Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

41–50 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#41
post #38

Earlier quoted context omitted.

Can you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?

First of all, Skype is Microsoft. Second, they're well known to collaborate already. If NSA wanted a Skype feed, they could have it server or client side. https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

That collaboration looks like the same mechanism used to adhere to warrants, subpoenas, and NSLs. Do you think that any internet service in the world doesn't have similar mechanisms to comply with law enforcement requests in their home country?

I think you are misleadingly using the word "collaboration".

I also think you have failed to understand the article correctly; there is no reference to client side collection. Take another look.

Re: A Backdoor in Skype for Mac OS X

#43
post #6

Earlier quoted context omitted.

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

Exactly right. Skype used to do peer-to-peer connections with nobody in the middle. If you knew how to modify the port forwarding configuration of your router, you could get very high quality connections. Now, everything goes through Microsoft servers where it can be conveniently wiretapped.

Skype used to do that ... with an obfuscated proprietary software blob. There's no reason to think they didn't have the ability to reroute on demand.

Re: A Backdoor in Skype for Mac OS X

#44
post #26

Earlier quoted context omitted.

Can you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?

Here is a recent article discussing the DEA doing this: https://www.washingtonpost.com/news/powerpost/wp/2016/09/30/... $600k to a particular airline employee, $1 million for a single parcel worker (this was over a few years). Also there is the various NSA efforts to insert people into the encryption standards process, as well as use cooperative sources within companies to insert vulnerabilities in the commercial enc…

The DEA program is pretty shocking and a great example, thanks for sharing!

The second one sounds more like an interdiction program, where vulnerabilities are inserted into the devices (this is a thing that was in the Snowden documents). The document gives no details. The highlights on the side are from an NYT journalist, not source material.

I disagree that the last example is an example of that. It's still unclear what the scanning was doing.

Re: A Backdoor in Skype for Mac OS X

#45
post #23

Earlier quoted context omitted.

'backdoor' comes with the implication that it was included intentionally to allow for future (secret) access. Where it could instead be a bug or mistake that was not intentionally included.

Maybe I misunderstood the current situation? Of course other services exploiting it isn't intentional, but giving a free pass to one of their own services was definitely intentional?

The article mentions: "the actual Skype Dashboard widget does not seem to utilize the backdoor into the Skype Desktop API despite the name" which, to me, lends more credence to the assumption that this was perhaps a test or a prototype and only included in the shipped version accidentally.

Re: A Backdoor in Skype for Mac OS X

#46
post #10
post #5

Earlier quoted context omitted.

If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

You didn't respond to the substance of his objection. The problem with the "NSA backdoor" hypothesis is that it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer. If the NSA has installed software on your machine that it can control, you are going to, in the parlance of our times, "get Mossad'd".

Re: A Backdoor in Skype for Mac OS X

#47
post #24
post #6

Earlier quoted context omitted.

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

>You mean more paranoid interpretation. honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts. further, all the arguments against this interpre…

So far you haven't said anything more than "NSA exists, therefore all software insecurities are reasonably attributable to them".

Re: A Backdoor in Skype for Mac OS X

#48
post #13

Calling this a backdoor is an extreme measure. I wasn't able to see any working example, nor any responsible disclosure which seems bad. Also, if somebody has the ability to run arbitrary code on your machine, I would think that it's game over at that point - backdoor or not. This is not a remote exploitable backdoor it seems.

> Calling this a backdoor is an extreme measure.

How else would you call the possibility to sidestep access controls by setting a specific string as identifier?

> I wasn't able to see any working example, nor any responsible disclosure which seems bad. First, those two statements kind of contradict each other. Second, from the advisory linked from the article:

    10/13/2016 - Vulnerability disclosed to vendor
    10/26/2016 - Patch released by vendor
    12/12/2016 - Advisory published
> Also, if somebody has the ability to run arbitrary code on your machine, I would think that it's game over at that point.

Yes, it has been game over all the time: People execute arbitrary code on their machines by installing free programs they downloaded from somewhere. But that's not the point. The point is that some application that has control over very sensitive data includes a possibility (to avoid the word "backdoor") to access that data without user-confirmation and alarms, which are otherwise built into the application on a design level.

Re: A Backdoor in Skype for Mac OS X

#49
I've heard rumors that the Skype codebase is a giant mass of unmaintainable code "approaching a singularity" and for this reason alone you wouldn't expect it to be terribly secure. At one time I wondered if I was too paranoid for adding another user account for the sole purpose of running Skype, but I no longer wonder.

That and the fact that OS X security is not fantastic to begin with, and I don't want anything weird showing up in screen sharing with job interviews (say, in search history).

Re: A Backdoor in Skype for Mac OS X

#50

I've heard rumors that the Skype codebase is a giant mass of unmaintainable code "approaching a singularity" and for this reason alone you wouldn't expect it to be terribly secure. At one time I wondered if I was too paranoid for adding another user account for the sole purpose of running Skype, but I no longer wonder. That and the fact that OS X security is not fantastic to begin with, and I don't want anything weir…

> That and the fact that OS X security is not fantastic to begin with.

Which OS do you use/prefer for better security?

Post reply on HN