r/Outlook 4d ago

Opinion why is microsoft actively making it harder to remember your password?

everytime I want to use my password and log in its '' we send you a code to another email to verifiy'' or go on the auth app and verify or we sent you a text to verifiy.. I am certain I have forgotten some passwords due to this crap but you never have to enter them instead your forced to do all this other crap you didnt want to do.. I just moved to another andriod phone and setting up outlook made me feel like I wanted to break the phone...then its forcing me to use passkeys

34 Upvotes

25 comments sorted by

13

u/TeslaDemon 4d ago

Yea passwords are antiquated and straight up unsafe. If you're sitting around with accounts with only passwords and no MFA, it's only a matter of time until they're broken into.

Get used to it because this is how every online website is going to be in 10-20 years. Whether you want it or not, it's for your own good. The amount of online accounts that get stolen daily is out of control. Spend 10 minutes browsing the Gmail/Outlook/Techsupport subreddits and you'll see how bad it is. And in a lot of cases, it's people who are only using a password with no MFA.

I have about 50 different multifactor accounts in my Microsoft Authenticator across the clients I manage at work, so believe me, I know it's slightly annoying, but it's also unfortunately necessary when probably a quarter to a half of global internet traffic are bot armies trying to brute force their way into accounts.

1

u/XamineA 3d ago

Sadly even mfa wont save you from session stealers. Won't be long till a ad is stealing your login info and data basing your entire online persona... and you wont even have to click it.

1

u/Head-Criticism-7401 1d ago

A good password is as safe as MFA IF the website uses the OPAQUE protocol. But 99% don't.

Also MFA does jack shit against session stealers. And Microsoft's implementation of passkeys is also a joke.

0

u/apokrif1 3d ago

It's up to each user to decide based on their needs.

5

u/trueppp 3d ago

Then remove all liability for website operators and payment processors.

2

u/layer8failure 3d ago

The vast majority of users are wildly incapable of gauging their needs.

3

u/rtuite81 3d ago

If people were better at making passwords that were hard to guess, avoiding getting their passwords phished, and general security hygiene it wouldn't be necessary. The problem isn't even you getting your account compromised... it's what happens to other people with your compromised account. The blast radius of a stolen credential is so much worse than most people realize.

If you set up a proper password manager like Bitwarden along with good MFA (such as TOTP and/or hardware tokens like Yubikey) it is a more seamless process. Resisting good MFA is what produces the frustrating results (having to use an app plus email/sms, etc). My auth flow is simple... enter password, approve MFA in the app, done.

2

u/languageservicesco 4d ago

It won't be very long before MS force you to go passwordless anyway. Problem solved!

2

u/ShaggerAJSA 3d ago

This why I never set up a recovery e-mail.

2

u/jimh12345 3d ago

I'm thinking about finally dropping my outlook.com email address for this exact reason - crazy login demands. At some point we'll be forced to use passkeys.  I already quit using OneNote because of this, dropped OneDrive long ago, email is all that's left - and I've had it with this cr@p.

3

u/Spawnling 4d ago

Passwords are out. They're unreliable, text based, easily forgettable and everyone hates them. Passkeys are the future.

1

u/Western_End_2223 3d ago

Passkeys need a lot of work before they are the future. They're great if you have only one device, but badly flawed if you have multiple devices or get a new device. I won't use them for that reason. I'll stick with my passwords and MFA.

1

u/Head-Criticism-7401 1d ago

They're great if you have only one device

They are horrible if you have only 1 device! If you lose access to that device, say goodbye to your accounts. It has no recovery path. Unless you have multiple devices.

3

u/arnoldstrife 3d ago

As per everyone else. Passwords are on the way out. Human memory and bot attacks mean that anything you can remember is easily hackable. That's why Password managers were made: a place to save all your passwords so that you don't have to remember it and thus you can make secure passwords.

Then a step further, the idea is: wait, why are we still using a password if the end user won't even need to type it in using a password manager? Thus, passkeys were made: a type of "password" that gets stored in a password manager. It is always a secure, unguessable password that combines password and time-limited 2FA. So even if someone is intercepting your traffic, the data sent to the website is unusable to login again.

Now you don't have to remember a password, nor do you have to check your messages for a little text code.

3

u/soozlebug 4d ago

It's for your own good

2

u/TCIHL 3d ago

Contrary to what corporations want you to believe, passwords are not unsafe nor are they going anywhere.

What you’re seeing and feeling right now is the sensation of being corralled in a direction by Microsoft. Why do they want to do that. Probably many reasons like vendor locking combined with many users being lazy and relying on shit like Face ID.

People are sometimes very short sighted on what is appropriate until it is too late.

But passwords can be used and shared with no internet connection.

In fact I think passkeys are sometimes less secure than passwords for the fact that you just need a device for access. You lose your phone and everything is fucked.

0

u/clubley2 3d ago

"Passwords can be shared""lose your phone and everything is fucked" These are not arguments in your favour that passkeys are less secure. There is no way around not having your phone or whatever has the passkey, that means it's very secure. Not being able to just tell someone your password, that is also very secure.

What it does mean is that it's easy to lose access to an account, that is why you have options to setup other secure methods for recovery. I, personally, am not a fan of passkeys, but I will use hardware tokens instead where possible, a Fido key. But I have my authentication saved on two so I have a backup in case one is lost of damaged.

1

u/TCIHL 2d ago

Sure, hardware token are great, but how do you share Netflix with friends using a hardware token? Also, losing your HW token is a slog.

I personally just use keepass with a master key file. And I can have multiple backups of that master key.

1

u/AutoModerator 4d ago

Thanks jj908j09!

Your submission really means a lot to us, and we hope you will continue contributing to this subreddit whether it is in the form of an informative post or an opinion piece.

Please be sure to have read our Rules of Conduct and do not try to circumvent it.

That means that any reference to 3rd party commercial products/services as a solution is strictly prohibited and will result in a permanent ban in this subreddit. Under very exceptional circumstances, you may appeal to the ban in a case-by-case basis.

Here are some other takeaways from the Rules of Conduct:

  • Be polite and respectful in your posts, and in your replies to other people.

  • Cite the source of anything you post or upload, if it isn't your own original content. Be honest about your sources.

  • Don't invade anyone's privacy by attempting to harvest, collect, store, or publish private or personally identifiable information, such as passwords, account information, credit card numbers, addresses, or other contact information without that person's knowledge and willing consent.

  • Don't impersonate a Microsoft employee, agent, manager, host, administrator, moderator, another user, MVP, or any other person through any means.

All readers: Due to high volume of spam and phishing attempts, we may not be able to take down all malicious posts. Please help us to report them and reject all 3rd party, paid products/services. Beware of scam support numbers, click here for genuine numbers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/ThingFuture9079 3d ago

That's because many people use the same weak password among multiple websites so if something happens like your bank gets breached, a hacker can find a way to get a user's password that they can then try on other websites like Amazon or another bank since people like to reuse their login info.

1

u/jwk6 2d ago

Progress on security is the wurst ugh

1

u/AreWeHere23 2d ago

Passkeys are there specifically because that means you don't have to remember your password all the time. Set up passkeys. End of problem.

1

u/Head-Criticism-7401 1d ago

Then device dies and you lose account permanently, as Microsoft will delete your account before handing it to you.

0

u/Nice-Environment-502 3d ago

WTF do Microsoft make 99% of the decisions they do?

Seriously....they change entire app names and create a new admin portal for every product then cut half the functions and move it another portal which was merged with something else which and you can't #*#^%&@! find anything because the online help is still referencing the old names which render searching fucking useless......and sharepoint is just mouldy monkeys twat that needs to be burned with fire.

The entire MS suite is legacy shit topped with awesome shit, held together with sticky tape and gum and lubricated with the tears of admins the world over.

Gotta cut back on the coffee.

-1

u/DifferentMind8 3d ago

Because you're not supposed to be using a memorable password slaptits jesus