Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

101–110 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#101

Earlier quoted context omitted.

The same is, or was at least, true of xbox live - someone registered using my email, and there's obviously no account confirmation, as the account is live and I receive email notifications etc, but I can't get into it or remove it, since I don't know the password. I wonder how many other sites do this to avoid friction on sign up?

Happened to me too. I have no way to tell them that I am indeed not xXx_Rastafarian_xXx .

You're going to end up on some federal agency list for being a suspected pothead ;)

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#102
post #79

Any idea the period of time this bug has been present? I remember the login process being inconsistent (especially among the iOS apps) when I signed up four years ago, but I attributed it to me just being unfamiliar with the service.

Yes. Wow yes. The interface is getting better, but its still awful. At least you can now return a missed call without going out the page, into contacts, and hunting the caller down. The OSX client is a whole other world of pain. FaceTime briefly looked like a promising replacement, but no.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#103

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

Because I don't want to sign up for Google+. I dislike the idea of bundling their social data mining solution with just about anything, like a less obvious and impossible to opt-out version of whatever-toolbar bundled with software years ago.

and you strangely believe microsoft isn't doing the same thing with skype's data?

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#104

Earlier quoted context omitted.

Happened to me too. I have no way to tell them that I am indeed not xXx_Rastafarian_xXx .

You're going to end up on some federal agency list for being a suspected pothead ;)

Fortunately even our fear of drugs isn't that insane.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#105

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

Because Skype always works. For example, most ISP in Russia still allow access to provider's network ever if internet connection is unpaid. Skype works, because somebody with internet who paid for it is gate for all unpaid users. Skype traffic is almost impossible to block except some hacks about detecting his autoupdate.

Works usually yes, but that isn't all a good service needs. I'd like to enjoy using it rather than getting Skype-rage. Interface, inability to block calls (from iOS at least), I'd better not start or I won't stop.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#106
post #5
post #3

Earlier quoted context omitted.

Even now Skype reaction is unbelievable. They are "investigating the issue" for almost 2 hours.

Stop saying "Skype", use "Microsoft" instead, and it's not unbelievable at all.

Given what I've heard of Skype-as-Microsof-Skype, it would be inaccurate to act like Skype has been assimilated or would have much if any overlap with the people handling Windows vulnerabilities.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#107

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

The audio quality of Skype is far superior to Hangouts.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#108

Earlier quoted context omitted.

Right. There's one developer at Skype who can just do that and push it to production, without talking to anyone else, or getting approval from anyone else. Be realistic. If two people need to talk about it, it's going to take longer than 2 minutes.

Longer than two minutes, definitely! More than 2 hours to investigate and fix? very doubtful. 3 months? That's a bit much...

I see your not familiar with the nature of code deployments and everything that has to happen beforehand. ;)

The two hours were most likely spent on office politics as opposed to fixing the problem. I'm surprised it wasn't > 5 hours to be honest.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#109
post #25
post #21

Earlier quoted context omitted.

While I don't necessarily agree with your parent's post, there's a relatively simple solution here. If you're using gmail, you can use the + operator to automatically tag emails. Here, it serves an alternative purpose. For example, if my email is daniel@gmail.com , then I would use daniel+hn@gmail.com when signing up for Hacker News.

Skipping over the fact that most email providers don't necessarily support this, and that not all websites/services will allow it (not saying they are right not to), this creates a whole new set of things to remember as even something as simple as +hn (which is surely simple enough that anyone could guess it) could be tougher on other sites, e.g. is Reddit +rd, +re, or...?

To carry this idea further, the +descriptor email trick has backfired on me before. Sometimes sites require an email login and it takes me several tries to even remember what my +descriptor was.

Sometimes, I don't actually remember and just end up going to my inbox to find an email from the site so I can look up what I used.

Another time, this backfired on me when I purchased concert tickets using a +descriptor email and couldn't login. The purchase form and login form had different validation rules, so the purchase form accepted my +descriptor email and charged me for it. The login form rejected my +descriptor email and I was rushing to contact customer service to print my ticket in time.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#110
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

Turing test failure, or highly trained human? I'm not sure.
Post reply on HN