Hacker News new | ask | show | jobs
by AYBABTME 4964 days ago
I once had a paid for account with Skype. One day I woke up with my account hacked into because of their poor security procedures, and the hacker having drained all the money (enjoying the automatic recharge), making international calls, until the limit of automatic recharges per day got exhausted.

I was curious about the break-in of my account because I always used good security practices, having a unique password for Skype, always logging in over https or the Skype client. Also I use a Linux distribution (Arch) so the chances of being infected by a virus of having a key-logger installed are pretty low. I found out that tools to expose any Skype accounts password were readily available online, so my security practices were pretty irrelevant.

Given that Skype's security is non-existent, I since assume that whatever info I put in my account is public and that there is no protection or security of my data whatsoever.

Since then, I revoked their access to my PayPal and my credit card. They are not trustworthy of my money, and I keep hearing from time to time about new huge security holes in their accounts. I do not recommend that anybody authorize any payment with them.

1 comments

Just yesterday I learned about a flaw that, knowing the previous one, allowed you to change password recovery email address on any Skype account.