Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Windows Live

July 15th, 2011, 13:31 GMT · By

New Windows Live Hotmail Features Tackle Account Hijacking Problem

SHARE:

Adjust text size:


Windows Live Hotmail
Enlarge picture
Two new security features rolling out to Windows Live Hotmail are designed to make it harder for attackers to compromise accounts and to better identify already hijacked identities.

Hotmail users will be able to report suspicious behavior coming from an email address belonging to one of their friends, in case of a hijacked account.

In addition, customers leveraging Hotmail will be required to set strong passwords for their accounts, making it harder for cybercriminals to break in through brute force “dictionary” attacks.

Spam can be considered somewhat of a trademark symptom of hacked email accounts, and the new “My friend’s been hacked!” option under the “Mark as” menu is designed to let users report potential hijacks.

“Our compromise detection system is always working in the background to detect unusual behavior. When we detect bad behavior from an account (like an account that suddenly starts sending spam), we mark that account as compromised,” revealed Dick Craddock, Group Program Manager, Hotmail.

“When you report that your friend’s account has been compromised, Hotmail takes that report and combines it with the other information from the compromise detection engine to determine if the account in question has in fact been hijacked. It turns out that the report that comes from you can be one of the strongest “signals” to the detection engine, since you may be the first to notice the compromise.”

Windows Live Hotmail accounts that have been reported as hijacked are essentially blocked so that attackers can no longer leverage them to send more spam.

The real owner of a hijacked account that has been blocked will be able to recover the email address and get control back, Microsoft said.

The feature works not only with Hotmail accounts, but also with services from additional providers such as Google and Yahoo, Craddock said.

“We’ve had this feature turned on for only a few weeks, and we’ve already identified thousands of customers who have had their accounts hacked and helped those customers reclaim their accounts. And we’ve found it to be very effective and fast. Accounts that you report as compromised are typically returned to the rightful owner within a day,” he explained.

But at the same time, Microsoft has worked to kill perhaps the main source of hijacked accounts, weak and common passwords.

The software giant will actually force users to set up strong passwords by blocking common phrases and words from being used in the first place.

Windows Live Hotmail users won’t be able to have ‘12345’ or ‘ilovecats’ as their account password, or to swap an existing password for one of the two examples above, or others like them.

“This new feature will be rolling out soon, and will prevent you from choosing a very common password when you sign up for an account or when you change your password. If you're already using a common password, you may, at some point in the future, be asked to change it to a stronger password,” Craddock added.

TELL US WHAT YOU THINK:

2,128 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Over 2 Million Windows Live Hotmail Users Leveraging HTTPS Encrypted (SSL) Email Option

Download New Outlook Hotmail Connector Upgraded with HTTPS / SSL Support

Windows Live Hotmail / ID Sign-in Experience Upgraded

Download Windows Live Mail 2011 15.4.3538.0513 with SSL Support

Windows Live Hotmail Turns 15

READER COMMENTS:


Comment #1 by: Zwanzer on 15 Jul 2011, 13:55 UTC reply to this comment

They have made logging in on Live Accounts considerably less userfriendly in the beginning of July 2011. People will therefore choose for shorter and less complicated passwords instead of what MS is asking in this article.


Comment #2 by: pale face on 08 Oct 2011, 15:22 UTC reply to this comment

that's what had happend with my account,I quess it has been blocked,Now how can I get into it again?Window live ask me to sign in and I forgot my password!!!I'm getting frustrated more and more,ask microsoft to reset my password and it is 7 days after and I still have no help from them.Friend of mine told me she was getting fishy looking e-mail from me what I,m 0 sure I didn't send.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM