Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

21–30 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#21
post #16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

While I don't necessarily agree with your parent's post, there's a relatively simple solution here. If you're using gmail, you can use the + operator to automatically tag emails. Here, it serves an alternative purpose.

For example, if my email is daniel@gmail.com, then I would use daniel+hn@gmail.com when signing up for Hacker News.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#22
post #16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I think it's possible to flip the order. Instead of managing 100 passwords for each account, manage 100 emails and ONE password for all accounts. Make sure your password is really strong, and you should be better-off than managing those 100 passwords, which require a secure password manager.

Of course it's better to have a real password manager, but for most people, who don't or can't be bothered setting this up, this would be a huge step forward since they anyway use the same email and the same password everywhere.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#23

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Instead of remembering all those weird email names, what you could do is: 1) Buy domain and attach google apps to it. 2) Switch catch-all email setting in preferences. 3) When register for a service use email like skype@domain.com or facebook@domain.com etc.

And for sites that don't have insufficiently permissive email regex validators, if you have gmail you can just add a '+' and do youremail+skype@gmail.com, youremail+facebook@gmail.com, etc.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#25
post #21
post #16

Earlier quoted context omitted.

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

While I don't necessarily agree with your parent's post, there's a relatively simple solution here. If you're using gmail, you can use the + operator to automatically tag emails. Here, it serves an alternative purpose. For example, if my email is daniel@gmail.com , then I would use daniel+hn@gmail.com when signing up for Hacker News.

Skipping over the fact that most email providers don't necessarily support this, and that not all websites/services will allow it (not saying they are right not to), this creates a whole new set of things to remember as even something as simple as +hn (which is surely simple enough that anyone could guess it) could be tougher on other sites, e.g. is Reddit +rd, +re, or...?

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#26
post #23

Earlier quoted context omitted.

Instead of remembering all those weird email names, what you could do is: 1) Buy domain and attach google apps to it. 2) Switch catch-all email setting in preferences. 3) When register for a service use email like skype@domain.com or facebook@domain.com etc.

And for sites that don't have insufficiently permissive email regex validators, if you have gmail you can just add a '+' and do youremail+skype@gmail.com, youremail+facebook@gmail.com, etc.

Yeah, you could do that as well. I just don't like the idea that someone holds my email address. After reading few stories where Google/Microsoft blocks access to email, I decided to move my email to custom domain. In case of any issues all I have to do is change MX names to new provider to start receiving my mails again.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#27

Earlier quoted context omitted.

But probably a little longer to find a fix, test it and release it...

Not really, no. Just stop the reset token from appearing in the client. Just send it by email like you're supposed to and that's it, vulnerability gone.

Yeah, but pushing a client fix takes time. They'll need an excuse in the meantime.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#28
It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf.

I see no recourse other than closing my account, if that's still possible. [edit] No, not even that is possible.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#30

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

I'm having the exactly same problem, and I can't believe they're doing it. They won't even let us protect ourselves. Could they botch worse than that?
Post reply on HN