TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tell HN: Microsoft Skype Security Is Flawed

153 点作者 samnwa大约 5 年前
I received an email today from Skype that someone had changed the email address on an old Skype account of mine. Presumably this means that they were able to gain access to a password. There was no mechanism in the email to block the action. Next, I received an email that said &quot;Someone started a process to replace all of the security info for the Microsoft account.&quot; Again, there was no way to block this action.<p>Both emails encouraged me to contact customer support. I did so only to be met with a request to fill out an online form with an incredible amount of personal information to verify the account. Why would I provide 10X the personal info that might then be made accessible to a user whose email address was swapped into the account with no verification at all?<p>Does anyone have any advice on how to resolve or escalate to Microsoft? Ideally the original email address on the account would be restored and more broadly, Live &#x2F; Skype should update their security procedures to avoid this type of &quot;easy to steal accounts&quot; security policy while hard to block the stealing of accounts.<p>Any help &#x2F; suggestions appreciated.

12 条评论

superkuh大约 5 年前
Skype security has been flawed ever since that series of odd buyout events that led to the sudden removal of end-to-end encrypted peer to peer operation.<p>First eBay bought what they thought was Skype but instead was only the license to the branding and users and not the p2p backend tech the swiss guys still owned. Then Microsoft stepped in out of nowhere to take the useless brand from eBay and the actual backend only to promptly throw away the entire backend and move to a centralized unencrypted model.
评论 #23157403 未加载
评论 #23156430 未加载
评论 #23156375 未加载
评论 #23157752 未加载
评论 #23156237 未加载
rodolphoarruda大约 5 年前
&gt; Both emails encouraged me to contact customer support. I did so only to be met with a request to fill out an online form with an incredible amount of personal information to verify the account. Why would I provide 10X the personal info (...)?<p>This by itself looks like a phishing attack. Did you click a link to Skype support in the second email message or find it by yourself going to the Skype website and browsing around?
评论 #23155961 未加载
评论 #23157067 未加载
buboard大约 5 年前
Thats how i lost my last account. They were asking me details like the account creation date which was &gt; 15 years old
评论 #23168486 未加载
评论 #23155236 未加载
nip大约 5 年前
Somewhat related, I ran (and am still running) into a very uncanny issue related to another product of Microsoft: Live &#x2F; Outlook.<p>When Live and Outlook got merged (IIRC a couple of years ago), my @msn.com address got an @outlook.com alias.<p>Unfortunately, this &quot;alias&quot; shouldn&#x27;t have been one and the email was actually owned by someone else.<p>By some sort of failed merging, I hence ended up getting access to someone else&#x27; emails: PayPal related emails, Dropbox access connected to this email account, private email exchanges, etc...<p>I tried to reach out to Microsoft but hit (expectedly) a wall.
aksss大约 5 年前
Anyone using [insert service here] should be using MFA of some sort. This would solve so many of these problems. It does sound like OP is being hit by a phishing attack, but assuming it&#x27;s not that, this can only be a lesson for everyone to turn on MFA now if you haven&#x27;t already. Yes, MS&#x27; consumer platform (live, hotmail, outlook, etc) supports it.
评论 #23163301 未加载
z3t4大约 5 年前
Try to contact all your contacts and tell them that your Skype account have been hacked. Also don&#x27;t give away any personal details unless you are 100% sure you are dealing with the official support. Your account will likely be used to scam your friends and family. If you have your voice online somewhere they can fake it, or just use the chat to impersonate you. Your personal details and chat history will make it very convincing.<p>Hi, this is Samnwa, your brother, we talking yesterday about xyz, how is that going? btw, could you help me login to my bank, can&#x27;t find my key card, can I use yours? Cool, alright, Just enter this number... Ooops I entered it wrong, lets try this number...
kuzee大约 5 年前
I experienced the same problem with a very old Skype account. There&#x27;s no way to reset my password because it says my Microsoft account doesn&#x27;t exist. My guess is they botched the account migrations from Skype to MSFT in a way that means we cannot prevent account takeovers not access the Skype account. I received an email saying my account was being taken over and given no way to disavow or prevent it. I&#x27;m very frustrated with MSFT security. I&#x27;m not even sure how one can report such a big.
Iolaum大约 5 年前
If the password to the account hasn&#x27;t changed, log in, change back the email and change the password.
评论 #23155057 未加载
2rsf大约 5 年前
How old was the account ? a few years ago they (tried to) move all the accounts to be Microsoft accounts with better security and policies
gruturo大约 5 年前
That&#x27;s a scary amount of information which is being asked of you. Are you sure the site asking for it is a genuine Microsoft asset?
评论 #23155788 未加载
confeit大约 5 年前
Did you reuse the password at any other site? Check your haveibeenpawned.
评论 #23158676 未加载
rakibtg大约 5 年前
This is most probably a phishing attack.
评论 #23158023 未加载