Breaking News

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio Creative Announces Sound Blaster AE-X Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Skype Tackles Hack Vulnerability (updated)

Skype Tackles Hack Vulnerability (updated)

Enterprise & IT Nov 14,2012 0

Skype has suspended its password reset function after reports that the feature could be used to hijack the service's accounts. The vulnerability, which emerged on a Russian blog about three months ago, could have exposed answerphone messages, old text message conversations and user details including date of birth.

Skype is looking into the problem.

"We have had reports of a new security vulnerability issue," said engineer Leonas Sendrauskas.

"As a precautionary step we have temporarily disabled password reset as we continue to investigate the issue further. We apologise for the inconvenience but user experience and safety is our first priority."

The hack involves using a victim's Skype-registered email address to create a new account which is also linked to an email account owned by the attacker.

If a password change is then requested using the target's username, the hijacker can access the resulting reset token via the Skype app itself using the newly-created bogus log-in.

The security hole was confirmed by The Next Web.

The news comes amid Microsoft's efforts to convince members of its Windows Live Messenger chat tool to switch to Skype.



Update

After temporarily removing the ability to reset passwords while it worked on a solution, Skype has now issued a fix for the security bug. The company also issued the following statement:

"Early this morning we were notified of user concerns surrounding the security of the password reset feature on our website. This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today so that it is now working properly. We are reaching out to a small number of users who may have been impacted to assist as necessary. Skype is committed to providing a safe and secure communications experience to our users and we apologize for the inconvenience."

Tags: Skype
Previous Post
Google Fiber Installations In Kansas Homes Started
Next Post
WD Unveils 802.11AC Wireless Router and Bridge for Maximum Wi-Fi Speeds

Related Posts

  • Skype's 'Meet Now' Calls Don't Need a Sign-up

  • EU Countries Disagree on Privacy Rules for WhatsApp, Skype

  • Skype's Screen Sharing Goes Mobile

  • New Skype for Web Released But Not For Safari, Firefox or Opera Browsers

  • Skype Introduces Background Blur Feature

  • Apple Removes Skype and Other Apps in China

  • Cortana is Coming to Your Skype Chat Window

  • Skype and PayPal team up with new Send Money feature

Latest News

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit
PC components

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit

Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio
Consumer Electronics

Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio

Creative Announces Sound Blaster AE-X
PC components

Creative Announces Sound Blaster AE-X

Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel
Gaming

Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel

COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition
GPUs

COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed