Live data from Hacker News

How Skype fixes security vulnerabilities

hub.zhovner.com

41–50 of 119 posts

Re: How Skype fixes security vulnerabilities

#41
post #4

Earlier quoted context omitted.

A lot of people use Discord now. I mean, you can use it inside of a browser, what can be easier than that?

Seems to be designed for games only, or did I end up in a targeted landing page?

Games are the target niche - but really - anyone can use it. At the end of the day - it's just a chat product - that has some gamer centric features.

Re: How Skype fixes security vulnerabilities

#43
post #15

Earlier quoted context omitted.

There have been a lot of instances of this happening to feminist or LGBT groups on Facebook and YouTube. These systems are fantastically abusable.

If I were setting up an automated abuse-report-receiving system that could automatically disable accounts, I would run some sort of filter for "is the account reporting the abuse itself a newly created account, and/or one with suspiciously low and non-human looking usage patterns?". But on the other side, malicious actors can solve that problem by having clickfarm workers in bangladesh create 30 fake facebook account…

> If I were setting up an automated abuse-report-receiving system that could automatically disable accounts, I would run some sort of filter for "is the account reporting the abuse itself a newly created account, and/or one with suspiciously low and non-human looking usage patterns?".

That does not help against these kiddy vandals mentioned in the article.

Re: How Skype fixes security vulnerabilities

#44

Earlier quoted context omitted.

If I were setting up an automated abuse-report-receiving system that could automatically disable accounts, I would run some sort of filter for "is the account reporting the abuse itself a newly created account, and/or one with suspiciously low and non-human looking usage patterns?". But on the other side, malicious actors can solve that problem by having clickfarm workers in bangladesh create 30 fake facebook account…

> If I were setting up an automated abuse-report-receiving system that could automatically disable accounts, I would run some sort of filter for "is the account reporting the abuse itself a newly created account, and/or one with suspiciously low and non-human looking usage patterns?". That does not help against these kiddy vandals mentioned in the article.

yes, exactly why it's a hard problem to solve.

Re: How Skype fixes security vulnerabilities

#45
I feel like this could be fixed very quickly if someone wanted to invest the time and was a bit on the chaotic side. 1) find Skype IDs of Microsoft managers, known people, big businesses with ties to MS 2) create 20+ fake accounts 3) start reporting abuse...

It's the same issue as in any big system - people on high enough positions are isolated from all the crap normal users have to deal with. If you can interrupt their business call though... I expect the fix will be coming soon.

Re: How Skype fixes security vulnerabilities

#46
post #34

Earlier quoted context omitted.

This. People talk about various alternatives, but I haven't seen one. The requirements are pretty simple 1) Chat and group chat (persistent) 2) Simple file transfer and image posting in chat 3) Good quality voice calls, video calls and group voice calls 4) Apps for android/iOS with shared contact lists 5) Single application for all of the above (to enable a single group set, switching between group chat and group cal…

Google hangouts?

Hangouts is not a bad idea actually. I think the chrome plugin actually makes it look like a decent desktop app too (?)

I very much prefer not to have to use a browser window for chat/voice/video.

Re: How Skype fixes security vulnerabilities

#47

I feel like this could be fixed very quickly if someone wanted to invest the time and was a bit on the chaotic side. 1) find Skype IDs of Microsoft managers, known people, big businesses with ties to MS 2) create 20+ fake accounts 3) start reporting abuse... It's the same issue as in any big system - people on high enough positions are isolated from all the crap normal users have to deal with. If you can interrupt th…

This is very true. OP can contact me for some MS employee Skype usernames. :)

Re: How Skype fixes security vulnerabilities

#48
I've been looking for a Skype alternative since the security of Skype was weakened after it was acquired by Microsoft. I've had my account stolen multiple times because their support has changed the primary e-mail address of my account, I had to use the same method the social engineers used to get my account back. Since then I've avoided sharing anything slightly sensitive over Skype, as chat history is synced with anyone who accesses your account.

Finding a replacement isn't easy, but I've used Wire (wire.com) for a year now and find it good enough feature-wise, and excellent security-wise. It has its quirks and can be a resource hog at times (the desktop app uses Electron IIRC), but it's worth switching from the security disaster that is Skype.

Re: How Skype fixes security vulnerabilities

#50
post #4

Earlier quoted context omitted.

A lot of people use Discord now. I mean, you can use it inside of a browser, what can be easier than that?

Seems to be designed for games only, or did I end up in a targeted landing page?

It's for gamers, but it's just chat and voice. I think it's smart of them to capture a niche because they have integration with streaming to Twitch. For example, it hides the names of contacts/server invites when you're streaming video online.
Post reply on HN