Live data from Hacker News

Skype vulnerability allowing hijacking of an account if you know just the email

pixus-ru.blogspot.ru

111–120 of 124 posts

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#111
post #100
post #97

By the way, Skype's registration page has inexplicable password rules. aaaaa1 - strength: medium aaaaa12345 - strength: poor =aStu!et$aQ@212345 - strength: poor

Yeah, at my last job, someone implemented a password strength checking feature that would actually reject stronger passwords. It required: 1. At least 3 out of the 4 categories uppercase, lowercase, digit, special character 2. No character could be repeated more than two times 3. No sequence of 3 or more increasing or decreasing letters or numbers could be present (and not even consecutive: "ta/Tbs#cz" would be rejec…

So... were ANY passwords created? I could see the success rate on this at like 1%.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#112
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

Netflix has a similar problem - http://blog.hardikr.com/tech/netflix-email-fail/

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#113

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

The company I work for uses it, ~150 Skype users. Works pretty well!

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#114
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

Turing test failure, or highly trained human? I'm not sure.

Encountering tech support people that would fail a Turing test is not nearly as rare as one would want it to be.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#115
post #100
post #97

By the way, Skype's registration page has inexplicable password rules. aaaaa1 - strength: medium aaaaa12345 - strength: poor =aStu!et$aQ@212345 - strength: poor

Yeah, at my last job, someone implemented a password strength checking feature that would actually reject stronger passwords. It required: 1. At least 3 out of the 4 categories uppercase, lowercase, digit, special character 2. No character could be repeated more than two times 3. No sequence of 3 or more increasing or decreasing letters or numbers could be present (and not even consecutive: "ta/Tbs#cz" would be rejec…

They must have really dedicated customers. That, or their users are required to use their system under the pain of multi-year imprisonment. I see no other way why would anyone agree to suffer through this.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#116

I'm genuinely curious- what's keeping people on Skype? There are better alternatives out there now (Google+ Hangouts, for example). Will this push any of you Skype users over?

Hangouts are very different use case from Skype. Skype is a messaging platform, g-hangout is a teleconference platform. They have intersecting, but not identical uses.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#117
post #39

In August I received an email from Skype thanking me for registering an account. But I already had an account, I didn't register this one. After comparing the new account name with part of my email, I came to the conclusion that someone mistyped their email address, and registered an account on my address. I contacted their live support, here's the conversation: George A: Hello! Welcome to Skype Live Support! My name…

Incidentally, I've had someone (judging from the last name I get to see in the email, a Chinese person) use one of my email addresses to register a WoW account. You don't actually need to verify the email address, so they don't need access.

What's interesting is after spending 30min or so clicking around Blizzard's site there is no way to actually contact support without having an account. You also can't claim the account, because you need a first and last name along with the email address, and I only have one of their names.

In the end I just left it, it was an old account and there is no evidence that they had real access, and as it was a legacy account I'd securified it anyway (creating a massive 32character random password and storing it in a password manager, just to close off any loose ends).

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#118
post #108

Earlier quoted context omitted.

Longer than two minutes, definitely! More than 2 hours to investigate and fix? very doubtful. 3 months? That's a bit much...

I see your not familiar with the nature of code deployments and everything that has to happen beforehand. ;) The two hours were most likely spent on office politics as opposed to fixing the problem. I'm surprised it wasn't > 5 hours to be honest.

Given your description I'm sure I'm lucky I'm not familiar with that. I've never worked at any place that has > 40 employees. If I can manage, I hope never to have to.

Re: Skype vulnerability allowing hijacking of an account if you know just the email

#120
post #108

Earlier quoted context omitted.

I see your not familiar with the nature of code deployments and everything that has to happen beforehand. ;) The two hours were most likely spent on office politics as opposed to fixing the problem. I'm surprised it wasn't > 5 hours to be honest.

Given your description I'm sure I'm lucky I'm not familiar with that. I've never worked at any place that has > 40 employees. If I can manage, I hope never to have to.

Yeah, there's no doubt it sucks but so can working for smaller organisations. It's all about the people your working with. The bigger the company, the more deadwood you likely have to work with.
Post reply on HN