Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

51–60 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#51
post #16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

http://www.keepassx.org/ is a free and open-source password manager. It makes using almost infinite numbers of accounts easy to use. If you use secure passwords they are like not possible to remember anyways.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#53
post #18

After successfully exploited this on my own account, tried again with my SO's account and https://login.skype.com/account/password-reset-request has been blocked. Pretty good emergency reaction. It should be noted that after my account password is changed, I tried to login with the old password, the Windows Skype app told me the username and password combination is wrong but it still let me logged in. This may be a d…

Apparently, https://login.skype.com/account/password-automation still works.

It only works if the account had a credit card on file and/or made purchases in the past. Unless you know the credit card number or the purchase ticket number, this link isn't much help.

Can't believe Skype has been ignoring this issue up until in got to the top of Hacker News and HabraHabr.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#54
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

The same is, or was at least, true of xbox live - someone registered using my email, and there's obviously no account confirmation, as the account is live and I receive email notifications etc, but I can't get into it or remove it, since I don't know the password. I wonder how many other sites do this to avoid friction on sign up?

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#56

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

On top of that a lot of people have their Skype accounts integrated with facebook having their one and only email accounts published over there.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#58
post #27

Earlier quoted context omitted.

Yeah, but pushing a client fix takes time. They'll need an excuse in the meantime.

It's not a client-side fix. Just stop the server from sending the token/link to the clients. Sure, that might degrade the client experience a bit(assuming that the client isn't just displaying a webview in which case no degradation would occur) but it would fix the problem for now. Later on you can take your time rolling out a client fix if it's required, but a hotfix server-side is entirely possible, there's no excu…

Right. There's one developer at Skype who can just do that and push it to production, without talking to anyone else, or getting approval from anyone else.

Be realistic. If two people need to talk about it, it's going to take longer than 2 minutes.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#59

Earlier quoted context omitted.

It's not a client-side fix. Just stop the server from sending the token/link to the clients. Sure, that might degrade the client experience a bit(assuming that the client isn't just displaying a webview in which case no degradation would occur) but it would fix the problem for now. Later on you can take your time rolling out a client fix if it's required, but a hotfix server-side is entirely possible, there's no excu…

Right. There's one developer at Skype who can just do that and push it to production, without talking to anyone else, or getting approval from anyone else. Be realistic. If two people need to talk about it, it's going to take longer than 2 minutes.

Longer than two minutes, definitely! More than 2 hours to investigate and fix? very doubtful. 3 months? That's a bit much...

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#60
post #23

Earlier quoted context omitted.

And for sites that don't have insufficiently permissive email regex validators, if you have gmail you can just add a '+' and do youremail+skype@gmail.com, youremail+facebook@gmail.com, etc.

Yeah, you could do that as well. I just don't like the idea that someone holds my email address. After reading few stories where Google/Microsoft blocks access to email, I decided to move my email to custom domain. In case of any issues all I have to do is change MX names to new provider to start receiving my mails again.

You can do the +modifier trick with GApps as well.
Post reply on HN