Microsoft Live Account Credentials Leaking from Windows 8 and Above
hackaday.com
hackaday.com
Windows 10 upgrade push made me to realize that that time passed a long time ago. Last time I booted to Windows for other reason than playing a game was seven years ago. LibreOffice works well with MS documents and you can always use them from Google drive.
Windows has lost it's grip for good.
I know the argument is often framed as open vs closed source ecosystems but I think and hope that ultimately having more options and more variety is good and interesting for us.
Windows, does deservedly get a lot of stick for it's past issues (windows rot etc) and present issues. However, I think ultimately what we learn from these scenarios is extremely beneficial for a lot of people.
As a Web Developer I hated IE 6. I still do. But, I have to admit that it taught me a lot. It taught me about the box-model. It taught me how to debug JS before the days of Firefox/Firebug. I know this was not by design or intention and I know this is easier to say in retrospect.
I can imagine a lot of people working in info-sec learnt a lot from the various failings of Windows and other platforms too.
I guess my point is don't be negative for the sake of it. If Windows is bad, I hope it improves. Same goes for all technologies. I'm a Chrome user but I still love to run Opera, Firefox and Edge now and then because I enjoy different experiences and love playing with new apps and features. I also have a Macbook for work and and and Ubuntu partition. I enjoy using them all.
Chrome has never actively tried to uninstall/remove competing browsers or corrupt your ability to reliably run them, I distinctly remember my own install of Windows 10 destroying my bootloaders set up by Linux and uninstalling applications automatically. Although it has show the ability to send as much information as it wants back home.
>If Windows is bad, I hope it improves.
I'm sure people in 2001 were saying the same thing about Microsoft and it appears they are emulating it again.
For me, it's that the system is completely closed and opaque, and there routinely isn't much I can do about it.
Not saying the other guys are perfect--far from it--but at least I can take a crack at changing things. Windows is the most closed-source OS I run (more so than OSX). When it doesn't do The Right Thing, I can get very negative.
And to your point, I feel I've learned much more from OSes that expose the internals and let me mess with them, than those that don't.
For your listed use case of gaming & document creation.
There are a lot of niche applications that are Windows only. All major CAD platforms, a decent chunk of FEA packages, hardware vendor software, etc. At the professional level, Windows still has quite the grip.
From a profession standpoint, I'm still tied to Windows because of Adobe's choice not to port to linux. Inkscape and Gimp are okay, but when you're the only one in the company running linux, what's the point?
And, for a game from 2006, you'll probably have to pray to the Windows-compatibility-mode gods at this point, too. I actually wouldn't be surprised, if it worked better under WINE...
That's just not true. I've got plenty of games from 2006 and earlier than run just as good as they originally did. Sure Oblivion crashes, but it did in 2006. Half-Life 2 runs pretty darn well. Company of heroes? Yep. Dawn of War and the expansions? Sure.
In fact, my overall gaming experience on windows 10 is far better than it was on windows xp and vista. Less overall crashing, and I never get bluescreens any more.
Windows still dominates on workstations, but that no longer locks people in like it used to. Some user-interfaces can be pushed onto the web or mobile apps. Suppliers further down the chain are now as likely to support Linux as Windows.
My employer is a hardware vendor, our software is turning out Linux-only for the forseeable future. Of course the office PC's for us an most of our customers are Windows, but this is workable because of all kinds of (mostly network based) interoperability that has grown up over the years.
Secondly, plugins - there are a heap of free and paid plugins that are Windows-only that I'm not sure will work in Linux (I know about being able to bridge them, but even 32/64 Windows bridges have issues!) - having said that I've not tried this lately, so hopefully there's been some good progress.
Third, and probably most intractably - it's a big enough ask to get school IT departments to support 'odd' software like Cubase; getting them to support Linux, alas, would be infinitely unlikely, so I'd still need a Windows PC to support my teaching work (which is my main income).
Thanks for the tip, though, I shall re-look into Bitwig again as it's on Linux, and then my GalliumOS Chromebook could become even more useful!
It's the applications that are key and if some application requires a Windows machine, that's what they buy.
Try installing Ubuntu on a brand new laptop. Its just not something a non technical user can deal with. I am sure a good share of us here on HN has, at-least one relative who calls us because the "internet is broken" imagine them trying to deal with something like ubuntu on a brand new computer.
I like to think this is partially our fault as consumers, we need to actually do more to demand hardware vendors to support Linux. Especially laptop manufacturers.
In my experience installing a friendly linux like Ubuntu is a lot more simple than installing Windows. Unless the hardware is very new the install will just work. If you want to play games you may have to play around with installing the latest video drivers from the vendor, but how is this any different from what you have to do on a Windows machine?
NX runs on Linux too.
Many run on Mac & Linux. Hell, AutoCAD runs on iOS & Android.
I think its difficult to know the vast amount of software that's user/business critical that's Windows-only and how many people will never run an OS that isn't pre-install on their computer. Even as a sysadmin/devops for over a decade, I'm still surprised how strong Windows is. Some of it is legacy inertia and some of it is merit. No one else is investing in gaming like MS does. No one else builds developer friendly tools that a very mediocre team of devs can be made productive with. No one else builds a dumbed-down office suite that even a high school drop out can be productive in. No one else markets to the business community like MS, etc, etc.
It also doesn't help the "year of the linux desktop" argument that Windows is losing to mobile, but Windows 10 includes many mobile concepts. In fact, as far as I can tell, its very much modeled after Android. I know grandma won't buy a Surface Pro, but it is now easier for her to go from Android or iOS to Win10 and not be scared or confused.
I think Windows has a long life still. Just because you don't like it, doesn't mean you can just wish it away. For segments that aren't the kinds of people who post on HN, its still very popular and that's ignoring its dominance in business.
Also I use two massive 27-inch screens at work. My co-worker Ubuntu boxes have difficulties driving them properly (probably driver issues, manufacturer's fault). Also text rendering is still subpar on Ubuntu.
Windows 10, IMO, provides many nice aspects in terms of UI experience. Not that I'm gonna start developing on Windows in any foreseeable future
Personally I don't use Windows anymore but it seems like it's going to take a lot of work to get rid of the Windows platform out of commodity IT.
> Windows has lost it's grip for good.
its* grip
Win10 tries really hard to make you log into your desktop with your Live Account credentials - you can't use the store without this. Whereas if it were just leaking a local login it would be much less critical.
But yes, I am quite annoyed by them requiring that I use online credentials to log in to a physical computer. I prefer to separate the two authentication mechanisms.
Pushing the MS Account for installing software is plain bad and it definitely won't help with user adoption like a non mandatory account would.
In one case, I unsuccessfully tried to create just a local account in Win 8, because they had hidden it behind 3+ layers of "sign in here with your live account". I was sure that there must be a way to create a local one, but just couldn't find the right path.
I for one am glad that the French Data Protection Authority is going after Microsoft, but it remains to be seen if it can lead to major changes in Windows 10 (for the benefit of the users):
https://www.cnil.fr/en/windows-10-cnil-publicly-serves-forma...
Call me old fashioned, but I prefer my login credentials to my physical PC to be different than for my online accounts.
It involves navigating to a "Create a Microsoft Account" screen, and then clicking the well-hidden "Sign in without a Microsoft Account" at the bottom. Quite a well thought out dark pattern, confused me at the time.
[1] http://www.hanselman.com/blog/HowToSignIntoWindows8Or81Witho...
https://support.microsoft.com/en-us/help/13951/windows-creat...
(I had a Windows 8 VM for compiling some software and used a local account.)
Is that substantially different from every corporate domain login credential system?
I have downloaded Netflix, Audible, tubecast and a whole bunch of other apps from the store
and so far, all is good. fingers cross ;)
The built-in weather app and tile is solid enough that I find people downloading a third party one kinda surprising.
http://lifehacker.com/install-windows-10-store-apps-without-...
I genuinely cannot imagine the day that I want a thing and go to the windows store to get it. Last night I installed AutoHotKey and Notepad++ for example (both long overdue admittedly) - all through my browser. Simplez.
It's not really a surprise if an app store needs an account. Are there any that don't?
Yeah the ones that have existed since forever: GNU/Linux repositories (Ubuntu's, Debian's, etc.). Even Ubuntu's Software Center, which you might find closer to an app store than a command line interface even though it's the same thing, does not require an account until you try to leave comments or review an application.
Then there were browser addon repositories which worked the same way, first from Firefox and later from all other browsers. (Except one of course.)
So yes, no account was the standard. Needing an account is something recent.
I'd just like to download apk files from the play store, but that's not possible without an account even though there's no reason for it whatsoever. Moreover, I'd like to contribute to many apps while still not attaching payment info to my account. Currently I bought some pro versions of apps via gift cards, but this doesn't work for subscriptions (even if you have 100 bucks prepaid on your account and the subscription is 1 buck a month, and don't get me started on country locking the credit). They all want to have your data and lock you in.
In Windows 10's case, it's only for apps. If you're happy with Win32 programs, you still don't need to use a Microsoft Account.
Did you actually use Windows 10 you're complaining about?
I'm complaining about walled gardens and application "stores" that require an account in particular, even when they don't require payment information (making them not a store at all, just a walled application garden).
And yes, I have used the Windows Store once or twice, but I don't see how that changes anything.
I borrow books and CDs from a public library: I need an account.
I borrow videos from BlockBuster or stream them from Netflix: I need an account.
I want to comment on HN or whatever: I need an account.
I want to get a job, I need an account (SSN etc).
Want to borrow a book from another library because it's missing in yours?
Want to switch from Netflix to a different streaming provider, but don't want to lose all your history?
You can't easily because you're in their walled garden.
Also nearly any Linux package manager ;) (if they count as an "app store" for you)
Isn't it possible to buy something in the Windows Store and login just for this one purchase? Note sure though, but I think I remember doing that with Windows 8.
The Windows Store or also the Play Store and Apple's App Store could function without account for free apps, too, as far as I understand it they just choose to require an account up-front, so that there's less friction in the moment a user considers buying an app.
Being honest, what would I want to use the store for?
1) Convenience: You don't have to search all over the web for your software and don't have to click through an installer when installing (because everything is packaged in a standardized way and can therefore be installed in a standardized way, too). Also, there's a centralized way of distributing updates now, meaning that not anymore each and every piece of software has to come with an auto-updater.
2) Security: If you don't install your stuff from the internet, you're also much less likely to install from a wrong source and therefore less likely to catch viruses. If there is a virus-infected app on the Windows Store, it's also possible for Microsoft to remove it. The UWP-apps that Microsoft is pushing along with their store, are also sandboxed, so again, much less likely for software to be able to damage your system.
Individual users can do this using by setting up suitable outbound rules in the Windows Firewall with Advanced Security snap-in (wf.msc).
Pretty much every non-standard Microsoft-only approach to things seem to be broken one way or another, only to be fixed after someone threatens to expose and exploit it. I know it's gotten better in recent years, but the fact that it's still something that seems to be pushing from the outside in, instead of being part of the manufacturer's culture is shining through rather harshly.
You should enable Two-factor Authentication (2FA) on your account.
https://support.microsoft.com/en-us/help/12408/microsoft-acc...
The app has access to:
- Identity
- Contacts
- SMS
- Camera
- Device ID & call information
- Other
https://play.google.com/store/apps/details?id=com.microsoft....
Am I the only one who thinks that?
That said, personally I do like the Microsoft Authenticator app very much, it's just a single tap on the phone to confirm the 2FA login, which is much more convenient than retyping a code. Disadvantage is that the Android version of the Microsoft Authenticator app can only have one account, I could not connect a second 2FA service (LastPass) to it.
Identity: Find or manage any Live/O365/MS account on your device
SMS: Read enrollment text message or backup texts (e.g. no network) for pushing auth requests
Camera: Enrollment via QR code
Device ID / Call info: Needed to reliably push notifications / send SMS + get phone number for verification texts whatever
Android's permission system is sort of obtuse
You don't just quickly write a browser from scratch in this day and age. And if you did, it would be so much better than Edge or the other contemporary browsers, because you could start out with a much better architecture...
Because people confuse Microsoft marketing fluff with reality?
"Microsoft Edge is built from the ground up to improve productivity, to be more secure, and to correctly, quickly and reliably render Web pages. While Microsoft Edge is the default browser for Windows 10 and is the best fit for most users, some enterprise customers have line-of-business applications built specifically for older Web technologies, which require Internet Explorer 11." [0]
"We designed Microsoft Edge from the ground up to prioritize power efficiency and deliver more battery life" [1]
"Microsoft Edge is designed from the ground up to provide a modern, interoperable, and secure browsing experience"[2]
[0] https://blogs.microsoft.com/firehose/2016/05/19/improvements...
[1] https://blogs.windows.com/windowsexperience/2016/06/20/more-...
[2] https://blogs.windows.com/msedgedev/2016/06/07/edge-enterpri...
Marketing: it is all fun and games until you validate the claims.
New isn't always better. It's not as if no one on the Chrome/Firefox/IE teams are working on the architecture of the existing browsers. If you had the resources to build a new browser from scratch, you probably would not end up with something better than the existing browsers.
The larger issue is the lack of 2fa by default. I think these kinds of attacks are symptoms of a larger problem that a lot of hosted services have been ignoring.
[1] There's probably a good argument that Edge should ignore network links like these, but I imagine businesses would be upset if suddenly no one can browse the intranet or open html/jpg/gif items on a share.
Works on up to date Windows 10 and Edge (there is an online test if you're vulnerable). If you don't use the listed software, you're probably completely safe (maybe there is other Microsoft software that does this, though?). If you don't use your Microsoft Live Account as a Windows account, you're safe (someone then just finds out the hash of your local password).
EDIT: Interestingly, Edge on the Xbox One is not vulnerable. It seems like the behaviour on the console is different.
If your password is common (see something like https://github.com/danielmiessler/SecLists/tree/master/Passw...) or <10 ASCII characters, it shouldn't take too long.
NTLM is a generic authentication layer. You use it to get single sign-on for your web APIs.
Why does he keep repeating "Spartan?" That was Edge's codename. Now its just Edge. Is he's referring to the engine that can be embedded into other applications? If so, its called EdgeHTML.
If it's only exposing the hash, why should you make your password stronger?
Great, I'll just store this in my password manag... oh, wait.
Your password hash is not sent over the wire. What is sent over the wire is the NTLMv2 response message. This, simplified, is: HMAC_MD5(Hash | challenge). If you want the gory details, check out MS-NLMP.
That said, a dictionary-attackable password + attacker with fast GPUs can still brute-forcing the HMAC, then attack the password hash (MD4). It's a bit harder than just banging on a simple hash, though not terrifically difficult.
As such, the protocol exchanges everything you would need in order to crack the password in the messages themselves. Adding a salt, unless you stipulate a way to share that salt across machines ahead of time, would not prevent cracking a password by intercepting the messages, because the salt would have to be in the message exchange as well. What a public / visible salt in the message exchange does do is eliminate rainbow table (instant) cracking based on intercepting the message.
To answer your question: NTLM is unsalted, and NTLMv2 adds a salt, which is exchanged in the messaging. In this case the salt is applied a bit differently -- MD5(MD5(password), salt) -- because the salt is randomly generated each time, and what's stored in the authentication database is just MD5(password). The salt is only in the challenge-response protocol, so you can still bulk-crack all the passwords in the database if you can steal it.
So, you can think of NTLMv2 as "half-salted" and when you tell people that, you'll have a great story to tell (for values of "great" which include crypto-inclined audiences).
EDIT: I think KMag has it right. The message has the username, domain, salt, and:
MD5(MD5(MD4(password), username || domain), salt)
The nesting is because of their attempts at shoe-horning this in their legacy codebase and trying to remain backward compatible. A more secure way to hash the same data, but not backward compatible, is; HMAC(salt, username || domain || password)Also available for illegitimate at http://www.shutterstock.com/pic-389962378/stock-photo-hacker... or http://www.shutterstock.com/pic-345906527/stock-photo-danger...