3 ms·
I don't think I can fault Skype for this "vulnerability" - the problem itself isn't really in code, but in people. Yes, within the article there's mention of a
by wwwigham 10y ago
I don't think I can fault Skype for this "vulnerability" - the problem itself isn't really in code, but in people. Yes, within the article there's mention of a past attack which relied on socially engineering a support specialist to send verification codes and guess the result, but that seems to have stopped. I'd actually love to know the key generation algorithm or the probabilities that go into guessing one of four-ish codes sent in a burst in just a few tries.
Still. the other exploit mentioned, the one not "patched" - This same kind of mass-reporting system exploit is usable in all manner of online forums and services - heck, HN's own flag feature could get pretty close (we just have some very hands-on moderators and an okay community)!
As for not restoring something when contacting support... I can understand why. It's _better_ this way, since then no malicious party who is _actually_ spamming with Skype accounts can retrieve an account using only a bit of social engineering! Instead they need to roll up new emails and new accounts. (And think of it this way: If a malicious party is abusing the system to get your account blocked, how will they know your new account to repeat the procedure? They shouldn't.)
Yes. It's a pity that the abuse reporting system is itself vulnerable to abuse, but... aren't most? Given Skype's massive userbase, putting the user reporting function behind a mechanical turk... the rate at which they'd need to comb through ban requests would seem to make fatigue (and thereby false positives which would result in the same outcome as now) inevitable. The only interesting way I've seen this abuse-system abuse handled in recent years was the League of Legends tribunal system[1], where they effectively handed penalty decisions to the community at large and let them come to a consensus. Though I don't know how well it worked and, honestly, that system seems just as game-able as the automated report button itself. In fact, it feels analogous to a Sybil attack[2] in the crypto world - get enough aligned malicious identities in a decentralized system and they effectively control it. The only "fix" is making identity creation too expensive to make gaining a controlling share of the identity-space prohibitive (which would entail making account creation difficult) - I feel that this is _directly at odds_ with account creation speed and this user acquisition for a service like this, so I can not fault Skype for falling on the middleground that they have.
[1]http://forums.na.leagueoflegends.com/board/showthread.php?t=2068259 http://forums.na.leagueoflegends.com/board/showthread.php?t=...
[2]https://en.wikipedia.org/wiki/Sybil_attack https://en.wikipedia.org/wiki/Sybil_attack
- Dylan16807 10y agoIf they guessed the verification code then there's clearly a massive code issue. And if a report system is broken enough you can just not have one. Or maybe take away the ability of an account to send friend requests while leaving the rest of it intact. That would take care of spambots without ruining real accounts.
- ordu 10y agoIf support team is vulnerable to abuse, so deal with it. For example, stop blocking accounts due to abuse reports. Just block account ability to contact with reporter. Make some automatic abuse detection system to deal with most popular cases. Invent some type of carma for users, keep it hidden, but let this carma influence on decision making of support team or abuse detection system. A little courage to face problem and some creativity to brain storm a solution... But Skype team seems lacking will to solve any problems.