![]() This allows you to login using your email address, your mobile number, or your Skype username. These are essentially multiple usernames. It’s a mammoth effort behind the scenes.Īs part of this process, they’re supporting the use of multiple ‘aliases’ for each account. Microsoft are on a mission to merge all of their identity platforms: consumer Microsoft accounts, work or school accounts (OrgId / AAD), and Skype accounts. ![]() Considering the simplicity of Skype’s overall approach to authentication, and their rather broad range of client APIs, I’d postulate that there’s some brute forcing in play as well, or there has been a credential leak. Skype are stating that this is most likely due to credential re-use, however I know of one IT security professional whose account was compromised despite using a unique password that was always stored in a password manager. Skype accounts are actively being compromised via simple username + password authentication, with no second factor validations in play. Skype accounts have never supported two-factor authentication. Linking a Microsoft account never prevented the Skype-based sign in. This allowed me to login to my Skype account via my Microsoft Account ( Anybody who has used the Windows 8 or Windows 10 apps for Skype will have been encouraged down this path. (It does now.)Īfter Microsoft acquired Skype, they added support for ‘linking’ a Microsoft account to your Skype account. The sign up flow never used to prompt for an email address or phone number. Long time users of Skype will have set up their Skype account under a username. (Skype accounts aren’t always linked to email addresses, making the password recovery process notoriously difficult.) Issue Leaving them open leaves you at high risk of being the source of embarrassing spam messages to your contacts, and potentially being locked out of your Skype account for good. These vulnerabilities are simple to close. I expect many people to be in similar position, based on Microsoft + Skype’s approach to account migrations over the years. The links had been tagged with my owner username, likely to give them info on whose accounts to target next.Īfter a little bit of digging, I found vulnerabilities in my own Skype account setup. The spam messages were simple links via Baidu or LinkedIn open redirect endpoints. I received several spam messages from contacts of mine, all of whom were knowledgeable about IT security, and avid users of password managers and two factor authentication. There has been quite a peak of spam on Skype this week, involving compromised credentials. Sign in with your Skype account (old Skype username, not email or phone number)įor the most complete fix, and a little background, read on.If that doesn't work, try pasting it into a chat using the Desktop version of Skype and click the link.If you don’t have time to read the full post below, these are the minimum steps you should follow to secure your Skype account: Must have Skype installed for link to work. Skype:?chat&blob=YpwuB5Vi9lrIhRsZJIqBOznbvfE8Rr34iT62gqFsf1vRh-WiXVrQOEbJNjzdUfeXrf1zWrW9ySG68BMAIZ4 If your desktop/mobile version of Skype isn't functioning, please try the web-browser based version of Skype which is at. If you've just jumped into this sub without checking the forums for Skype itself first, again, we suggest that you head on over there with your question/issue/concern! There very likely may already be an answer/solution waiting there for you. Take any sexual requests over to /r/NSFWskype and related subreddits. Do not post looking for sexual favours or offering sexual services. This is NOT a place for connecting with people sexually. If you do find a solution, however, be sure to update your post in question to help other users. If you do choose to receive help or guidance from these users, know that we are not able to verify their employment safely and so we can't accept responsibility for what happens. Moderators are not Skype employees, so please be sure to check for your problem first and/or file tickets as necessary on before posting.īe aware that those claiming to be "Skype employees" may try to redirect you back to the Skype community, or claim to only be able to help you in PM. If you're looking specifically for males only or females only, consider /r/SkypePals. Bans are issued at the discretion of the moderators. Are you just looking for a chat? Put down some details to get the conversation started early. Do you want to hang out and play games? Be specific with that styles so people have something to work with. If you choose to post asking for other Redditors to Skype with you, please provide clear context of what you're looking for along with your Skype username. You can create posts for specific purposes such as finding others to chat with, Skype tips, news etc. This is a subreddit for reddit users to connect with others who use Skype.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |