Live data from Hacker News

Tell HN: Microsoft Skype Security Is Flawed

news.ycombinator.com

31–40 of 43 posts

Re: Tell HN: Microsoft Skype Security Is Flawed

#31
Anyone using [insert service here] should be using MFA of some sort. This would solve so many of these problems. It does sound like OP is being hit by a phishing attack, but assuming it's not that, this can only be a lesson for everyone to turn on MFA now if you haven't already. Yes, MS' consumer platform (live, hotmail, outlook, etc) supports it.

Re: Tell HN: Microsoft Skype Security Is Flawed

#32
post #25

Earlier quoted context omitted.

They gradually removed[0] the peer to peer operation because it sucked - quality was bad, calls dropped, outages, bad mobile support. [0] https://arstechnica.com/information-technology/2012/05/skype...

Quality was not bad, calls didn't drop, no outages, good mobile support. Because it's p2p couldn't be hacked, it was replaced.

Quality was good and calls didn't drop, but the mobile support was poor. The original design assumed that it can use both cpu time and bandwidth of peers, and that isn't very good for devices on battery and metered data plans.

Re: Tell HN: Microsoft Skype Security Is Flawed

#33

Skype security has been flawed ever since that series of odd buyout events that led to the sudden removal of end-to-end encrypted peer to peer operation. First eBay bought what they thought was Skype but instead was only the license to the branding and users and not the p2p backend tech the swiss guys still owned. Then Microsoft stepped in out of nowhere to take the useless brand from eBay and the actual backend only…

They gradually removed[0] the peer to peer operation because it sucked - quality was bad, calls dropped, outages, bad mobile support. [0] https://arstechnica.com/information-technology/2012/05/skype...

That's now how I remember it.

I used skype before I had ADSL, and was amazed at the quality.

After MS bought it, I noticed a drop in quality, as well as an increase in reports of said drop online.

Re: Tell HN: Microsoft Skype Security Is Flawed

#35
Somewhat related, I ran (and am still running) into a very uncanny issue related to another product of Microsoft: Live / Outlook.

When Live and Outlook got merged (IIRC a couple of years ago), my @msn.com address got an @outlook.com alias.

Unfortunately, this "alias" shouldn't have been one and the email was actually owned by someone else.

By some sort of failed merging, I hence ended up getting access to someone else' emails: PayPal related emails, Dropbox access connected to this email account, private email exchanges, etc...

I tried to reach out to Microsoft but hit (expectedly) a wall.

Re: Tell HN: Microsoft Skype Security Is Flawed

#36
post #25

Earlier quoted context omitted.

Quality was not bad, calls didn't drop, no outages, good mobile support. Because it's p2p couldn't be hacked, it was replaced.

Quality was good and calls didn't drop, but the mobile support was poor. The original design assumed that it can use both cpu time and bandwidth of peers, and that isn't very good for devices on battery and metered data plans.

Maybe if data caps greatly increase with 5G, something p2p like Skype would could be retried.

Re: Tell HN: Microsoft Skype Security Is Flawed

#37
I experienced the same problem with a very old Skype account. There's no way to reset my password because it says my Microsoft account doesn't exist. My guess is they botched the account migrations from Skype to MSFT in a way that means we cannot prevent account takeovers not access the Skype account. I received an email saying my account was being taken over and given no way to disavow or prevent it. I'm very frustrated with MSFT security. I'm not even sure how one can report such a big.

Re: Tell HN: Microsoft Skype Security Is Flawed

#38
post #31

Anyone using [insert service here] should be using MFA of some sort. This would solve so many of these problems. It does sound like OP is being hit by a phishing attack, but assuming it's not that, this can only be a lesson for everyone to turn on MFA now if you haven't already. Yes, MS' consumer platform (live, hotmail, outlook, etc) supports it.

Without widespread U2F support, the list of individual MFA secrets I would have to maintain would be unmanageable. It's not yet reasonable to expect users to have MFA on all of their accounts; only their most important ones.

Re: Tell HN: Microsoft Skype Security Is Flawed

#40
post #4

Thats how i lost my last account. They were asking me details like the account creation date which was > 15 years old

yeah, i read about that requirement. there is a way to interrogate skype's windows desktop client install to extract the account creation date. even squirreled away a support link about how to do this which of course is now broken.

Edit: new link here

https://answers.microsoft.com/en-us/skype/forum/all/skype-ac...

Post reply on HN