Kloppt Strato eigentlich die Auth Codes für Domainumzüge in Steintafeln und lässt die per Eselkarre zum Inhaber liefern oder was dauert da so lange... Strato ist echt der letzte Laden. 3 Stunden und immer noch kein Auth Code für eine .com Domain. #strato #authcode
@bugbear Couldn't you request the #Authcode and move the #domain to cheaper one ?

( #Mastodon #instance are locked to the #domain they were made on sadly...)

I agree on the "just because I had it in the past" #sentiment .
#SocialMedia is a sideproject at best
 
•acws #acws

@GossiTheDog the sheer fact that #MSPs & #CSPs can access clients' setups without proper #authorization [including #KYC / #KYB, #AuthCode|s and proper authorization via contract] is already sickening.

Such fundamental #ITsec fuckups are reasons alone not to use #Azure or any #Microsoft products & services at all...

  • I mean, it doesn't require #Mitnick-level skills to pull this off, since it doesn't necessitate #Lapsus-Style #SIMswap or other means to gain access...
Kevin Beaumont (@[email protected])

Attached: 3 images This is the partner.microsoft.com portal, it allows CSPs - Cloud Solution Providers - to gain access to their customer's environments. CVE-2024-49035 was around improper privilege management, i.e. being able to access things you shouldn't. It being in CISA KEV says it was being exploited in the wild. That portal allows a huge footprint of access by design.

Cyberplace