Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

21–30 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#21
post #15

Earlier quoted context omitted.

An access that bypasses regular security / auth, isn't that the definition of a backdoor?

No. A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not. Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.

> Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.

Are you addressing me personally? What does that have to do with what I said?

> A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access.

Isn't that the case here?

Re: A Backdoor in Skype for Mac OS X

#22
post #15

Earlier quoted context omitted.

An access that bypasses regular security / auth, isn't that the definition of a backdoor?

No. A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not. Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.

Why is it that everything either has to be a blatant backdoor or an innocent mistake or tinfoil hat territory? I find it hard to believe that nobody ever wrote a backdoor and took the time to conceal it as an innocent, plausible mistake.

Re: A Backdoor in Skype for Mac OS X

#23
post #15

Earlier quoted context omitted.

An access that bypasses regular security / auth, isn't that the definition of a backdoor?

'backdoor' comes with the implication that it was included intentionally to allow for future (secret) access. Where it could instead be a bug or mistake that was not intentionally included.

Maybe I misunderstood the current situation? Of course other services exploiting it isn't intentional, but giving a free pass to one of their own services was definitely intentional?

Re: A Backdoor in Skype for Mac OS X

#24
post #6
post #4

Earlier quoted context omitted.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

>You mean more paranoid interpretation.

honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application

Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts.

further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic - which by the very nature of such activities they demonstrate that they do not. They (3 letter agencies) want every possible vector of information gathering regardless of the privacy, security, and legal issues that arise.

Re: A Backdoor in Skype for Mac OS X

#25
post #8

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

most likely, too -- we can go on about state involvement etc, but without evidence I think ockham's razor applies here.

I think it's more in Hanlon's razor territory than Ockham's razor. It's absolutely not unheard-of to see deliberate backdoors in a lot of commercial software (usually as some debugging port that the devs didn't think anyone would find), but it's just much more likely that it's a product of incompetence than malice.

Re: A Backdoor in Skype for Mac OS X

#26
post #10

Earlier quoted context omitted.

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

Can you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?

Here is a recent article discussing the DEA doing this: https://www.washingtonpost.com/news/powerpost/wp/2016/09/30/...

$600k to a particular airline employee, $1 million for a single parcel worker (this was over a few years).

Also there is the various NSA efforts to insert people into the encryption standards process, as well as use cooperative sources within companies to insert vulnerabilities in the commercial encryption systems:

http://www.nytimes.com/interactive/2013/09/05/us/documents-r...

Also the FBI/Yahoo email program was apparently done by just the CEO, a lawyer, and a few members of the email team. The security team wasn't informed, nor the board.

https://www.theguardian.com/technology/2016/oct/04/yahoo-sec...

Re: A Backdoor in Skype for Mac OS X

#27
post #6
post #4

Earlier quoted context omitted.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

Exactly right. Skype used to do peer-to-peer connections with nobody in the middle. If you knew how to modify the port forwarding configuration of your router, you could get very high quality connections.

Now, everything goes through Microsoft servers where it can be conveniently wiretapped.

Re: A Backdoor in Skype for Mac OS X

#28
post #24
post #6

Earlier quoted context omitted.

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

>You mean more paranoid interpretation. honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts. further, all the arguments against this interpre…

Just because it has happened doesn't mean it's always happening. Without any proof of intent, yeah, I'd consider it (plausible?) paranoia.

Re: A Backdoor in Skype for Mac OS X

#29
post #22

Earlier quoted context omitted.

No. A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not. Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.

Why is it that everything either has to be a blatant backdoor or an innocent mistake or tinfoil hat territory? I find it hard to believe that nobody ever wrote a backdoor and took the time to conceal it as an innocent, plausible mistake.

I agree! It's absolutely possible that a clever person would disguise an intentional backdoor as an innocent mistake.

As the two can't be distinguished at first blush, the wise approach is to adopt an innocent-until-proven-guilty approach. Which is to say assume it's an accident until it can be proven intentional. This way, both possibilities are taken seriously without jumping from zero all the way to tinfoil at the drop of a hat.

Post reply on HN