Having problems with Outlook logins due to the exponential growth of Bot brute force attempts

zenparadox

Ars Tribunus Militum
2,565
Subscriptor++
So in the last few weeks every time I've tried to login to my @live.com main email, i get the blockout saying too many incorrect login attempts. I use very strong passwords, and as at first I could just click "send me a 2FA code to my registered phone number", punch that in and good to go, I wasn't concerned.

As it has gone on for weeks now, suddenly I am getting blocked because I can't use the 2FA code to phone, it just says "this method isn't working".

The link to try and retrieve your account requires you to login ffs.

After some googling I've learned you can set up an alias to use as a login, and then disable using the actual email address for login attempts, which thwarts the bots.
However I still need to get back into the account somehow to do that.

I se cookie blockers and never leave any device logged in to the accountwhich was good practice, but has made me vulnerable to the clowns that gave us AI's shit-bots of the hackpocalypse nightmare.

Does anyone have any knowledge on how to get back in reliably? I have all of my important things tied to that account, so would like to try and get in once and enable the alias thing and then I should be good. I had to download the MS authenticator app for my work account, but didn't want to tie it to my epersonal one at the time, not knowing what shenanigans were coming.

Is there anyway to add my personal account to it while I can't actually log in?

Key info that may affect any answers;
I don't have any outlook apps installed on my phone or PC, I just use the web browser version.
My PC has always been set to delet all cookies etc on closing the browser.
I have one of the security keys that Ars used to give out with memberships, but never used it as I read that it's best to have two, in case you lose the one....(might be another option, still have to somehow get back int my email to enable it)

Any help greatly appreciated, AI sure has a lot of downsides right now. :|
 

zenparadox

Ars Tribunus Militum
2,565
Subscriptor++
OK so after some more searching I found suggestions to try using work accounts to login, as if you're getting the complete block of log in options as I was, one of the only options left was log in with another account. It twigged at work today that my work email is MS based. Was going to try that and then just went why don't I try logging in at work and see, was able to login no problem at all at work.*
Kept the account logged in and as I'd had to download the MS authenticator app for the work laptop/account a while back**, I was then able to add the personal account to the authenticator app, so should be good moving forward, appreciate your helping regardless that I found an alternate way @rain shadow .

Couple of interesting points that clarified today though as I fixed it;
*while I do believe that the rise in brute forcing attacks using AI bots is part of the problem, I'm equally suspicious it's just MS being total pieces of shite and trying to annoy people who don't want to allow supercookies/use their data mining apps, into loading their apps. The enshittification of everything MS only accelerates, never decelerates. My phone number has been the 2FA recovery point for the personal email for a long time, and it's never been problematic before to use the phone to confirm, but suddenly it is? Also I wasn't getting any notifications of password change attempts, and many of the people in forums locked out as I was were getting those notifications a lot. Lastly it's been locking me out for about 4 days saying everything I legitimately try on the same devices I've been using for years is suspicious, but when I log in on another different computer that's not suspicious. Seems legit...

**I didn't want to put the personal email on the authenticator app originally because I don't want MS apps on my phone, they can go fuck themselves with the data mining that enables. I force stop the authenticator app after each use. Going to look at getting a second UBI key and migrate the personal account to that, and get rid of the authenticator app off my phone. It's weird I only had to use it the very first time I logged into the work laptop, for my work email. I'd love to migrate off the @live.com email, but that's a ton of work as it's the email account for everything. Also any other provider of a 'free' email account will be just as bad...

If anyone understands much better why suddenly over the course of a few weeks this all went crazy when I'm not doing anything different, and it corrects my mostly guessing understanding as stated so far, very interested to become slightly less ignorant and know he he.
 

Paladin

Ars Legatus Legionis
33,627
Subscriptor
Not 100% sure but if the authenticator app is just a TOTP implementation, you can use a few alternatives.

https://en.androidsis.com/The-best-two-step-authentication-apps-(TOTP)/

I use the google one myself since I have had a google account for decades so, whatever, they already have as much meaningful data as they can extract from me. Redhat has one on that list though. Might be worth a shot. They are a pretty big focus for security researchers so if a TOTP app does something sketchy besides just the basic math function it requires and maybe a backup to the cloud of your choice, it would set off big red flag alarms with a lot of people. That would completely defeat the purpose of the app if it were doing stuff in the background, etc.

I get your attitude about wanting to limit exposure to Microsoft but you already use them for free email so.... that cow is well out of the barn. Yes, limit where you can but you're risking a lot more loss than a bit of loss of privacy, it seems.

If nothing else, just consider Protonmail or something as an alternative. Yes, migrating takes work but if you do it over time it isn't that bad. Keep the old live.com account just in case, and keep it logged in on some browser alternate you never use, if necessary. Make your life easier while also separating your daily usage from them.
 
  • Like
Reactions: zenparadox