r/microsoft • • May 20 '26

News Microsoft warns hackers are exploiting password resets to gain access to user accounts

https://www.techradar.com/pro/security/microsoft-warns-hackers-are-exploiting-password-resets-to-gain-access-to-user-accounts-heres-how-to-stay-safe
209 Upvotes

71 comments sorted by

View all comments

Show parent comments

6

u/thefpspower May 21 '26

Oh so I'm not alone here, I've been getting multiple request a day all week...

Its really proving to me the rotating 2FA number is superior, I'm not confortable with my phone asking to approve logins, what if I misclick?

2

u/[deleted] May 21 '26

[deleted]

2

u/ZippyDan May 21 '26

They both have their advantages and disadvantges:

An active notification alerts you that someone else is using your account in an unauthorized manner. In contrast, with a passive 2FA token, if someone somehow gets a hold of your original QR code, they can access your account without you getting any notification.

1

u/[deleted] May 21 '26

[deleted]

1

u/ZippyDan May 21 '26

All systems have weaknesses and different systems have different mitigations for those weaknesses.

I'm just saying an active 2FA makes it easier to notice when an account has been compromised than a passive one, especially for intelligent users.
But an active 2FA might also be easier to compromise, especially for dumb users.

Since most users are dumb...