Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

11–20 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#11
post #4

Earlier quoted context omitted.

Damn, it takes 2 minutes to "investigate the issue" if you simply follow the steps.

But probably a little longer to find a fix, test it and release it...

Block password reset. It is as simple as that.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#12
I think it's a good practice to always use unique, unpredictable email addresses when signing for online services.

1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo.

2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak of email addresses on Box... luckily it was only emails that got leaked, at least according to Box support).

3. It's easier to block spam, once a service misbehaves or gives away the email.

I wrote a little more about using it as a "passwordless password manager" at http://blog.gingerlime.com/2011/passwordless-password-manage...

update: (if blog post is too long...) this does not mean setting up hundreds of different email accounts. On most services like hotmail, google and yahoo you can simply append some unique string to your email address, e.g. john+f820938422@gmail.com. Making this unpredictable is important however, so appending +facebook and +twitter is not helping much though...

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#13
post #4

Earlier quoted context omitted.

Damn, it takes 2 minutes to "investigate the issue" if you simply follow the steps.

But probably a little longer to find a fix, test it and release it...

Not really, no. Just stop the reset token from appearing in the client. Just send it by email like you're supposed to and that's it, vulnerability gone.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#14

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Instead of remembering all those weird email names, what you could do is:

1) Buy domain and attach google apps to it.

2) Switch catch-all email setting in preferences.

3) When register for a service use email like skype@domain.com or facebook@domain.com etc.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#15
post #2

OP at http://habrahabr.ru/post/158545/ (russian) says that he reported this vulnerability about 3 month ago. The lack of any reaction is unbelievable. Hint: you can change your email to something like user+skype@gmail.com to avoid registration of new email address.

[deleted]

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult!

I think something is really broken in today's web authentication scheme. I think there is really huge need for some independent and reliable service (Mozilla's Personas maybe).

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#18
After successfully exploited this on my own account, tried again with my SO's account and https://login.skype.com/account/password-reset-request has been blocked. Pretty good emergency reaction.

It should be noted that after my account password is changed, I tried to login with the old password, the Windows Skype app told me the username and password combination is wrong but it still let me logged in. This may be a different bug in caching?

Hope we can get a postmortem report out of this...

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#20
post #16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

[deleted]
Post reply on HN