Earlier quoted context omitted.
The same is, or was at least, true of xbox live - someone registered using my email, and there's obviously no account confirmation, as the account is live and I receive email notifications etc, but I can't get into it or remove it, since I don't know the password. I wonder how many other sites do this to avoid friction on sign up?
Happened to me too. I have no way to tell them that I am indeed not xXx_Rastafarian_xXx .
Skype vulnerability allowing hijacking of an account if you know just the email
101–110 of 124 posts
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#102Any idea the period of time this bug has been present? I remember the login process being inconsistent (especially among the iOS apps) when I signed up four years ago, but I attributed it to me just being unfamiliar with the service.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#103I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?
Because I don't want to sign up for Google+. I dislike the idea of bundling their social data mining solution with just about anything, like a less obvious and impossible to opt-out version of whatever-toolbar bundled with software years ago.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#104Re: Skype vulnerability allowing hijacking of an account if you know just the email
#105I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?
Because Skype always works. For example, most ISP in Russia still allow access to provider's network ever if internet connection is unpaid. Skype works, because somebody with internet who paid for it is gate for all unpaid users. Skype traffic is almost impossible to block except some hacks about detecting his autoupdate.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#106Earlier quoted context omitted.
Even now Skype reaction is unbelievable. They are "investigating the issue" for almost 2 hours.
Stop saying "Skype", use "Microsoft" instead, and it's not unbelievable at all.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#107I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#108Earlier quoted context omitted.
Right. There's one developer at Skype who can just do that and push it to production, without talking to anyone else, or getting approval from anyone else. Be realistic. If two people need to talk about it, it's going to take longer than 2 minutes.
Longer than two minutes, definitely! More than 2 hours to investigate and fix? very doubtful. 3 months? That's a bit much...
The two hours were most likely spent on office politics as opposed to fixing the problem. I'm surprised it wasn't > 5 hours to be honest.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#109Earlier quoted context omitted.
While I don't necessarily agree with your parent's post, there's a relatively simple solution here. If you're using gmail, you can use the + operator to automatically tag emails. Here, it serves an alternative purpose. For example, if my email is daniel@gmail.com , then I would use daniel+hn@gmail.com when signing up for Hacker News.
Skipping over the fact that most email providers don't necessarily support this, and that not all websites/services will allow it (not saying they are right not to), this creates a whole new set of things to remember as even something as simple as +hn (which is surely simple enough that anyone could guess it) could be tougher on other sites, e.g. is Reddit +rd, +re, or...?
Sometimes, I don't actually remember and just end up going to my inbox to find an email from the site so I can look up what I used.
Another time, this backfired on me when I purchased concert tickets using a +descriptor email and couldn't login. The purchase form and login form had different validation rules, so the purchase form accepted my +descriptor email and charged me for it. The login form rejected my +descriptor email and I was rushing to contact customer service to print my ticket in time.
Re: Skype vulnerability allowing hijacking of an account if you know just the email
#110In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…