Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

1–10 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#4

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of.

http://arstechnica.com/tech-policy/2014/12/newly-published-n...

Re: A Backdoor in Skype for Mac OS X

#5
post #4

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).

Re: A Backdoor in Skype for Mac OS X

#6
post #4

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

You mean more paranoid interpretation.

Microsoft controls the servers, they don't need a client backdoor to access messages.

Re: A Backdoor in Skype for Mac OS X

#7
post #4

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

That is not at all a realistic interpretation. This is an 'authentication bypass' for a Skype API for locally executed code. Any even slightly serious attacker who has got to that point has already won - they don't need a 'Skype backdoor'.

Re: A Backdoor in Skype for Mac OS X

#8

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

most likely, too -- we can go on about state involvement etc, but without evidence I think ockham's razor applies here.

Re: A Backdoor in Skype for Mac OS X

#9
post #6
post #4

Earlier quoted context omitted.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

But if they wanted plausible deniability when they get caught...

Re: A Backdoor in Skype for Mac OS X

#10
post #5
post #4

Earlier quoted context omitted.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what they want instead of showing up and serving the corporate entity with a NSL. Saying the organization as a whole could provide data exfiltration much more efficiently by other means, does not rule out the possibility that other techniques could be used instead for various non-technical reasons.
Post reply on HN