What The Microsoft Hack Means For You

  Рет қаралды 86,390

Ken Harris

Ken Harris

Күн бұрын

Microsoft was recently hacked by state hackers and all the emails in Office 365 were able to be accessed. This video gives an overview of what happened and some alternatives for more privacy friendly options.
00:00 Overview
05:16 MS Scanning Your Files
07:47 Private Cloud Storage Options
12:06 Private Email Options
13:53 PGP Warning
15:13 Private Messaging
17:28 Outro
Articles:
arstechnica.com/security/2024...
arstechnica.com/information-t...

Пікірлер: 388
@KenHarrisio
@KenHarrisio 4 ай бұрын
Some clarification regarding Telegram; it is encrypted, but it just isn't the best option for privacy. The only zero knowledge encryption used is with secret chats which can only be used in one-on-one conversations for mobile. If you want private messaging, one of the other platforms is going to be quite a bit better suited. Edit: Holy hell, this video became my most viewed video overnight and the channel just grew massively! Thanks everyone for the support. The views are still coming in and the CTR keeps going up. I've not seen that happen on a video before. I saw many people had been asking questions. I'll start writing some replies later on today.
@Dante-420
@Dante-420 4 ай бұрын
The server side code is also proprietary. The main dev has provided justification for this, but if you really need security (instead of a convenient app) then you don't need a centralized server (that you have no control over) to begin with, even if it is just storing encrypted data.
@desmondsparrs
@desmondsparrs 4 ай бұрын
just use Signal. I still use Telegram because Im a member of many tech groups but I just view it as this app is not encrypted. except private chats, which no one uses. Signal is 1000% better if privacy is important
@xzs432
@xzs432 4 ай бұрын
wow that's great, just found you today on my recommended page, i'm mainly into tech and videogames!
@Mavendow
@Mavendow 4 ай бұрын
Regardless of TG's backend security, its main issue is being tied to a number. Anyone who wants in can take the number and voila - access to everything. There are options to make this more secure, but there's a catch: it's very likely the user has used said number for _other_ online recovery methods. Which, are what TG uses to verify the 2FA. These corps have created a circular loop of insecurity via the information they make us divulge "for our security." Ironic.
@Tyrael7-bf1ld6zu6s
@Tyrael7-bf1ld6zu6s 4 ай бұрын
Telegram should never be used 😂😂😂😂😂😂
@Ed_Stuckey
@Ed_Stuckey 4 ай бұрын
There is no *CLOUD* - it's just someone else's computer.
@deadspaceman
@deadspaceman 4 ай бұрын
i am cloud
@deadspaceman
@deadspaceman 4 ай бұрын
Space computer = cyber cloud?
@oceania68
@oceania68 4 ай бұрын
Unless you make your own, then it's "Your Cloud" haha.
@pehclark7256
@pehclark7256 4 ай бұрын
Cloud or "Rented hardware"(the real term)?
@akirathedog777
@akirathedog777 4 ай бұрын
I used to parrot that meme until i got into the workforce Cloud computing and edge computing are actual things
@Chris-on5bt
@Chris-on5bt 4 ай бұрын
Just shared with my boss at work. Any time I mention security people kind of roll their eyes and are like "Its in the cloud with a multi billion dollar corporation, they won't screw it up." I can only hope that maybe people are going to start taking security threats more seriously.
@KJ-xt3yu
@KJ-xt3yu 4 ай бұрын
just because its in the cloud doesnt mean its secure. 🍿🚬... it means its still your problem to validate. validate. validate.
@ZingsVideos
@ZingsVideos 4 ай бұрын
@@KJ-xt3yu Confirmed by the list of sites at haveibeenpwned.that that have leaked my info.
@Sonya_Makepeace
@Sonya_Makepeace 4 ай бұрын
The "Cloud" is someone's server.
@felderup
@felderup 4 ай бұрын
@@Sonya_Makepeace looked up tahoe-lafs?
@KenHarrisio
@KenHarrisio 4 ай бұрын
Security has been an issue with corporations for years. They only see it as a cost rather than something that needs to be done. One org I worked at had almost no interest in getting the security issues with our systems fixed. There's also a constant stream of Reddit threads of other people saying they have those issues in their orgs as well. Until insurance companies and/or legislation make this a bigger priority, then things like the 23andme hack will continue.
@QuantumKurator
@QuantumKurator 4 ай бұрын
That does it. Going back to AOL. Where is my CD.
@MarcosRobertoDosSantosJF
@MarcosRobertoDosSantosJF 4 ай бұрын
Check any magazine from the 90’s. You will find a bunch install CDs there! Hahaha!
@oceania68
@oceania68 4 ай бұрын
lol
@robertanderson5092
@robertanderson5092 4 ай бұрын
Prodigy had prettier colors
@KenHarrisio
@KenHarrisio 4 ай бұрын
Add Netscape Navigator for maximum nostalgia!
@ausfoodgarden
@ausfoodgarden 4 ай бұрын
My coffee cup is sitting on it. 🤣
@quatreraberbawinner2628
@quatreraberbawinner2628 4 ай бұрын
5 days later, nice of Microsoft to notify me
@mikeloeven
@mikeloeven 4 ай бұрын
Here people said I was dumb for not syncing my stuff with 360 and only using local email accounts
@geofftottenperthcoys9944
@geofftottenperthcoys9944 4 ай бұрын
This is why I try NOT to use any cloud service at all. I believe in OFFLINE backups, not relying on another company to do the right thing.
@njpme
@njpme 4 ай бұрын
Encrypt the data before you upload it.
@geofftottenperthcoys9944
@geofftottenperthcoys9944 4 ай бұрын
@@njpmeNo, I will not use them at all.
@njpme
@njpme 4 ай бұрын
@@geofftottenperthcoys9944 seems a lil extreme, but I respect it. An encrypted offline backup can be the beneficial to something on-prem
@BenjaminWalburn
@BenjaminWalburn 4 ай бұрын
You're still relying on other companies, just in a different way.
@BoGy1980
@BoGy1980 4 ай бұрын
@@BenjaminWalburn says who? If geoff is like me, he has his own mailserver running, and makes offline backups weekly and local online backups daily... so on which company do we rely for our data then?
@AnonYmous-yz9zq
@AnonYmous-yz9zq 4 ай бұрын
Insert sound of old guys laughing. How will MS screw up again? I wouldn't let them walk my dog.
@zer00rdie
@zer00rdie 4 ай бұрын
Yet here you are.
@Ebani
@Ebani 4 ай бұрын
@@zer00rdie Might wanna try to make sense
@zer00rdie
@zer00rdie 4 ай бұрын
@@Ebani Are you really that daft?
@Ebani
@Ebani 4 ай бұрын
@@zer00rdie Sounds like you need help
@zer00rdie
@zer00rdie 4 ай бұрын
@@Ebani Okay bud.
@DragonGrafx-16
@DragonGrafx-16 4 ай бұрын
I've been using Open/LIbre Office for a decade now... never once tied Office 365 to my MS account.
@friendlyninja5048
@friendlyninja5048 4 ай бұрын
Had to for my school account when I was in college. My personal account is pretty much only used for Xbox though
@bonariablackie4047
@bonariablackie4047 4 ай бұрын
Me too.
@incandescentwithrage
@incandescentwithrage 4 ай бұрын
Well yeah, but this was an issue with Exchange Online permissions. Libre Office is not a mail server.
@o0Donuts0o
@o0Donuts0o 4 ай бұрын
@@incandescentwithrageYeah. OP is like “I’m a vegan. Ask me anything because I’m interesting.”
@rabokarabekian409
@rabokarabekian409 4 ай бұрын
I work with FDA regulated businesses. Dropboxes are usually quite secure against the people who need to use them (sic), since there is rarely any discipline about naming, organization of folders, tracking of revisions, or team member interactions online. The other constant is my sermon about only one human can use one username/password, and that security changes should require at least two top humans to sign recorded authorization for changes. I also like "lockbox" type temporary access using offline documented requirements. Someone other than those top two should formally document the verifications before release for prod. (Is your dev open to www by any means?) And oh yeah, no "Test", "Fallback", or "Default" accounts of any kind ever.
@larrykent196
@larrykent196 4 ай бұрын
Thank you for sharing this. Cheers!
@japanstation1
@japanstation1 4 ай бұрын
This is also why OAUTH should not be used - if the account used for OAUTH it is hacked (and if you used MS for OAUTH, then it was), everything you have access to using that account is at risk. Different ID and password for every single service you use.
@zazethe6553
@zazethe6553 4 ай бұрын
But everything allows you to reset your password with your primary email. So if your main email is hacked you're screwed anyway. Might as well use oauth for secondary accounts then.
@pascalmartin1891
@pascalmartin1891 4 ай бұрын
The problem with this approach is that a cloud provider manages thousands of services, invisible to you. They need OAUTH. What is true is that centralized authentication across multiple vendors is not necessarily a safe move. One vendor's security fails, and you watch the domino effect..
@monad_tcp
@monad_tcp 4 ай бұрын
@@zazethe6553 the difference is that you can change your email password, what happened in this attack was an read access to the mailbox, they can read mails that where there, after the security is patched, the new mails with the confirmation won't be getting there. the problem with this reset approach is that you must use a token second factor authentication, the email must be the third factor, the password always the first. OAuth is insecure by design, it was created for laziness and social login, which is bullshit.
@monad_tcp
@monad_tcp 4 ай бұрын
@@pascalmartin1891 There's other ways of doing federation of services without using oauth.
@j_t_eklund
@j_t_eklund 4 ай бұрын
I use luks2 files. Simple to maintain. A lot of custom options to tweak your preferences. Can have multiple passwords and does not rely on cloud at all unless you put it there.
@B_r_u_c_e
@B_r_u_c_e 4 ай бұрын
Very good. Thank you. Also, Threema.
@nospamallowed4890
@nospamallowed4890 4 ай бұрын
It would help if the US and Canada caught up to the EU and passed some laws to protect individuals privacy while retaining the ability to issue a warrant for access. Then we would stop the need to use foreign (EU/Swiss) services and give us back the ability to trust the privacy of data handled by our service providers. BTW, the video missed the worst personal data privacy offender... modern cars surveillance through their "convenient features" and infotainment systems vacuuming everything from your phone. Which they then use to create very comprehensive profiles of you and sell to anyone who will pay.
@Mavendow
@Mavendow 4 ай бұрын
The fact that's even a thing is ridiculous. The idea that our own car could be used to spy on us, I mean. What kind of cursed world are we living in.
@BoGy1980
@BoGy1980 4 ай бұрын
if you're afraid of that, then look into that smartphone you put into the car first, that's 10x more terrible for privacy, especially iphones, they straight out lie to you when you set them on "privacy mode"
@danvin1967
@danvin1967 4 ай бұрын
Thank's, it's a great eye opening video. I wonder where Apple's iCloud as a storage fits into this?
@KenHarrisio
@KenHarrisio 4 ай бұрын
I'm not fully sure about the privacy of their offering. I know they started offering something called Advanced Data Protection not long ago. It apparently uses zero knowledge encryption, but it doesn't apply for the entirety of iCloud.
@JanoschNr1
@JanoschNr1 4 ай бұрын
Does Outlook belong to the 365 service pack?
@SniffHeinkel
@SniffHeinkel 4 ай бұрын
Glad I never used Office 365.
@legionofanon
@legionofanon 4 ай бұрын
Never used 365 and refused at every turn use an email account to log into my computer. I just knew it would turn bad someday
@SniffHeinkel
@SniffHeinkel 4 ай бұрын
@@legionofanon Indeed. I've always thought it was dangerous not to use a local administrator account. I guess I was right.
@friendlyninja5048
@friendlyninja5048 4 ай бұрын
And they thought I was crazy for wanting a local user account 🤣
@Drunkbobnopantss
@Drunkbobnopantss 4 ай бұрын
this is why i dont use microsoft live account to log in its less secure
@InuYasha-SitBoy
@InuYasha-SitBoy 4 ай бұрын
keep it og and xor lol. or just email zip but say the password is “drowssap backwards” or something? great video :D
@Mavendow
@Mavendow 4 ай бұрын
AI would theoretically break both of those with relative ease. If the recipient is willing to undo an xor, then a safer choice is using the SHA-1 of a zip archive's name as the PW. An AI would need to pull down an implementation of SHA-1 and run it to break the PW, which most AIs I'm aware of simply won't be able to achieve. For now. The WolframAlpha plugin shows it's just a matter of time.
@InuYasha-SitBoy
@InuYasha-SitBoy 4 ай бұрын
@@Mavendow i like that hash of file as pw idea. seems obvious in hindsight. i feel like theres only so much that an ai can try to do before its gives up right? like what indicates to give up on trying to open file? wolfram alpha’s new to me. i looked it up looks cool
@vazaruspaytonas7017
@vazaruspaytonas7017 4 ай бұрын
They are already using the accounts to send system emails. I have received 2 system emails asking click a link and open outlook. I report as spam but I don't think that matters at this point.
@edhahaz
@edhahaz 4 ай бұрын
Oh no the russians stole my emails instead of paying MS advertising for them! (lmao)
@liquidsnake6879
@liquidsnake6879 4 ай бұрын
It's not your emails they're looking for, they got those as part of the wide net no doubt, but it's not your data they're looking for
@techguydilan
@techguydilan 4 ай бұрын
@@liquidsnake6879 seriously, some businesses that deal with government secrets as well as our government and military sometimes uses M365. I know a lot of public universities do (as I work for one). So I will fight you on those words you privacy heathen.
@pehclark7256
@pehclark7256 4 ай бұрын
What the hack is TLS certificate? That hilarious Secretary said while important "recipes for disasters" were leaked for 2 whole months costing the secretary her promotion. And then she blame the patriarchy.🤷
@davidew98
@davidew98 4 ай бұрын
I think there was a little confusion in what you said. This is not just simply a hack of a development or production tenant. Hacking into an admin account of just one tenant will not give you access to the whole system. This sounds like a hack that goes much farther than that. it sounds like it’s an account owned by Microsoft admin for the whole service that got hacked.
@BoGy1980
@BoGy1980 4 ай бұрын
why wouldn't pgp encrypt the subject? I sent mails with pgp and those subjects are fully encrypted, you get a blank subject line before the mail is decrypted. Maybe find another mailclient, that has pgp properly integrated, like Thunderbird (FREE / OSS / all OS)
@monad_tcp
@monad_tcp 4 ай бұрын
because its annoying
@justinpatterson5291
@justinpatterson5291 4 ай бұрын
Storage is either local. Or its not an option for me.
@xoxoxo-42
@xoxoxo-42 4 ай бұрын
Uncle Sam back door
@MarcosRobertoDosSantosJF
@MarcosRobertoDosSantosJF 4 ай бұрын
Epstein island backdoor!
@ausfoodgarden
@ausfoodgarden 4 ай бұрын
Luckily we use Openoffice as cloud-based word processing just seems so counter intuitive. Let's create documents with personal data, buiseness IP and just throw them out into the cloud. Seems legit. Nope! Why would we put those documents out there? Sure if they were to be shared publicly I suppose. Nice video Ken. I hope more folks manage to see this and take some action.
@o0Donuts0o
@o0Donuts0o 4 ай бұрын
How has using OpenOffice protected you from anything?
@ausfoodgarden
@ausfoodgarden 4 ай бұрын
@@o0Donuts0o No Microsoft No Cloud what don't you understand?
@o0Donuts0o
@o0Donuts0o 4 ай бұрын
@@ausfoodgarden So you think because you use Open Office you are somehow magically protected for all your documents being exfiltrated from your device, server, network or premises? Okay…
@EstiDeColiss
@EstiDeColiss 4 ай бұрын
Is this related to Outlook aka Hotmail?
@KenHarrisio
@KenHarrisio 4 ай бұрын
Not Outlook directly but if someone uses the O365 email service, then yes. Hotmail wasn't mentioned in the articles I looked through.
@Mavendow
@Mavendow 4 ай бұрын
A good security policy is to assume everything has been breached. I won't go into too much detail (YT won't allow my comment if I do) but basically these guys are skilled at obtaining access to other parts of organizations once they have admin access somewhere else. That's why we regularly see companies announce "they got X, but not Y and Z." Then weeks later: "Well, it seems they got Y too. But don't worry, Z is safe!" Then next month: "Ah, it seems they got everything." It's literally their job; they do this for a living. Save the hassle of finding out later, once it's too late, by assuming everything was taken.
@leeentertainmentchannel247
@leeentertainmentchannel247 4 ай бұрын
U sound honest and u know your shit. Im sub
@KenHarrisio
@KenHarrisio 4 ай бұрын
My man! Thanks for the sub! 🍻
@MrBokkyboy
@MrBokkyboy 3 ай бұрын
Yo ken thx for the vid. Will be sharing this with my manager and CEO in our next meeting 👍🏽. I do have a question. In your diagram I don't see apple eco system. Could you collaborate on that? Because to me it seems that because it's not mentioned that it's better then for example Microsoft?
@KenHarrisio
@KenHarrisio 3 ай бұрын
Hell yeah brother, thanks for the support! I think Apple has a solid eco system. It seems like they take security more seriously than MS. Looking at that from an OS perspective, a lot of that has to do with how Windows works. Apple has also been doing well with increasing their security overall too. Lockdown Mode and Advanced Data Protection are a couple of their most recent features that I think are really good. I haven't tried Private Relay yet, but I heard that's also good. Apple wants people to think they are the better option, which is probably why they have done a better job at securing their stuff overall. If they had stuff like this happening to them, it'd be a huge blow to their PR.
@Tyrael7-bf1ld6zu6s
@Tyrael7-bf1ld6zu6s 4 ай бұрын
I knew this all along ever since the blue screen problem, and it's still there
@PlanetTwilow
@PlanetTwilow 4 ай бұрын
All the GRU needs is to get one agent into a critical position inside MSoft, and we are all foooked.
@user-yn7ll3qz1p
@user-yn7ll3qz1p 3 ай бұрын
Shame it was the CIA and not Russia that did the hack then... you are already "fooked"...
@jimmiller9330
@jimmiller9330 4 ай бұрын
There probably was no accidental foobar. All it takes is some social engineering and money to enlist a MS (or cloud service) employee or developer to tweak a configuration setting.
@TwoBassed
@TwoBassed 4 ай бұрын
Or incriminating evidence! Maybe someone showed Bill his ‘Fantasy Island’ videos!
@jiffonbuffo
@jiffonbuffo 3 ай бұрын
Sometimes I wished those who hated offline storage, particularly microSD card haters on the smartphone segment, get subjected to "cloud disasters" so they get their eyes opened. I don't hate cloud, I just hate a could-ONLY option.
@MichelStumpf
@MichelStumpf 3 ай бұрын
pCloud also swiss base company (servers are not in Switzerland though) but they have a Crypto option with Zero-Knowledge privacy as well
@bog6106
@bog6106 4 ай бұрын
I want someone to spy on me so I don't feel alone. If I find out no one pays attention to me even on the internet then I will be crushed!
@robertanderson5092
@robertanderson5092 4 ай бұрын
Attention 304
@bog6106
@bog6106 4 ай бұрын
gimme attention please@@robertanderson5092
@user-ec3rm9wr1n
@user-ec3rm9wr1n 4 ай бұрын
😂😂😂😂😂😂 I love it 😻
@rabokarabekian409
@rabokarabekian409 4 ай бұрын
Me, too. I am SSSOOOO significant.
@Ben24-7
@Ben24-7 3 ай бұрын
Interesting, because both me and my partner received a fishing email purporting ro be from Facebook regarding copyright violations, to me seemed odd that we both received the emails within minutes of each other ,
@jimmyjames3136
@jimmyjames3136 4 ай бұрын
Thank you.
@Stim-Winded
@Stim-Winded 4 ай бұрын
Was that breach confined to E3 accounts and below?
@KenHarrisio
@KenHarrisio 4 ай бұрын
I haven't seen any information covering that specifically, only that all accounts were able to be accessed.
@Stim-Winded
@Stim-Winded 4 ай бұрын
@@KenHarrisio Thank you most gratefully.
@Talik13
@Talik13 4 ай бұрын
The part at 0:25 about trusting cloud services is something that boomers just don't seem to get. The owner of our store got it in her head (probably from some reactionary "don't trust google" post in her LinkedIn feed) that Google was completely unsafe and decided to migrate our entire team's online infrastructure from Google to Microsoft claiming it was more secure. Of course she didn't know all the work that went into setting up the Google accounts, calendars, and integrations with external platforms like Canva, Trello, Notion, etc - so we spend 3 months moving everything over to Microsoft. And now here we are. It doesn't matter WHOSE platform you use, they're all vulnerable. What a waste of time and energy.
@KenHarrisio
@KenHarrisio 4 ай бұрын
This is spot on. I think the reason that the "cloud" has taken off so much has mostly been because of the marketing. The suits think that outsourcing and getting rid of most of the on prem staff/infrastructure is the easy way. I suppose it might work well for some, but the security issues will always be there and the costs for this stuff just keep rising.
@5mxg
@5mxg 4 ай бұрын
Yaaay 'cloud' everyone. Cloud = not your server.
@user-ec3rm9wr1n
@user-ec3rm9wr1n 4 ай бұрын
Bingo 😀
@danmar007
@danmar007 3 ай бұрын
Gates gets rebooted? Or booted?
@GTOGregory
@GTOGregory 4 ай бұрын
Would an authenticator app be helpful now when logging onto 360 applications, especially email?
@rinzler9775
@rinzler9775 4 ай бұрын
They already have that option. Would not have stopped this.
@monad_tcp
@monad_tcp 4 ай бұрын
@@rinzler9775 the only way this would have stopped is if they encrypted the mail inbox with the user credentials, why don't they do that ? probably because stupid spy agencies used that "test Oauth token" to do "their job".
@GTOGregory
@GTOGregory 4 ай бұрын
@@rinzler9775 Option being the pivotal word. It's not mandatory. Token protection helps. Token protection creates a cryptographically secure tie between the token and the device (client secret) it's issued to. It's another layer of security.
@inappropriatejohnson
@inappropriatejohnson 4 ай бұрын
With storage drives so cheap now, why does anybody use the cloud?
@tommyboi0
@tommyboi0 4 ай бұрын
Lol Microsoft... Why would a serious person ever use anything directly affiliated with the exception of API requests
@vmlinuxz
@vmlinuxz 4 ай бұрын
The problem is that 99?9 percent of even hardcore IT people won't do as good of a job protecting their own servers as a cloud service like Microsoft.
@varelse01
@varelse01 4 ай бұрын
I started using an offline Linux machine and thumb drives to store all my stuff. Private AND less risky.
@jezzamobile
@jezzamobile 4 ай бұрын
I tried Tresorit - very unimpressed ☹️
@GrannyBender
@GrannyBender 4 ай бұрын
The password is "infected"
@AncientSlugThrower
@AncientSlugThrower 4 ай бұрын
Good luck installing windows without an emaill address in 202X. It is possible, but how many people just mashed in their email account to get an install rolling? That has to be a lot of email addresses. Probably not the Russians.
@Mavendow
@Mavendow 4 ай бұрын
Windows 11 requires a custom ISO to do it reliably. While I have modded my copy of Windows, this is not what everyone should be doing, because it makes the OS and by extension the device cryptographically insecure. A popular tool to do this is Rufus, and who's to say that developer's PC hasn't been compromised? Heck, Microsoft included a backdoor within their Visual C++ *compiler* years ago. Only after people noticed that their compiled exe's were contacting MS's servers did they backtrack. The solution is to start avoiding MS tools wherever security is required.
@TwoBassed
@TwoBassed 4 ай бұрын
I figure CIA more likely, they have access to the Epstein Island footage, plenty of leverage!
@markwrede8878
@markwrede8878 4 ай бұрын
Microsoft One Drive as the host for Office has committed the greatest heist in American history, taking hostage all the working files of the nation.
@pkf4124
@pkf4124 4 ай бұрын
The only safe data is offline on a server you own, backed up in several locations that you 100% own and even then its only really safe from non government sponsored stuff.
@rinzler9775
@rinzler9775 4 ай бұрын
Office 97 was the pinnacle, then it was all down hill.
@mikerollin4073
@mikerollin4073 4 ай бұрын
Great stuff
@87detto
@87detto 4 ай бұрын
So what about Apple's end-to-end encrypted iCloud Drive and their Mail and Chat service?
@BoGy1980
@BoGy1980 4 ай бұрын
apple, lol, those guys that told the state couldn't hack their phones and within 2 weeks it was announced that the iphone was unlocked... you gotta believe everything apple says, and then after you gained all that knowledge, just take the opposite of those words and forget what apple said. They're the biggest hypocrits and liars in tech
@Maelael
@Maelael 4 ай бұрын
This is just another reason why you should be changing passwords every 90 or so days to ensure your safety. If there is ever word of a hack involving a company/bank/service or anything else you use, change your passwords, AND security questions ASAP, and keep hyper vigilant. Report to the company/bank/service if you receive a sudden request text or email for a password change inquiry that you DID NOT request. Make sure that any email that you suddenly get from an unknown source is legit, and if you are super unsure, be safe and run that on a vurital machine that if you feel something is seriously not right, you can kill that instance, wiping out the possible threat. Do your homework if you get cold-called, and reverse lookup numbers that you deem suspiciuos. And lastly, come up with complicated, passwords that no one would easily guess and use a different password and username for EVERY site that you use. This will help lessen your exposure and will make your life easier.
@rabokarabekian409
@rabokarabekian409 4 ай бұрын
Hmm, tell me again, How fast does a computer work with no human interaction? OOOOOOhhhhhhhhhhhhhh - huh.
@BenjaminWalburn
@BenjaminWalburn 4 ай бұрын
Password changes aren't nearly as helpful as you think.
@soundspark
@soundspark 4 ай бұрын
I believe Thunderbird can encrypt the subject line.
@BoGy1980
@BoGy1980 4 ай бұрын
exactly!
@KarrennCoffey
@KarrennCoffey 4 ай бұрын
Hi, can I store my data on your system, oh,oh yes, I'm sure you won't search it. Kind of like the medicine cabinet in your host's house...
@steveblanchard7293
@steveblanchard7293 4 ай бұрын
Why hasn't this been reported in the Mainstream?
@KenHarrisio
@KenHarrisio 4 ай бұрын
I got the impression from the article that MS is trying to downplay this as much as they can. I noticed some articles coming up in previous weeks talking about it as well, but I haven't noticed it get much coverage.
@user-ec3rm9wr1n
@user-ec3rm9wr1n 4 ай бұрын
Everyone knows......
@rabokarabekian409
@rabokarabekian409 4 ай бұрын
Lamestream?
@debugin1227
@debugin1227 4 ай бұрын
You should have gonad’s face in the thumbnail, note gatesy
@maxscott3349
@maxscott3349 4 ай бұрын
One of the biggest problems I have with all this security stuff is that I have almost no data that has any reason to be secured. My bank account, sure. Which- if I ever have a reason to have a lot of money in my checking, I'll probably open a separate account. I don't keep more than a few hundred in it normally, so a breach there is not the end of the world. Nothing else I have online matters. I can see my email being abused against someone else but nobody has my email either. I have accounts on several hundred websites that exist solely because they made me. There's 4 or 5 things I actually want passwords on. Everything else is a complete waste of my time and should be optional.
@ElbowNi
@ElbowNi 4 ай бұрын
You realise that this attack was conducted by hacked "home computers" in residential areas, so the traffic comes from clean IP addresses in the region. Not protecting your IT infrastructure, be that web sites LAN or WAN just gives the bad guys more choice. "Midnight Blizzard used residential proxy networks, routing their traffic through a vast number of IP addresses that are also used by legitimate users"
@xTheToolx
@xTheToolx 4 ай бұрын
Your data is training the next generations of AI advent into cyborgs and androids. Your likeness, views, and thoughts have all been sold to the highest bidder long ago. All hail Skynet that will continue to live in our image.. right down to the mannerisms and personalities. Immortality???
@guser7137
@guser7137 4 ай бұрын
The point is that that information that you deem unimportant paints a very accurate image of you. To the extent it can be used to predict your behaviour. If your behaviour can be predicted, it becomes very easy to manipulate you.
@maxscott3349
@maxscott3349 4 ай бұрын
@@guser7137 If they have enough information to manipulate me, they're not doing a very good job. Plus all these passwords and accounts are not going to protect any data from the people who are selling it.
@bassmaiasa1312
@bassmaiasa1312 4 ай бұрын
You might consider that a criminal could use that 'second tier' data to convince a friend or family member that they know you personally. "I went to school with your son years ago." "Oh, that's nice."
@zimissscameras
@zimissscameras 4 ай бұрын
no way that was an error, it was by design
@BenjaminWalburn
@BenjaminWalburn 4 ай бұрын
You're clearly not a dev, or someone with critical thinking skills.
@zimissscameras
@zimissscameras 4 ай бұрын
@@BenjaminWalburn
@piratelechuck1911
@piratelechuck1911 4 ай бұрын
@@BenjaminWalburn You're clearly someone with more pronouns than braincells.
@spootnewton7121
@spootnewton7121 4 ай бұрын
Keep or bring applications and data back in-house. Disconnect critical systems from the internet completely. Keep physical backup copies in multiple and diverse locations. Or, suffer the inevitable consequences coming soon.
@kjetilhvalstrand1009
@kjetilhvalstrand1009 4 ай бұрын
Funny how standardized authentication services, are the security hole, how can imagine :-P
@KZ9955
@KZ9955 4 ай бұрын
I honestly just use Libre Office.
@Vaclav999
@Vaclav999 4 ай бұрын
means nothing because i dont use Microsoft Products. Close Hells Gates.
@PlanetTwilow
@PlanetTwilow 4 ай бұрын
Note, MSoft forced all 'hotmail' users to use cloud outlook to access email.
@Lets_DoWhatWeWant
@Lets_DoWhatWeWant 4 ай бұрын
Got Veracrypt?
@stuart_gill
@stuart_gill 4 ай бұрын
I was waiting for this to be mentioned too. This is the first video I’ve seen on this channel, so I’ll look at the other videos here.
@AndTecks
@AndTecks 4 ай бұрын
you look like an ex marine from 1980 with a good camera
@sonofsandwiches6892
@sonofsandwiches6892 4 ай бұрын
Ah yes, that reminds me. I need to convert my Windows 10 PC to Linux this weekend.
@xzs432
@xzs432 4 ай бұрын
lol me and my mom use libra office and we don't use onedrive!
@RonnieRedd
@RonnieRedd 4 ай бұрын
Only use your own network
@MarkyGoldstein
@MarkyGoldstein 3 ай бұрын
Microsoft is increasing its Linux deployments in Azure for good reasons
@GuiOpsDev
@GuiOpsDev 4 ай бұрын
THIS is why I won't update my Outlook 365. The newest version REQUIRES that you sync your entire email contents with MS's Office 365 servers. NOPE! Not in a million years!!
@RussMichaels
@RussMichaels 4 ай бұрын
How about Google hangouts, is that secure communication?
@zoneundertop
@zoneundertop 4 ай бұрын
No
@KenHarrisio
@KenHarrisio 4 ай бұрын
Something like Jitsi or Signal's calling service is going to be better for security and privacy.
@TheZettaze
@TheZettaze 4 ай бұрын
Isn’t hangouts discontinued like everything else google makes?
@Mavendow
@Mavendow 4 ай бұрын
​@@TheZettaze It's called 'chat' now. It's the one product they somehow keep rebranding after saying it's going to end.
@RussMichaels
@RussMichaels 4 ай бұрын
@@TheZettaze no its part of gmail and google workspace, it got renamed to Google meet and google chat
@Douglas_Blake_579
@Douglas_Blake_579 4 ай бұрын
Here we have the reason that every OS and every Storage option should be free standing and isolated to the user's systems.
@justna9516
@justna9516 4 ай бұрын
Oh great. My mom use 365 for coding class
@niv8880
@niv8880 4 ай бұрын
It's only a matter of time before everyone's business is public business
@Tautolonaut
@Tautolonaut 4 ай бұрын
I've been told I don't own anything, so why should I care what mistakes they make with their data?
@travisleabeck2572
@travisleabeck2572 4 ай бұрын
Okay...so why the fuck is there a toggle for being able to read EVERYBODY's emails at once!
@DailyCorvid
@DailyCorvid 4 ай бұрын
A think a more intelligent questions would be, who created a toggle for being able to read everybody's emails. Plenty of reasons why somebody would want that. But not many people who would admit to having actually done it. I think it must have been by design.
@travisleabeck2572
@travisleabeck2572 4 ай бұрын
@@DailyCorvid you and I both know that my question was entirely rhetorical. Hence the exclamation instead of a question mark. And I'm pretty sure most of the people in this comment section are smart enough to give an answer to yours. We all knew this was a thing. We just didn't know the extent of their capabilities and now that the cat is out of the bag it's going to be real sad to see nothing get done about it. I always knew that emails and windows itself had backdoors written into them. But I had at least hoped that the backdoor for emails had to be toggled per individual. Fucking crazy that there is an all or nothing. I have a few thoughts about how this scenario could be weaponized for evil obviously, but a few wear it could be used for good as well. Let's say someone at Microsoft is just waiting on a certain initiative to do a mass leak of corrupt government officials. And these hackers just destroyed their timeline. Hopefully we will see some positive fallout from this. Whether it is action against privacy invasion or some action similar to what I theorized. hopefully both
@DailyCorvid
@DailyCorvid 4 ай бұрын
I think you missed the point of what I was saying - I wasn't making out your comment was dumb, I was saying it must have been done purposefully to begin with, and that's why it was never detected. Somebody covered their tracks having set it up, and it was done with intention to be used the way it was.
@travisleabeck2572
@travisleabeck2572 4 ай бұрын
@@DailyCorvid I know you weren't friend. I'm not arguing that you were. And I'm agreeing with your statement as well if you read into my reply. I just didn't say so outright. Sorry for the confusion
@travisleabeck2572
@travisleabeck2572 4 ай бұрын
@@DailyCorvid but I do realize that maybe I missed your point that this was always a singular agent or entity(agency) who meant for this do be kept secret and hidden even from the heads of the hydra. I touched on that thought, but may have misread that that was you focus.
@jonny1872
@jonny1872 4 ай бұрын
Russian State hackers, what a surprise, it's always the person they don't like at the time.
@TwoBassed
@TwoBassed 4 ай бұрын
I’d believe CIA state hackers before Russian!
@TehPwnerer
@TehPwnerer 4 ай бұрын
If you want private mail roll your own VPS/mail server
@searealOG
@searealOG 4 ай бұрын
Our mail
@recommens-comedy-central9761
@recommens-comedy-central9761 4 ай бұрын
It's not free YOUR THE PRODUCT
@burprobrox9134
@burprobrox9134 4 ай бұрын
MS is at the forefront of offshoring and contractors are NEVER as security conscious
@TheEquestriancolt
@TheEquestriancolt 4 ай бұрын
Don't forget about TUTA as a private secure mail provider as well.
@Lownwolf-sm5py
@Lownwolf-sm5py 4 ай бұрын
He mentioned tutanota which is the old name for tuta
@TheEquestriancolt
@TheEquestriancolt 4 ай бұрын
Thanks I MISSED HIM SAYING IT. @@Lownwolf-sm5py
@AlexKidd4Fun
@AlexKidd4Fun 3 ай бұрын
For the uninitiated, Larry Ellison of Oracle was first to say this back in the 2000s. Look it up. 😉
@beckylowery5236
@beckylowery5236 2 ай бұрын
I am hacked... I need to know what to do to get into my computer... I can not loose my pictures... I lost all my pictures before in a fire.. lost my whole life with my children at that time.
@KenHarrisio
@KenHarrisio 2 ай бұрын
I'll need to get some more context to help you out. Are you currently using Windows, and If so, which version? Also, what anti virus do you have installed on your computer? Do you also have any more details on the infection, like odd programs appearing or any other odd behavior?
@beckylowery5236
@beckylowery5236 2 ай бұрын
@@KenHarrisio yes it is windows... not sure what antivirus was on it.. I know it did have McAfee, Norton and Avast were all on it. I have been extremely stalked for a while now. To the point every thinks I am crazy. I am not technology inclined. Whoever has hacked me has been keeping a record of all that I do for a feed years it seems. They told me so by posting on the different social media apps and they are hacked into my home TVs as well as my phone. It is an iPhone. It taunts me. At some point I know they will have a very bad end. But I wish them to stop now. It literally drives me crazy.
@KenHarrisio
@KenHarrisio 2 ай бұрын
@@beckylowery5236 As far as Windows, I would recommend using something called a second opinion scanner. A good one is Kaspersky Virus Removal Tool. You could also try Malwarebytes. You don't need to pay for it, as you can just use the on demand scanner for free. As for the iPhone, if it has iOS 16 or newer, you could consider using Lockdown Mode. It'll restrict the usability of the phone though. You can find more info on Apple's website about it. It's really easy to turn on and off if you decide to try it.
@RandomUser25122
@RandomUser25122 4 ай бұрын
Microsoft are now forcing my Windows 10 pc to use my Hotmail login. I’ve had to close my Hotmail email addresses because someone was trying to get access, even though I haven’t used the accounts as email for nearly a decade. I discovered with the login my doc folder and documents were on their stupid cloud. FFS I’m guessing the Russians will have the data over to the dark web just because they can
@technicalfool
@technicalfool 4 ай бұрын
Don't forget to create a Microsoft account with your Windows 11 device. Pfff...
@simplemechanics246
@simplemechanics246 4 ай бұрын
MS never ever had any security on any level.
@nil0bject
@nil0bject 4 ай бұрын
test domain in production is still in production. M$ can burn in hell
@robmorgan1214
@robmorgan1214 4 ай бұрын
If companies and governments keep relying on MS, they get what they deserve. The MS dev team can also read all your mail if the hackers can...
@johnnopeyy4129
@johnnopeyy4129 4 ай бұрын
When it rains it's the Rusaians. 🙄
@F-Bomb313
@F-Bomb313 4 ай бұрын
wow, scary
@mkeyx82
@mkeyx82 4 ай бұрын
I don't use any of the MS services so the answer for me is: nothing, absolutely nothing.
@hackaboom
@hackaboom 3 ай бұрын
people wonder why i get "huffy" about giving out information to people that dont need it. least priv pepes, least privilege for the love of all that is holy, least (no if possible) privs.
@thewholeroll
@thewholeroll 4 ай бұрын
I'm pretty sure that Microsoft believe this attack is limited to Microsoft's own corporate 365 mailboxes and not customer tenants.
@vazaruspaytonas7017
@vazaruspaytonas7017 4 ай бұрын
Yes this true because the guids for each account are different for each tenant. So the test account in a separate tenant is not the same.
@npcwill283
@npcwill283 3 ай бұрын
Does not feel like a mistake . Just leave one account with special privilege's and you can sell that shit to the NSA for millions !
@pwood5733
@pwood5733 4 ай бұрын
So they had another massive data release
@leos3003
@leos3003 4 ай бұрын
Hope they have a good time reading my Grandma's emails. I don't trust M$ for a second. But I also don't email anything useful.
How to never accidentally run Malware: Must Have Windows Tweaks
7:21
The PC Security Channel
Рет қаралды 307 М.
1🥺🎉 #thankyou
00:29
はじめしゃちょー(hajime)
Рет қаралды 79 МЛН
ДЕНЬ РОЖДЕНИЯ БАБУШКИ #shorts
00:19
Паша Осадчий
Рет қаралды 6 МЛН
ПАРАЗИТОВ МНОГО, НО ОН ОДИН!❤❤❤
01:00
Chapitosiki
Рет қаралды 2,8 МЛН
Indian sharing by Secret Vlog #shorts
00:13
Secret Vlog
Рет қаралды 61 МЛН
2 USB boot drives EVERY PC user should make before it's too late!
8:48
Ask Your Computer Guy
Рет қаралды 1,4 МЛН
Explanation of VPNs for dummies
18:56
TotallyNotK0
Рет қаралды 808
Setting up VR on MSFS 2020 Oculus Quest 2
15:23
Mike K
Рет қаралды 69 М.
6 Most Secure Web Browsers in 2024 (which is the best?)
11:22
Cyber Lab
Рет қаралды 153 М.
Extracting Firmware from External Memory via JTAG
7:59
Joe Grand
Рет қаралды 106 М.
How to Check if Someone is Remotely Accessing Your Computer
16:58
[MSFS] Airbus A320neo Startup Tutorial|Drawyah
22:00
Drawyah
Рет қаралды 408 М.
German State Is Ditching Windows For Linux
30:23
Ken Harris
Рет қаралды 76 М.
i love you subscriber ♥️ #iphone #iphonefold #shortvideo
0:14
wyłącznik
0:50
Panele Fotowoltaiczne
Рет қаралды 24 МЛН
Xiaomi Note 13 Pro по безумной цене в России
0:43
Простые Технологии
Рет қаралды 2,1 МЛН
Will the battery emit smoke if it rotates rapidly?
0:11
Meaningful Cartoons 183
Рет қаралды 4,5 МЛН
iPhone 15 Unboxing Paper diy
0:57
Cute Fay
Рет қаралды 1,7 МЛН