Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

31–40 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#35

This wouldn't be the first time Microsoft has worked with the NSA https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

Given the context of this API, it would be of very little value to the NSA. (It is only accessible by applications that are already running on the user's computer, and only provides access to Skype.)

If the NSA wanted to intercept or forge Skype conversations and had access to Microsoft to do so, they would have a much easier time doing so on the server side.

Re: A Backdoor in Skype for Mac OS X

#36
post #24
post #6

Earlier quoted context omitted.

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

>You mean more paranoid interpretation. honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts. further, all the arguments against this interpre…

It seems to me to be a paranoid interpretation because if Microsoft wants to hand Skype-related user data over to the NSA, they'll do so on the server side and not the client side.

Secondly, this is a pretty stupid way of doing it. 'If you use this client identifier than anything goes' seems vastly more like a stupid coding mistake than it does a sneaky covert backdoor into accessing Skype from the local machine.

Re: A Backdoor in Skype for Mac OS X

#37
post #10

Earlier quoted context omitted.

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

Can you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?

NKW gave a nice summary of some recent actions. For more historical examples, I highly suggest any of James Bamford's excellent books on the NSA. _The Puzzle Palace_ is a massive tomb, but a very good read. I haven't had a chance to read _Shadow Factory_ yet, but it is in my pile.

Re: A Backdoor in Skype for Mac OS X

#38
post #10

Earlier quoted context omitted.

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

Can you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?

First of all, Skype is Microsoft. Second, they're well known to collaborate already. If NSA wanted a Skype feed, they could have it server or client side.

https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

Re: A Backdoor in Skype for Mac OS X

#39
post #21

Earlier quoted context omitted.

No. A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not. Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.

> Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought. Are you addressing me personally? What does that have to do with what I said? > A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. Isn't that the case here?

- Not you personally. I have experience with HN comments. Just covering my bases.

- No, it's not the case here. Unless you can prove it. There's no evidence it was done intentionally.

Re: A Backdoor in Skype for Mac OS X

#40
post #22

Earlier quoted context omitted.

No. A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not. Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.

Why is it that everything either has to be a blatant backdoor or an innocent mistake or tinfoil hat territory? I find it hard to believe that nobody ever wrote a backdoor and took the time to conceal it as an innocent, plausible mistake.

Alright, I'm burnt out and I don't want to think about work for a few mins, so:

I tire of the logic such as "well...what IF...someone...did that intentionally!" Then people think they're smarter than everyone else, using words like sheeple and such.

Shit happens. Merges fail. Teams miss stuff. I once randomly discovered a hole in a web app where data was being leaked from an ajax call without logging in. No conspiracy.

Yes, if I were a 1337 haxxor and I wanted to disguise a commit to, say, Linux for my backdoor I would disguise it as a mistake. Totally right, that would be smart and awesome. I'd have something to say on the next HN post of "What makes a Senior Software Engineer", because a junior engineer would not be this smart.

As an aside, long before the NSA reveals of 2013 there had been reports of back doors in skype. My clock skew causes me to forget how many years ago that was, but I'm gonna say somewhere 2005-2008. As 2013 passed, I thought back on that and laughed.

So yeah, Skype is backdoored. Is this one of them? Perhaps. Or it's yet another big corp fail. Orrrr...getting crazy now....it's a bug, but then it was discovered long ago by smart people and has been exploited. So it wasn't internal conspiracy, just a good find by some NSA dude.

Anyway. Back to my code.

Post reply on HN