Microsoft is another major offender. When logging in, I get redirected 20 times between various domains, none of which in microsoft.com
Microsoft is another major offender. When logging in, I get redirected 20 times between various domains, none of which in microsoft.com
I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or an Xbox live account, so some other account. Often I've just found it easier to give up and make a new account.
I was pulling my hair out the other day trying to find my Microsoft credentials in LastPass. I was searching for "microsoft", "office", "outlook" etc. until I finally found them under "live.com".
Well, a login system is a very central part, and other websites suck too, like Amazon still uses the old account login page since 1996 too. But Microsoft redirects way too often, it is worse.
Very frustrating - fortunately I don't use Skype regularly but it's always an exercise when somebody asks for my username.
* One account required me to log in with a username, and was associated with my main email address. * The other account required me to log in with my main email address.
In a way, they were both related to the same email, but different accounts. This shouldn't even have been possible, but it seems that one was an old MS account, and the other was an old Skype account. My roster ended up being split half and half between the two.
The steps I found to unlink within the XBox UI didn't work, futher research now leads me to the following discussion which I am about to try: https://answers.microsoft.com/en-us/outlook_com/forum/oemail...
Edit: it looks like this was possible in the past (basically deleting the Skype account?), but not anymore.
[1] https://support.microsoft.com/en-us/help/12412/microsoft-acc...
I confirmed over the phone with their support that was indeed the correct site before typing anything into it.
I said think about what you're asking for a second. Should I answer your questions? Couldn't get them to understand. Wound up hanging up and calling again and waiting on hold.
Obviously I terminated the conversation.
"Hello, am I talking to Nick Lamb?" "Yes, this is me" "OK, I'm calling from Example Bank and our confirmatory password is Melons" [not the actual bank or password] "Thanks, that checks out, what can I do for you?"
This happened because I had one of those conversations you're talking about, and they were like "Aha! We have something we can do for those situations, call us and set a password we can use" so I hung up and sure enough they've used that password ever since. I like it.
It's not a _good_ password, but hey, how many times does anyone try the wrong one? Literally never. So it's good enough.
The site itself is branded just like Templeton's own site. From what I could gather, it is actually their site but even the whois is something non descript. Quite ridiculous. And of course they don't have any way whatsoever that I could find to report things like vulnerabilities or phishing attempts.
One day S&M will catch up and have a fit at the fragmented "front face" - quite right too. To be honest the board should also give a shit about their org's outward appearance.
Bit of a fail all 'round, really.
Or is that an unrelated thing?
By having CDN assets on a separate domain, you not only easily avoid accidentally sending any cookies along to the other domains (so if your CDN gets owned at least they aren't getting user credentials or session cookies), but it's also a small performance optimization as there are less things sent in the headers.
The important distinction is that the user should never ENTER any information onto those domains directly. They should be for displaying static resources only, so there is no need to "build trust" for them.
It wouldn’t load because Facebook.com was blocked and apparently they were doing a full redirect via fb. Crazy.
This is also exploited by malicious actors to occasionally buy out fake ads for amazon.com or bestbuy.com (or even, hilariously, youtube.com) which actually direct you to support scam websites claiming your computer is infected.
Google seems to have no desire to correct this by making their advertisements show you the actual URL are you going to be directed to.
Verify that any link you click on is not an ad. Always look for the first native result. The policies permitted around ads make them simply a security risk to click on.
Having a bank as a current client, I am often joking about what would happen if Jeff Bezos takes control for a month. And when I am angry, I ask what would happen if Amazon or Google start selling credits or insurances, tomorrow.