Sadly, Skype is still used a lot. More than half of the emails I receive with a next step of communication proposal come suggesting Skype. The only way to beat it would be to have another communication solution which can be used as simple as Skype is (for any age, technical literacy, etc.).
How Skype fixes security vulnerabilities
61–70 of 119 posts
Re: How Skype fixes security vulnerabilities
#62Earlier quoted context omitted.
> If I were setting up an automated abuse-report-receiving system that could automatically disable accounts, I would run some sort of filter for "is the account reporting the abuse itself a newly created account, and/or one with suspiciously low and non-human looking usage patterns?". That does not help against these kiddy vandals mentioned in the article.
yes, exactly why it's a hard problem to solve.
Oh, and check if they actually speak English well enough to communicate with customers. As a customer, I instantly notice outsourced callcenters.
Re: How Skype fixes security vulnerabilities
#63I've been looking for a Skype alternative since the security of Skype was weakened after it was acquired by Microsoft. I've had my account stolen multiple times because their support has changed the primary e-mail address of my account, I had to use the same method the social engineers used to get my account back. Since then I've avoided sharing anything slightly sensitive over Skype, as chat history is synced with a…
Re: How Skype fixes security vulnerabilities
#64Skype makes me sad. I used it 10 years ago, and it was great - or at least pretty good, compared to the other options. Video calls, screen sharing, chat. But it had a number of problems. Mostly surrounding using it on multiple devices, making it very hard to keep track of what has and has not been read. Log onto Skype on a device I have not used in a couple of days, and "unread" messages show up - messages I have alr…
This seems to have finally been addressed, at least on my OSX/iOS combo.
Re: How Skype fixes security vulnerabilities
#65Sadly, Skype is still used a lot. More than half of the emails I receive with a next step of communication proposal come suggesting Skype. The only way to beat it would be to have another communication solution which can be used as simple as Skype is (for any age, technical literacy, etc.).
This. People talk about various alternatives, but I haven't seen one. The requirements are pretty simple 1) Chat and group chat (persistent) 2) Simple file transfer and image posting in chat 3) Good quality voice calls, video calls and group voice calls 4) Apps for android/iOS with shared contact lists 5) Single application for all of the above (to enable a single group set, switching between group chat and group cal…
Re: How Skype fixes security vulnerabilities
#66I've been looking for a Skype alternative since the security of Skype was weakened after it was acquired by Microsoft. I've had my account stolen multiple times because their support has changed the primary e-mail address of my account, I had to use the same method the social engineers used to get my account back. Since then I've avoided sharing anything slightly sensitive over Skype, as chat history is synced with a…
That makes me wonder about their long term intentions (and if I'll lose credibility with my contacts that finally migrate to Wire just before wire vanishes or gets bought out by Facebook or Microsoft...)
Re: How Skype fixes security vulnerabilities
#67Earlier quoted context omitted.
One can require the account before many years old before having much weighting. Also, require verified phone number by sms or a verified non prepaid credit card. Allow the user to use your site without that stuff, but restrict actions that spammers like to requiring it.
Requiring phone number or credit card is an extremely effective way to have a large class of (legitimate) users nope out of your service
Re: How Skype fixes security vulnerabilities
#68Earlier quoted context omitted.
I switched to Wire a year ago and haven't looked back. It meets all your requirements, and has end-to-end encryption (based on Signal Protocol) too.
I tried to use Wire with Zhovner (the author of this article) and it consumed 2 full CPU power for a simple voice call. My laptop heated up to 83°C, Zhovner's laptop was also hot. That's pretty strange since Wire has only interface written in javascript, all the core things are in Rust.
Re: How Skype fixes security vulnerabilities
#69Earlier quoted context omitted.
One can require the account before many years old before having much weighting. Also, require verified phone number by sms or a verified non prepaid credit card. Allow the user to use your site without that stuff, but restrict actions that spammers like to requiring it.
Requiring phone number or credit card is an extremely effective way to have a large class of (legitimate) users nope out of your service
Re: How Skype fixes security vulnerabilities
#70I don't think I can fault Skype for this "vulnerability" - the problem itself isn't really in code, but in people. Yes, within the article there's mention of a past attack which relied on socially engineering a support specialist to send verification codes and guess the result, but that seems to have stopped. I'd actually love to know the key generation algorithm or the probabilities that go into guessing one of four…
And if a report system is broken enough you can just not have one. Or maybe take away the ability of an account to send friend requests while leaving the rest of it intact. That would take care of spambots without ruining real accounts.