Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Look at this fantastic piece of advice from Microsoft!

Look at this fantastic piece of advice from Microsoft!

Scheduled Pinned Locked Moved Uncategorized
38 Posts 36 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • theodric@social.linux.pizzaT theodric@social.linux.pizza

    Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

    leorjorge@mastodon.socialL This user is from outside of this forum
    leorjorge@mastodon.socialL This user is from outside of this forum
    leorjorge@mastodon.social
    wrote last edited by
    #15

    @theodric This has to be an LLM response... even leaving alone this horrible security advice, the whole response is trying to do the exact opposite of what the OP asked!

    evehaswords@toot.catE 1 Reply Last reply
    0
    • theodric@social.linux.pizzaT theodric@social.linux.pizza

      Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

      bluetea@ioc.exchangeB This user is from outside of this forum
      bluetea@ioc.exchangeB This user is from outside of this forum
      bluetea@ioc.exchange
      wrote last edited by
      #16

      @theodric omfg. seriously.

      1 Reply Last reply
      0
      • kc@social.coopK kc@social.coop

        « Additionally, Microsoft has methods for scanning the contents of password-protected zip files, such as extracting possible passwords from the bodies of an email or the name of the file itself »

        Isn’t that technically a cybercrime in most countries 🤔

        6@possum.city6 This user is from outside of this forum
        6@possum.city6 This user is from outside of this forum
        6@possum.city
        wrote last edited by
        #17

        @kc@social.coop the fines are just the price of doing business 😜

        1 Reply Last reply
        0
        • theodric@social.linux.pizzaT theodric@social.linux.pizza

          Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

          burak@gursoy.socialB This user is from outside of this forum
          burak@gursoy.socialB This user is from outside of this forum
          burak@gursoy.social
          wrote last edited by
          #18

          @theodric p4ssw0rd1

          1 Reply Last reply
          0
          • theodric@social.linux.pizzaT theodric@social.linux.pizza

            Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

            ljwrites@writeout.inkL This user is from outside of this forum
            ljwrites@writeout.inkL This user is from outside of this forum
            ljwrites@writeout.ink
            wrote last edited by
            #19

            @theodric “Microsoft has methods for scanning the contents of password-protected zip files, such as extracting possible passwords from the bodies of an email or the name of the file itself[.]” Cool and normal stuff, your storage provider telling you that they are essentially cracking your data.

            1 Reply Last reply
            0
            • theodric@social.linux.pizzaT theodric@social.linux.pizza

              Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

              hugh@mastodon.nzH This user is from outside of this forum
              hugh@mastodon.nzH This user is from outside of this forum
              hugh@mastodon.nz
              wrote last edited by
              #20

              @theodric
              Does it suggest "password" or "ABC123"?

              ricci@discuss.systemsR 1 Reply Last reply
              0
              • leorjorge@mastodon.socialL leorjorge@mastodon.social

                @theodric This has to be an LLM response... even leaving alone this horrible security advice, the whole response is trying to do the exact opposite of what the OP asked!

                evehaswords@toot.catE This user is from outside of this forum
                evehaswords@toot.catE This user is from outside of this forum
                evehaswords@toot.cat
                wrote last edited by
                #21

                @LeoRJorge @theodric Offering irrelevant / off topic advice is pretty normal for humans where complicated or obscure questions are in play (source: reading lots of StackOverflow and forum responses written before the advent of stochastic parrots). That said, I do agree this is likely slop since the point about the passwords would have to be hallucinated.

                leorjorge@mastodon.socialL 1 Reply Last reply
                0
                • kr3st3n@infosec.exchangeK kr3st3n@infosec.exchange

                  @theodric @phloggen Fantastic advice. I also noted that files larger than 2GB are exempt from scanning?!?

                  Thanks. I’ll just add 2GB of randomness before my payload, then…

                  Checkmark security (or compliance for some) at its best. 👍

                  h5e@tech.lgbtH This user is from outside of this forum
                  h5e@tech.lgbtH This user is from outside of this forum
                  h5e@tech.lgbt
                  wrote last edited by
                  #22

                  @kr3st3n @theodric @phloggen yeah but it also says “Ensure that the size of the password-protected zip files does not exceed the 2 GB limit to avoid unnecessary consumption of the scanning quota.”??

                  1 Reply Last reply
                  0
                  • evehaswords@toot.catE evehaswords@toot.cat

                    @LeoRJorge @theodric Offering irrelevant / off topic advice is pretty normal for humans where complicated or obscure questions are in play (source: reading lots of StackOverflow and forum responses written before the advent of stochastic parrots). That said, I do agree this is likely slop since the point about the passwords would have to be hallucinated.

                    leorjorge@mastodon.socialL This user is from outside of this forum
                    leorjorge@mastodon.socialL This user is from outside of this forum
                    leorjorge@mastodon.social
                    wrote last edited by
                    #23

                    @EveHasWords @theodric Yeah, maybe I was giving too much merit to the Microsoft employee who posted the reply...

                    1 Reply Last reply
                    0
                    • kr3st3n@infosec.exchangeK kr3st3n@infosec.exchange

                      @theodric @phloggen Fantastic advice. I also noted that files larger than 2GB are exempt from scanning?!?

                      Thanks. I’ll just add 2GB of randomness before my payload, then…

                      Checkmark security (or compliance for some) at its best. 👍

                      ? Offline
                      ? Offline
                      Guest
                      wrote last edited by
                      #24

                      @kr3st3n@infosec.exchange @theodric@social.linux.pizza @phloggen@expressional.social this is an actual technique that works against many commercial AV and EDR solutions

                      ? 1 Reply Last reply
                      0
                      • ? Guest

                        @kr3st3n@infosec.exchange @theodric@social.linux.pizza @phloggen@expressional.social this is an actual technique that works against many commercial AV and EDR solutions

                        ? Offline
                        ? Offline
                        Guest
                        wrote last edited by
                        #25

                        @kr3st3n@infosec.exchange @theodric@social.linux.pizza @phloggen@expressional.social a related one is to generate a bunch of very large benign archives to flood the scan queue before it picks up your payload, giving it time to execute before the system flags it.

                        1 Reply Last reply
                        0
                        • theodric@social.linux.pizzaT theodric@social.linux.pizza

                          Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

                          rmikke@en.osm.townR This user is from outside of this forum
                          rmikke@en.osm.townR This user is from outside of this forum
                          rmikke@en.osm.town
                          wrote last edited by
                          #26

                          @theodric

                          Link Preview Image
                          1 Reply Last reply
                          0
                          • hugh@mastodon.nzH hugh@mastodon.nz

                            @theodric
                            Does it suggest "password" or "ABC123"?

                            ricci@discuss.systemsR This user is from outside of this forum
                            ricci@discuss.systemsR This user is from outside of this forum
                            ricci@discuss.systems
                            wrote last edited by
                            #27

                            @hugh @theodric It's worse, if you were to follow the advice above it in the article, you would either include the password in the text of the email or use the filename as the password

                            1 Reply Last reply
                            0
                            • theodric@social.linux.pizzaT theodric@social.linux.pizza

                              Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

                              icewolf@masto.brightfur.netI This user is from outside of this forum
                              icewolf@masto.brightfur.netI This user is from outside of this forum
                              icewolf@masto.brightfur.net
                              wrote last edited by
                              #28

                              @theodric what the..what??

                              thetenuousorder@meow.socialT 1 Reply Last reply
                              0
                              • icewolf@masto.brightfur.netI icewolf@masto.brightfur.net

                                @theodric what the..what??

                                thetenuousorder@meow.socialT This user is from outside of this forum
                                thetenuousorder@meow.socialT This user is from outside of this forum
                                thetenuousorder@meow.social
                                wrote last edited by
                                #29

                                @IceWolf @theodric make sure to be as unsafe as possible so windows doesn't need to put in any work on... services that worked just fine before?

                                1 Reply Last reply
                                0
                                • theodric@social.linux.pizzaT theodric@social.linux.pizza

                                  Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

                                  mahryekuh@hachyderm.ioM This user is from outside of this forum
                                  mahryekuh@hachyderm.ioM This user is from outside of this forum
                                  mahryekuh@hachyderm.io
                                  wrote last edited by
                                  #30

                                  @theodric In an unrelated statement, a Microsoft employee also recommended the use of generic locks that are easy to pick, lest you’ll never be locked out of your house again.

                                  1 Reply Last reply
                                  0
                                  • theodric@social.linux.pizzaT theodric@social.linux.pizza

                                    Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

                                    sauc3@hachyderm.ioS This user is from outside of this forum
                                    sauc3@hachyderm.ioS This user is from outside of this forum
                                    sauc3@hachyderm.io
                                    wrote last edited by
                                    #31

                                    @theodric

                                    Classic Microslop

                                    1 Reply Last reply
                                    0
                                    • theodric@social.linux.pizzaT theodric@social.linux.pizza

                                      Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

                                      epic_null@infosec.exchangeE This user is from outside of this forum
                                      epic_null@infosec.exchangeE This user is from outside of this forum
                                      epic_null@infosec.exchange
                                      wrote last edited by
                                      #32

                                      @theodric I am concerned that Defender is trying to decrypt files at all...

                                      1 Reply Last reply
                                      0
                                      • theodric@social.linux.pizzaT theodric@social.linux.pizza

                                        Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

                                        swelljoe@mas.toS This user is from outside of this forum
                                        swelljoe@mas.toS This user is from outside of this forum
                                        swelljoe@mas.to
                                        wrote last edited by
                                        #33

                                        @theodric relatedly, if everybody uses the same password the odds of someone guessing a password goes way down, right? Like, if there are 50 people in an organization and they each have their own password, an attacker is 50 times more likely to guess a password. That's just basic math.

                                        womble@infosec.exchangeW 1 Reply Last reply
                                        0
                                        • theodric@social.linux.pizzaT theodric@social.linux.pizza

                                          Look at this fantastic piece of advice from Microsoft! https://learn.microsoft.com/en-au/answers/questions/2007466/are-costs-incurred-when-attempting-to-scan-passwor

                                          aura@gts.foxsnuggl.esA This user is from outside of this forum
                                          aura@gts.foxsnuggl.esA This user is from outside of this forum
                                          aura@gts.foxsnuggl.es
                                          wrote last edited by
                                          #34

                                          @theodric ah, passwords as social convention

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups