Earlier quoted context omitted.
more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...
That is not at all a realistic interpretation. This is an 'authentication bypass' for a Skype API for locally executed code. Any even slightly serious attacker who has got to that point has already won - they don't need a 'Skype backdoor'.
A Backdoor in Skype for Mac OS X
11–20 of 112 posts
Re: A Backdoor in Skype for Mac OS X
#12Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.
more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...
EDIT: Also: http://www.cs.unc.edu/~fabian/papers/foniks-oak11.pdf
Re: A Backdoor in Skype for Mac OS X
#13Also, if somebody has the ability to run arbitrary code on your machine, I would think that it's game over at that point - backdoor or not. This is not a remote exploitable backdoor it seems.
Re: A Backdoor in Skype for Mac OS X
#14Earlier quoted context omitted.
If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).
Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…
Isn't it already disclosed in the Snowden documents that Skype has received NSLs?
Re: A Backdoor in Skype for Mac OS X
#15calling this a backdoor is pretty disingenous
Re: A Backdoor in Skype for Mac OS X
#16Earlier quoted context omitted.
That is not at all a realistic interpretation. This is an 'authentication bypass' for a Skype API for locally executed code. Any even slightly serious attacker who has got to that point has already won - they don't need a 'Skype backdoor'.
Are Mac OS apps unable to debug other applications or generally mess with their process space? If so, like on Windows, then this API is basically a courtesy and not a real security boundary in the first place.
Re: A Backdoor in Skype for Mac OS X
#17Re: A Backdoor in Skype for Mac OS X
#18calling this a backdoor is pretty disingenous
An access that bypasses regular security / auth, isn't that the definition of a backdoor?
Where it could instead be a bug or mistake that was not intentionally included.
Re: A Backdoor in Skype for Mac OS X
#19Earlier quoted context omitted.
That is not at all a realistic interpretation. This is an 'authentication bypass' for a Skype API for locally executed code. Any even slightly serious attacker who has got to that point has already won - they don't need a 'Skype backdoor'.
Are Mac OS apps unable to debug other applications or generally mess with their process space? If so, like on Windows, then this API is basically a courtesy and not a real security boundary in the first place.
Re: A Backdoor in Skype for Mac OS X
#20calling this a backdoor is pretty disingenous
An access that bypasses regular security / auth, isn't that the definition of a backdoor?
If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not.
Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.