Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

81–90 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#81

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

Because Skype always works. For example, most ISP in Russia still allow access to provider's network ever if internet connection is unpaid. Skype works, because somebody with internet who paid for it is gate for all unpaid users. Skype traffic is almost impossible to block except some hacks about detecting his autoupdate.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#82
post #69
post #51

Earlier quoted context omitted.

http://www.keepassx.org/ is a free and open-source password manager. It makes using almost infinite numbers of accounts easy to use. If you use secure passwords they are like not possible to remember anyways.

I moved from PC Applications for Password usage to use passdroid on the phone. Like this I have the passwords always in my pocket.

Thanks to the power of free open-source software there is keepassdroid of course. ;)

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#83

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

So now you need a password manager to remember the email addresses instead of the password.

What problem are you solving?

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#84

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

As far as I know, Google+ Hangouts doesn't let you call people.

Is there a way to actually just phone somebody with it, the phone on their computer rings, and they answer it?

Preferably with a standalone client, as I can't guarantee I'd remember to open and leave open a browser tab.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#85
post #5

Earlier quoted context omitted.

Stop saying "Skype", use "Microsoft" instead, and it's not unbelievable at all.

Except that Microsoft has a pretty stellar reputation when it comes to security procedures. They're well known as being among the best in the industry.

No they don't. They have a reputation for taking months to respond to security issues, responding with "yeah whatever, we'll look into it" and then doing nothing for months, leaving software vulnerable to known exploits because "its not patch day yet", and similar bullshit.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#86

It's even worse! Their website is so broken you can't change your password (new password fields are disabled) and you can't set a new email address as primary (the "make primary" button only appears when the new email address field is empty). Also, if you first add a new email address, save, then set it to primary, it disappears. Wtf. I see no recourse other than closing my account, if that's still possible. [edit] N…

The solution is here: http://www.reddit.com/r/netsec/comments/13664q/skype_vulnera...

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#87
post #50

Earlier quoted context omitted.

I think it's possible to flip the order. Instead of managing 100 passwords for each account, manage 100 emails and ONE password for all accounts. Make sure your password is really strong, and you should be better-off than managing those 100 passwords, which require a secure password manager. Of course it's better to have a real password manager, but for most people, who don't or can't be bothered setting this up, thi…

And then one of the accounts' password is stored in plaintext and the database is leaked with the mail addresses and everyone can easily log in as you at 100 services. Never, ever, re-used passwords for anything you value.

Except, as the comment you responded to suggested, you would use a different email for each service.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#88

I think it's a good practice to always use unique, unpredictable email addresses when signing for online services. 1. Most people use the same or similar password, so once one account gets hacked, the attacker is probably able to use many other accounts on different services with the same email address/password combo. 2. It's easier to spot services that spam, or that leak your email address (I became aware of a leak…

So now you need a password manager to remember the email addresses instead of the password. What problem are you solving?

The problem I was trying to solve is of many people who use the same password and email everywhere, and who won't use a password manager or feel it's too complicated to install or use etc.

The email addresses are not as sensitive as passwords. Sure. If someone gets hold of all of them AND your master password you're in trouble. But same goes to getting your password manager file and the password for it.

The difference is you don't need a password manager software. You can store this list anywhere which is reasonably safe.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#89

Earlier quoted context omitted.

So now you need a password manager to remember the email addresses instead of the password. What problem are you solving?

The problem I was trying to solve is of many people who use the same password and email everywhere, and who won't use a password manager or feel it's too complicated to install or use etc. The email addresses are not as sensitive as passwords. Sure. If someone gets hold of all of them AND your master password you're in trouble. But same goes to getting your password manager file and the password for it. The differenc…

Your scheme is no easier to implement than having a different password for each website. You have effectively moved part of the password out of the password and into the email address.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#90
post #50

Earlier quoted context omitted.

I think it's possible to flip the order. Instead of managing 100 passwords for each account, manage 100 emails and ONE password for all accounts. Make sure your password is really strong, and you should be better-off than managing those 100 passwords, which require a secure password manager. Of course it's better to have a real password manager, but for most people, who don't or can't be bothered setting this up, thi…

And then one of the accounts' password is stored in plaintext and the database is leaked with the mail addresses and everyone can easily log in as you at 100 services. Never, ever, re-used passwords for anything you value.

did you actually read what I was saying on the blog post or the comment??

Most people re-use not only the password, but also their email. This is the worst combination.

If you use an unpredictable, unique email address, and use a secure password. Even if it leaks on one site, the attacker has no easy way to predict what your email address is going to be on any other site without having access to the list of email addresses.

Post reply on HN