Live data from Hacker News

How Skype fixes security vulnerabilities

hub.zhovner.com

71–80 of 119 posts

Re: How Skype fixes security vulnerabilities

#71
post #57

Last week Skype dropped 2/3 of my contacts list. I contacted their chat support to tell them about it. The person on the other end was insisting that I might be using another Skype account where my other contacts are. Which of course I ain't since I'm not that stupid. He then suggested the stupid bullshit Tier 1 support usually does, like reinstalling Skype. I did as asked. Then he asked me for remote control of my P…

For all who read this and wonder about their own backup before something strange happens, backing up the contacts from the Skype is easy: Contacts / Advanced / Backup Contacts to File Consider doing this if you also find that "losing contacts is unacceptable." There's, of course, also "Restore Contacts from File."

I don't have that option. Is this a Windows-specific or a "Skype for Business" thing?

Re: How Skype fixes security vulnerabilities

#72
post #30

Earlier quoted context omitted.

This. People talk about various alternatives, but I haven't seen one. The requirements are pretty simple 1) Chat and group chat (persistent) 2) Simple file transfer and image posting in chat 3) Good quality voice calls, video calls and group voice calls 4) Apps for android/iOS with shared contact lists 5) Single application for all of the above (to enable a single group set, switching between group chat and group cal…

Discord does most of this. I've entirely moved to using it for voice comms with people where I'm suggesting the platform. It's guest support is pretty robust, so just fire someone a link and they can dial in from their browser if they don't have the app. Call quality is better than Skype, there's separate persistent chat rooms too. I like it a lot.

Their tagline is "Free Voice and Text Chat for Gamers".

Re: How Skype fixes security vulnerabilities

#73
post #15

Earlier quoted context omitted.

There have been a lot of instances of this happening to feminist or LGBT groups on Facebook and YouTube. These systems are fantastically abusable.

If I were setting up an automated abuse-report-receiving system that could automatically disable accounts, I would run some sort of filter for "is the account reporting the abuse itself a newly created account, and/or one with suspiciously low and non-human looking usage patterns?". But on the other side, malicious actors can solve that problem by having clickfarm workers in bangladesh create 30 fake facebook account…

The cases I've heard of have generally been crowd-sourced, not automated.

Re: How Skype fixes security vulnerabilities

#74

I've been looking for a Skype alternative since the security of Skype was weakened after it was acquired by Microsoft. I've had my account stolen multiple times because their support has changed the primary e-mail address of my account, I had to use the same method the social engineers used to get my account back. Since then I've avoided sharing anything slightly sensitive over Skype, as chat history is synced with a…

I've looked at alternatives too, tried Jitsi.org and Ring.cx so far, with Jitsi seeming to be more robust when establishing connections through NAT. Thanks for the suggestion about Wire, will have to try that too.

Re: How Skype fixes security vulnerabilities

#75
post #30

Earlier quoted context omitted.

Discord does most of this. I've entirely moved to using it for voice comms with people where I'm suggesting the platform. It's guest support is pretty robust, so just fire someone a link and they can dial in from their browser if they don't have the app. Call quality is better than Skype, there's separate persistent chat rooms too. I like it a lot.

Their tagline is "Free Voice and Text Chat for Gamers".

Yeah, they're definitely targeting that market initially - but I'm seeing communities outside that sphere start using it: https://facebook.github.io/react/blog/2015/10/19/reactiflux-...

It's not perfect, but if you're looking for voice, group voice, and group text chat, it's a great solution. Very, very simple setup, little overhead.

It is missing Video and Screen sharing, though.

Re: How Skype fixes security vulnerabilities

#76

Last week Skype dropped 2/3 of my contacts list. I contacted their chat support to tell them about it. The person on the other end was insisting that I might be using another Skype account where my other contacts are. Which of course I ain't since I'm not that stupid. He then suggested the stupid bullshit Tier 1 support usually does, like reinstalling Skype. I did as asked. Then he asked me for remote control of my P…

Re business usage: I've found https://zoom.us/ to be a good alternative to Skype for conference calls and screen sharing - it's freemium, free for calls up to 40 minutes (after which you just re-call everyone). Quality of the call and software seems to be a lot better, maybe that's just because corporate firewalls don't try and do weird stuff to it though :D

Re: How Skype fixes security vulnerabilities

#77
post #63

I've been looking for a Skype alternative since the security of Skype was weakened after it was acquired by Microsoft. I've had my account stolen multiple times because their support has changed the primary e-mail address of my account, I had to use the same method the social engineers used to get my account back. Since then I've avoided sharing anything slightly sensitive over Skype, as chat history is synced with a…

Why don't you try Jitsi? https://jitsi.org/

I just had a look at Jitsi and it seems like the Android app is in alpha stage, and that there won't be any iOS app (https://jitsi.org/Documentation/FAQ#ios). Smartphone apps are important to convince my contacts to make the switch, and to be able to communicate with them over the same channel when they're away from the computer.

Re: How Skype fixes security vulnerabilities

#78

I don't think I can fault Skype for this "vulnerability" - the problem itself isn't really in code, but in people. Yes, within the article there's mention of a past attack which relied on socially engineering a support specialist to send verification codes and guess the result, but that seems to have stopped. I'd actually love to know the key generation algorithm or the probabilities that go into guessing one of four…

If support team is vulnerable to abuse, so deal with it. For example, stop blocking accounts due to abuse reports. Just block account ability to contact with reporter. Make some automatic abuse detection system to deal with most popular cases. Invent some type of carma for users, keep it hidden, but let this carma influence on decision making of support team or abuse detection system.

A little courage to face problem and some creativity to brain storm a solution... But Skype team seems lacking will to solve any problems.

Re: How Skype fixes security vulnerabilities

#79
I recently had an interview on Skype.

I added the interviewer in my contact list, but we were never able to start a video conference. We did it by phone instead. I did not have the job. Thanks Skype. Not to mention the interviewer had Skype Pro.

Not to mention the intrusive ads.

Re: How Skype fixes security vulnerabilities

#80
post #57

Earlier quoted context omitted.

For all who read this and wonder about their own backup before something strange happens, backing up the contacts from the Skype is easy: Contacts / Advanced / Backup Contacts to File Consider doing this if you also find that "losing contacts is unacceptable." There's, of course, also "Restore Contacts from File."

I don't have that option. Is this a Windows-specific or a "Skype for Business" thing?

I don't know how specific it is but I know it works in the Windows version of the program. In your case, I guess it's too late to do the backup for your current problem, if you miss the contacts obviously they were deleted before you knew that you can backup them. But it can help you saving the remaining ones.
Post reply on HN