What happens if your Windows Account gets hacked?

Dukenukem117

Member
Aug 25, 2016
34
0
11
Here's something I never considered until this week when I started reviewing my cybersecurity situation. All my devices are upgraded to Windows 10, and I use my MS login for convenience/store. If someone were to steal my laptop or somehow crack my Windows 10 login, what could they do? Let's assume they don't immediately do anything that reveals the breach.

At the very least, I think that means they can decrypt any encrypted data?

Could they control other computers via remote? Lock me out? Thoughts?

When they say it lets you sync passwords, what are they syncing?
 

mikeymikec

Lifer
May 19, 2011
20,378
15,066
136
If they change your MS account password, they stop you logging into your own computer / windows account.

When you say 'decrypt encrypted data' what do you mean exactly? One thing I have seen is that bitlocker'd devices (such as a Surface 3 I encountered) has the encryption keys stored in the MS account. To access them it wanted to do 2FA.

I would only use an MS account to log in to Windows if I had multiple MS devices and desperately wanted sync'ing between them. Even then there's plenty one can do without logging into Windows with an MS account, for example OneDrive can be configured to access an MS account even though the user is logging in to Windows with a standard local account.
 

Dukenukem117

Member
Aug 25, 2016
34
0
11
I suppose if you didn't set up 2FA with your MS account, they could just go to the town. But MS only uses SMS 2FA, which is the least secure form.

I also wonder if the Xbox is now a point of attack since it uses the same MS account.