Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

71–80 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#71
Not quite as bad but it is also possible to get a user's IP address just by sending them a friend request. This has been known about and exploited for months, possibly over a year. It's meant that high profile users of Skype on sites like youtube or twitch.tv have to keep their skype private and/or connect to it specifically with a proxy to avoid getting DDOSed

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#72

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

Because I don't want to sign up for Google+. I dislike the idea of bundling their social data mining solution with just about anything, like a less obvious and impossible to opt-out version of whatever-toolbar bundled with software years ago.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#73
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

The same is, or was at least, true of xbox live - someone registered using my email, and there's obviously no account confirmation, as the account is live and I receive email notifications etc, but I can't get into it or remove it, since I don't know the password. I wonder how many other sites do this to avoid friction on sign up?

sony network is the same. i have a throwaway gmail address which was used to sign up for the sony network an various games. at first i replied to any email that i didn't sign up for this, then i contacted sony network customer service, they said something marketing, i decided to not care. now every email from sony gets a direct way to the spam folder.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#74

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

I use Skype quite regularly. I'd much prefer to move to Google+ Hangouts but there are a few things that make using it more painful than Skype:

* More people that I'm in contact with have Skype installed vs. have Google Voice and Video installed

* I use Adium as my IM client as I find it easier to use than Google+ in browser chat. To avoid double notifications, I keep chat closed 'in browser', which adds friction when starting a hangout

* Skype makes the call much faster than Google+ hangouts. In hangouts, the call usually times out but if I leave the window open, the other party will eventually join

On the plus side:

* Google+ hangouts call quality is usually much better

* Skype can't do multi-user video

* I find the 'in call' Google+ hangouts interface much more intuitive.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#75

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

Well, I'm not a big fan of Skype but I tend to use it for longer calls with family overseas (USEurope) because I experience quite significantly better video/audio quality. Few months back (it's fixed now I think) I even had freezing video every so often on Google Hangout.

Or screen sharing, it was completely unusable in Google Hangouts on Linux just 2 months back whereas Skype didn't have any issue and worked (surprisingly!) flawlessly.

I don't really perceive the network effect that much, everybody I have on Skype also has a Google account.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#76

Earlier quoted context omitted.

Yeah, you could do that as well. I just don't like the idea that someone holds my email address. After reading few stories where Google/Microsoft blocks access to email, I decided to move my email to custom domain. In case of any issues all I have to do is change MX names to new provider to start receiving my mails again.

You can do the +modifier trick with GApps as well.

Yes, but one of the great things about having GApps with your own domain name, is that you are not tied to Google as an email provider, and can easily switch. If you use something like the '+' modifier, then if you switch away you need to switch to someone that supports the same modifier.

So if your goal is to maintain email-provider independence, then relying on provider-specific features like the '+' modifier works against that goal.

For me though, the main reason I don't use it is most sites that I want to use it on reject the '+' in the address as invalid. It happens enough that I don't bother trying anymore.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#77
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

While I admit it's stupid they don't verify new user's email addresses, it doesn't look like doing so would even prevent this recent attack. If I understand the attack correctly, the only way to prevent your account being taken is to change you email address to something unknown. In effect using the uniqueness of your email address as a 2nd password.

This attack it truly horrendous and its disclosure will most likely reverberate for a while.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#78
post #68

Earlier quoted context omitted.

I do it, and have done it for a pretty long time. In the vast majority of cases, it's (almost) in the form of sitename@myemailaccount.com - which is usually pretty easy to remember. If someone was directly targeting me, and had my email address from another site, they could probably figure out what I'd used elsewhere. But if it's just a script running through email addresses harvested from site A, then mine will almo…

Nice way to find where spam comes from. Sadly this is at best a complicated workaround, that will will work for people that are motivated enough to remember for each different service a separate email and password and additionally to this you have to remember as well the credentials to manage your email address and check the emails from different sites. In my case it would mean having about 100 email addresses.

You actually don't need separate emails for this. You can use (name+tag@provider.com, Gmail supports it and others too I'm sure). Or you can use your own domain (Google Apps makes this really trivial) and have the part before @ be the sitename (that's what OP suggests) and then have catch-all address. You might receive slightly more spam if you turn on catch-all, but I have a setup like this a it works.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#80
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

While I admit it's stupid they don't verify new user's email addresses, it doesn't look like doing so would even prevent this recent attack. If I understand the attack correctly, the only way to prevent your account being taken is to change you email address to something unknown. In effect using the uniqueness of your email address as a 2nd password. This attack it truly horrendous and its disclosure will most likely…

The first step of this attack is to create another account for the email address controlled by a victim. If Skype sent verification email to this address asking the victim to click a link to confirm creation of the new account, this first step wouldn't work.
Post reply on HN