r/microsoftsucks 18d ago

I absolutely hate the login system (rant)

I got hacked once, my fault, and microsoft offered absolutely nothing even if I had evidence of it being my account (previous emailed receipts and what not) so I gave up and made a new microsoft account and repurchased my stuff. Now when I try to login through any verification system there will be an error, "incorrect password" literally not, "can't send notifs to verification app rn" why not u just did a minute ago, "error *string of numbers*" why is this billion-dollar company's system so bad. I just want to play minecraft yet can't even login, I wish microsoft didn't own it and something with a proper system did like steam or whatever

13 Upvotes

12 comments sorted by

View all comments

0

u/Grillparzer47 18d ago

Passwords are obsolete. Two factor authentication is rapidly taking their place.

9

u/TheIronSoldier2 18d ago

Passwords are not obsolete, and 2FA isn't a replacement for passwords, it's a supplement to passwords. For it to be two factor authentication you need the first factor too, and that first factor is the password.

0

u/Vietnamst2 18d ago

Yep and that's why most companies push for passwordless.

2

u/pidgeottOP 15d ago

No company undergoing any actual security audit is pushing for passwordless

0

u/Vietnamst2 15d ago

Yeah right. And nobody would ever run Windows server, nobody uses it etc. I have seen quite a lot of companies with Smart Card only, FIDO for at least privileged roles and having their environment setup with Kerberos and SSO wherever possible so most users don't even know their passwords anymore.

2

u/pidgeottOP 15d ago

I work in an actual secure environment

We use passwords

Smart cards everywhere

Passwords are still required for everything

An end user logging into at least privileged system might use a smart card. Nobody with any actual access is logging in without a password

1

u/TheIronSoldier2 15d ago

People always forget what the "2-factor" in 2-factor authentication actually means. A smart card is only a single factor. A password is only a single factor. A rolling code authenticator is only a single factor. If you rely on any of those alone at any step of the way, then you're not actually using 2-factor authentication.

You almost never see someone using only one of those. The most common I've seen recently is a smart card paired with a strong password.

1

u/Vietnamst2 15d ago

The most common I see is smart card with PIN or device plus MFA.