Dan Rose: Microsoft Bob's Sign In. Signing In To Microsoft Bob With A Password-"Protected" Account. August 2008, archiviert vom Original am 20. November 2008; abgerufen am 1. August 2008 (englisch): „But instead of requiring you to perform some kind of authentication first -- answer a question ("What is your mother's maiden name?"), etc., you can enter any new password and it will replace the original one! Anyone can do this to any password "protected" Microsoft Bob account. There is absolutely no prior authentication required whatsoever.
This means User1 could change their own password just by mistyping their password three times and entering a different password the fourth time -- and not have to bother with Microsoft Bob's Change password option.
It also means that User1 could change the passwords of User2, User3, User4, etc. in exactly the same way. Consequently, any user could change any other user's password simply by mistyping it three times then entering a new password when prompted -- and then enter their account.“
web.archive.org
Dan Rose: Microsoft Bob's Sign In. Signing In To Microsoft Bob With A Password-"Protected" Account. August 2008, archiviert vom Original am 20. November 2008; abgerufen am 1. August 2008 (englisch): „But instead of requiring you to perform some kind of authentication first -- answer a question ("What is your mother's maiden name?"), etc., you can enter any new password and it will replace the original one! Anyone can do this to any password "protected" Microsoft Bob account. There is absolutely no prior authentication required whatsoever.
This means User1 could change their own password just by mistyping their password three times and entering a different password the fourth time -- and not have to bother with Microsoft Bob's Change password option.
It also means that User1 could change the passwords of User2, User3, User4, etc. in exactly the same way. Consequently, any user could change any other user's password simply by mistyping it three times then entering a new password when prompted -- and then enter their account.“