Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"because Skype support didn't verify if the person owned the account or not, just wanted those 3 points mentioned above"

So, what? Is the author expecting Skype to just have some "does this person own the account" crystal ball? What do they want? If it's security questions, I don't consider those much of a solution because the questions tend to be very poor on the ratio of "things I can remember specifically" to "things people can't look up about me".



There is a huge difference between:

* poor security question, which is up to the user to choose

* poor account recovery policy which is Microsoft choice, is the same for all users and which the user cannot do anything about


One thing they could do is check if you're still logged in when you call up claiming to need account recovery.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: