Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is the issue with data being tied and connected....

Not long ago, someone here raised similar concerns with Microsoft 's ecosystem

It stemmed from their current underway process to force all Minecraft accounts to Microsoft accounts, and the current Microsoft account process, if you don't add a phone number during account creation, locks and bans the account automatically after a week with they only recovery option being to then give a phone number, and most voip ones are auto detected and not accepted.

If you set up the account with an alternate email, that has no effect. Setting up TOTP has had scattered reports over sometimes allowing the account to not auto ban you, but recent reports are that this too often won't stop it. There are reports that using Microsoft s own authenticator app, does stop the account from auto banning you unironically, that I have not confirmed

Of course this means they can then tie it to potentially your computer pending how you set up Windows, or Xbox live, etc. Which is a risk if you've been formerly banned from something like xbox- everything is now linked, and therefore subject to action automatically with no human team to talk to about the process.

Also, if you then go and give it to them then afterwards try to remove it, the system will not let you without extreme effort, and more details.

I worry greatly about this situation where our personal accounts are all tied together through hardware ids, mandatory phone numbers,IP addresses, and different accounts across systems, only to all get banned or locked out at once with no recourse - or demanding more data(like Minecraft indirectly giving Microsoft every single phone number for the biggest player base in the world, as mandatory(with specific exceptions for like one or two countries who's laws they are working around now, with Korea appears to be one)

Also, so many companies use Amazon, Google, Microsoft company emails and systems- your full name is there, so there is a increasing risk that if something happens to your company account, the systems knows your personal accounts and by name, bans or affects them too.

Privacy advocates are being proven right about the need to be able to not give info that ties everything together



This. I genuinely wonder if people understand how much data is flowing about them on a daily basis and whether they would care if they did. I am just a guy at a place and I personally think I have way more insight in people's private lives than I should.

I can't imagine how bad it is at a less regulated institution.


Do you have the source information on the minecraft accounts? I'm about to fall on this grenade myself. Needless to say I've avoided an MS account like the plague but of course that didn't do much good in the end.

Can you play at all once banned?


I have done some poking around and digging into the microsoft account lock out thing, out of curiousity- only to find it appears to be true, as i've had a LOT of test accounts banned in the past 2 months. I was trying things like setting up alternate emails, and TOTP...

I suspect burner phones are the only way to not give one's phone number, or to gamble with the microsoft authentication app, which theoretically ever since recent versions of android should not be able to pull your phone number from the hardware - theoretically. I have not tested that out yet.

There's quite a bit about this out there Here's one such thread where a lot are trying to figure out why they are being forced to give up their number https://github.com/MultiMC/Launcher/issues/4093

to my understanding, since they fully linked it- once your MS account auto locks- you can't do anything, since it's linked to Minecraft- as well as other stuff. You'd think they'd allow one to still play Minecraft- but i guess if you can't log into the account, you're out of luck




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: