Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

61–70 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#62
post #16

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I do it, and have done it for a pretty long time. In the vast majority of cases, it's (almost) in the form of sitename@myemailaccount.com - which is usually pretty easy to remember.

If someone was directly targeting me, and had my email address from another site, they could probably figure out what I'd used elsewhere. But if it's just a script running through email addresses harvested from site A, then mine will almost always be irrelevant on site B.

The main reason I use it though is that it's a great way to figure out where spam is coming from. Last week for instance I got a "male enhancement" spam from an email address I've only ever given to scan.co.uk. That addres is now on my block list and I doubt I'll be buying through them again.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#63

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

Tons of folks (think: grandmothers and parents and other potentially non-tech-savvy folks) have been using Skype to communicate with family members across the globe for many years. Simply expecting them to switch to Google Hangouts is a tall order.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#64
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

The same is, or was at least, true of xbox live - someone registered using my email, and there's obviously no account confirmation, as the account is live and I receive email notifications etc, but I can't get into it or remove it, since I don't know the password. I wonder how many other sites do this to avoid friction on sign up?

Happened to me too. I have no way to tell them that I am indeed not xXx_Rastafarian_xXx .

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#65

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

The existing user base. When you communicate daily with a ton of customers using Skype, switching to something else seems a remote prospect at best.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#66
post #33
post #16

Earlier quoted context omitted.

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I use unique and secure passwords for all online services, https://agilebits.com/onepassword makes it really simple.

[deleted]

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#67
post #49

Earlier quoted context omitted.

Except that Microsoft has a pretty stellar reputation when it comes to security procedures. They're well known as being among the best in the industry.

Well, they've certainly cleaned up their act, but I definitely wouldn't say that they're known to be among the best in the industry.. I remember just a few year ago, you could get to ring0 in Windows and install a rootkit just via the registry.. Let's not forget all the hotmail vulnerabilities similar to this that have been active for an indeterminate amount of time..

A few years is an enormous period of time especially when it comes to tech and infosec.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#68
post #16

Earlier quoted context omitted.

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

I do it, and have done it for a pretty long time. In the vast majority of cases, it's (almost) in the form of sitename@myemailaccount.com - which is usually pretty easy to remember. If someone was directly targeting me, and had my email address from another site, they could probably figure out what I'd used elsewhere. But if it's just a script running through email addresses harvested from site A, then mine will almo…

Nice way to find where spam comes from.

Sadly this is at best a complicated workaround, that will will work for people that are motivated enough to remember for each different service a separate email and password and additionally to this you have to remember as well the credentials to manage your email address and check the emails from different sites.

In my case it would mean having about 100 email addresses.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#69
post #51
post #16

Earlier quoted context omitted.

Are you suggesting to have a different email address for every online service we use? Today I manage about 100 different unique passwords for every online service. This is already very inconvenient. Adding as well as having different bogus email addresses would be at least 2 times more difficult! I think something is really broken in today's web authentication scheme. I think there is really huge need for some indepe…

http://www.keepassx.org/ is a free and open-source password manager. It makes using almost infinite numbers of accounts easy to use. If you use secure passwords they are like not possible to remember anyways.

I moved from PC Applications for Password usage to use passdroid on the phone. Like this I have the passwords always in my pocket.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#70
post #44

Earlier quoted context omitted.

This appears to be a bug. After adding the email address and clicking save, logging out, and logging in, I found the email address was successfully added. At this point I could change it to the primary one, click save, paste my password, and click the button on the password prompt to successfully change my primary email address. If I tried to add the email and make it primary in one session, it would not work. If I e…

Doesn't work for me - I can add a new email address, but when I sign out and back in it's vanished. Feels like they might have disabled parts of the account management system.

The site is very buggy indeed. But it is possible to change the primary email adress if, when you are prompted to retype your password, you "type password and click button by mouse, not by "Enter" key" (as the post says). Maybe that would work for you...
Post reply on HN