincare is Instagram
Mashable's new series Don't@ Me takes unpopular opinions and backs them up withreasons. We all haveSnapchat removes Juneteenth filter that prompted users to smile to break chains
Snapchat apologized for its insensitive Juneteenth filter that asked users to smile to break chainsWatch the wild Kansas City Super Bowl parade car chase
The Kansas City Chiefs' Super Bowl parade got off to a start nobody expected on Wednesday — itHuawei to launch new foldable phone in February
Huawei is about to launch its third foldable smartphone. The company announced on its Weibo accountBorder agents can search phones without a warrant, court rules
Customs and Border Protection agents once again have a green light to freely search the phones and cChris Evans passionately defends Cool Ranch Doritos amidst heated chip debate
Chris Evans loves Cool Ranch Doritos, and he's not about to apologize for his good taste.After comedSamsung's new Galaxy A series phones offer options for all budgets
If you've been holding off on buying one of Samsung's pricey flagship phones, I don't blame you &mdaTeen behind the Bitcoin/Twitter hack sentenced to 3 years in prison
The hacker behind last year’s big Twitter hackhas just been sentenced to hard time.Graham Ivan