Microsoft Security Issue

woman in black hoodie holding a bank card

Over the past few days, I’ve been receiving multiple emails from Microsoft’s Account Team with single-use codes. At first, I assumed that my son or wife was trying to access the account. And the folks at Microsoft added the text “If you didn’t request this code, you can safely ignore this email. Someone else might have typed your email address by mistake.” But I started to get concerned as the number of these messages increased and no one said “hey dad, I can’t get in the Office”. Finally, I decided it was time to figure out what was going on.

So, I first logged into my Microsoft account (account.microsoft.com) and went to the security panel. From there I opened “View My Activity”.

What I saw alarmed me. There multiple attempts to log in from places like Vietnam and Guyana.

Now, I was pretty confident in my account’s security. I update my password regularly and use a strong password. And when I looked at the “session activity” it states that “incorrect password entered”. Which seems pretty solid. I’m pretty sure that an old password has been leaked from a data breach and is in some list available on the dark web.

But I think it’s not adequate. Exploring further, I realize that I had not yet enabled two-factor authentication, nor connected it to my authentication app. So, I fixed that promptly. I firmly believe everyone really should do these steps for all their account. Do you know where to do that? I thought I’d help out by adding the steps.

One enables that from the Advanced security panel.

I encourage all of you to make sure your security settings are using the most up-to-date protocols:

  • Multifactor authenication
  • Authentication Apps
  • Pass Keys

Also, I opted to sign out of EVERY app. Yeah, it’s a bit of a pain, but I don’t want to have my information compromised. I like that I can do that from the control panel.

Anyway, we really can’t be too safe on today’s internet, can’t we?

Have you seen a spike in Microsoft Single Use Code emails that are not from you? Let me know in the comments.

Oh, Lord…LastPass

I’ve used LastPass for several years now. Even through a couple of data breaches. But this latest saga, especially with the, *ahem*, lack of transparency in their communications eroded my trust in the app. After looking over several options (if you’re looking, check out PCMag’s list of Best Password Managers), I opted for NordPass.

With all that, yesterday, this video came into my YouTube feed:

If you’re still on LastPass, why!?

It’s a rather snarky rendition of how LastPass failed in their security controls. Anyway, it reminded me of my frustrations with them. I was willing to turn a blind eye to many of their issues due, well, laziness. Porting to a new provider was going to be a pain the…you know. However, a friend of mine’s information was released in this hack, and it was brutal. This was the tipping point for me, watching the impact of this for a friend’s business.

This finally motivated me to shift to Nordpass. It turned out that the transition was nowhere near as hard as I imagined. So, so far, I find the tool works fine and have no problem recommending them. It’s only based on a few weeks of experience, though. I’ll keep exploring it further.

Anyway, I hope you have great weekend plans.

DNA, Technology and Unintended Consequences

From Wired Magazine: “There’s No Such Thing as Family Secrets in the Age of 23andMe”

This looks at the fascinating intersection of biological tech with democratized data, laden with so many “unintended consequences” in the DNA market (is it right to call this a “market”?).

I believe there was no way to guess these issues would come up when humanity first developed medical insemination. DNA databases and the commodification of DNA data: I doubt we could’ve guessed this coming about 10 years ago, much less in the 1970s.

Many, many questions, so few answers. The way forward seems murky. I guess it always is.

A Tuesday Haiku

Humanity’s child

Born of electrons’ motion

Will flowers be loved?



Discussing Artificial Intelligence with a friend I wonder if AI will be our contribution to the universe. If Fermi’s Paradox will be overcome by humanity in spite of our drive towards insanity.

I wonder…

Surveillance and Culture

In my Human Relations class we’re discussing corporate surveillance. In one of my responses I brought up my concern about how companies, tracking their employees, are then responsible for securing that data. In response, one of my classmates shared this video with me that’s quite relevant. As he described it, it’s a 20-minute Socratic exploration into data security and social surveillance. Some very interesting discourse, for me at least. Powerful questions to ask as technology’s ability to track our every move grows daily.

The Dance Of The Bits

Bits and bytes dancing
Our culture is in motion
Technology’s grace

F***ing Annoying Robocalls

Gads! Yet another robocall on my office line. This one was about our “vehicle warranty expiring”. Massively annoying.

I, interested as I am in things marketing, I had to wonder what kind of ROI these provide. How many people bite on these schemes? How much money is made?

I expect that the investment for most of these comes in the acquisition of the spoofing software and the list of phone numbers to use for the fake caller-id. Either time, or a few bucks on some dark-web server. So, like spam email, a very low follow through rate is fine. The software probably sends out hundreds of calls a day (thousands?), so one or two folks responding and closing does, in the end, pay off. This calculus doesn’t include jail time, fines, etc for law violations. If these folks are offshore, they might be lacking.

My main thought: if you’re a legitimate business, I urge you to use caution with these bots. Confirming doctors appointments, is, I think, fine use of these technologies. For cold calling clients: no…dear god, don’t do it! Invest the time and resources to do this right. Research your contacts, know who you’re calling, and how you will make their life better.

What do you think? Let me know.

Exploring The Microsoft Surface

I’ve had a Surface for several months now. Only recently have I explored this thing in greater depth.

Just discovered the hand writing input option. which I’m using right now. It’s pretty good, in my opinion.There are some things it’s taking me a bit to get used to. One: the way it processes when I get to the end of entry line. Sometimes it takes a few seconds to catch up. On the other side, every so often it will start to process my entry mid-word.  Things often get weird. Every so often it will let me keep adding letters. Other times it just stops and gets funky. Probably my learning curve.

Have you spent any time on one of these? What did you think? I actually rather like it. We’ll see. I plan to explore it more.

I love all this interest in manual typewriters

I find this new love
With manual typewriters
Deeply endearing