Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

41–50 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#41
post #27

Earlier quoted context omitted.

Not really, no. Just stop the reset token from appearing in the client. Just send it by email like you're supposed to and that's it, vulnerability gone.

Yeah, but pushing a client fix takes time. They'll need an excuse in the meantime.

It's not a client-side fix. Just stop the server from sending the token/link to the clients. Sure, that might degrade the client experience a bit(assuming that the client isn't just displaying a webview in which case no degradation would occur) but it would fix the problem for now.

Later on you can take your time rolling out a client fix if it's required, but a hotfix server-side is entirely possible, there's no excuse keeping this vulnerability possible when it's been made this public(step by step instructions to hack someone's account, with screenshots!) especially since you were contacted privately about it ~3 months ago.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#42
post #27

Earlier quoted context omitted.

Not really, no. Just stop the reset token from appearing in the client. Just send it by email like you're supposed to and that's it, vulnerability gone.

Yeah, but pushing a client fix takes time. They'll need an excuse in the meantime.

You don't push the fix to the client. They have some notification system ou there that is sending the messages to the client. They just need to stop it from sending these kind of messages. Obviously I can't say how much work is involved in that - but they don't need to push an updated client.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#43
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

As usual, making this public and widely broadcasted will probably encourage them to finally listen to you :)

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#44

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

This appears to be a bug. After adding the email address and clicking save, logging out, and logging in, I found the email address was successfully added. At this point I could change it to the primary one, click save, paste my password, and click the button on the password prompt to successfully change my primary email address. If I tried to add the email and make it primary in one session, it would not work. If I e…

Doesn't work for me - I can add a new email address, but when I sign out and back in it's vanished. Feels like they might have disabled parts of the account management system.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#45
post #33
post #16

Earlier quoted context omitted.

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I use unique and secure passwords for all online services, https://agilebits.com/onepassword makes it really simple.

[deleted]

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#46
post #16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I don't really see the need for passwords anymore. Mozilla's Personas looks good for the web.

With the rise of mobile apps though, we introduce more usernames and password daily.

Believe there is an easier way to handle user authorisation and here is a post about it. https://gist.github.com/4052818

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#48
post #5
post #3

Earlier quoted context omitted.

Even now Skype reaction is unbelievable. They are "investigating the issue" for almost 2 hours.

Stop saying "Skype", use "Microsoft" instead, and it's not unbelievable at all.

Except that Microsoft has a pretty stellar reputation when it comes to security procedures. They're well known as being among the best in the industry.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#49
post #5

Earlier quoted context omitted.

Stop saying "Skype", use "Microsoft" instead, and it's not unbelievable at all.

Except that Microsoft has a pretty stellar reputation when it comes to security procedures. They're well known as being among the best in the industry.

Well, they've certainly cleaned up their act, but I definitely wouldn't say that they're known to be among the best in the industry.. I remember just a few year ago, you could get to ring0 in Windows and install a rootkit just via the registry.. Let's not forget all the hotmail vulnerabilities similar to this that have been active for an indeterminate amount of time..

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#50
post #16

Earlier quoted context omitted.

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I think it's possible to flip the order. Instead of managing 100 passwords for each account, manage 100 emails and ONE password for all accounts. Make sure your password is really strong, and you should be better-off than managing those 100 passwords, which require a secure password manager. Of course it's better to have a real password manager, but for most people, who don't or can't be bothered setting this up, thi…

And then one of the accounts' password is stored in plaintext and the database is leaked with the mail addresses and everyone can easily log in as you at 100 services.

Never, ever, re-used passwords for anything you value.

Post reply on HN