Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

51–60 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#51
post #47
post #24

Earlier quoted context omitted.

>You mean more paranoid interpretation. honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts. further, all the arguments against this interpre…

So far you haven't said anything more than "NSA exists, therefore all software insecurities are reasonably attributable to them".

[deleted]

Re: A Backdoor in Skype for Mac OS X

#52
post #47
post #24

Earlier quoted context omitted.

>You mean more paranoid interpretation. honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts. further, all the arguments against this interpre…

So far you haven't said anything more than "NSA exists, therefore all software insecurities are reasonably attributable to them".

sure! Oh except for the fact that i linked an articule documenting skype specifically catering to NSA surveillance programs, and the NSA having a history of getting software to introduce vulnerabilities they can exploit...

but hey, why not throw out the facts to pile on?

Re: A Backdoor in Skype for Mac OS X

#53

I've heard rumors that the Skype codebase is a giant mass of unmaintainable code "approaching a singularity" and for this reason alone you wouldn't expect it to be terribly secure. At one time I wondered if I was too paranoid for adding another user account for the sole purpose of running Skype, but I no longer wonder. That and the fact that OS X security is not fantastic to begin with, and I don't want anything weir…

> That and the fact that OS X security is not fantastic to begin with. Which OS do you use/prefer for better security?

Any not-too-common linux distribution with a recent kernel is probably a comparably good choice.

Re: A Backdoor in Skype for Mac OS X

#54
post #52
post #47

Earlier quoted context omitted.

So far you haven't said anything more than "NSA exists, therefore all software insecurities are reasonably attributable to them".

sure! Oh except for the fact that i linked an articule documenting skype specifically catering to NSA surveillance programs, and the NSA having a history of getting software to introduce vulnerabilities they can exploit... but hey, why not throw out the facts to pile on?

It's the facts that are the problem with your weird theory: this doesn't even make sense as an NSA backdoor. It only works if they've already backdoored your computer.

Re: A Backdoor in Skype for Mac OS X

#55

This wouldn't be the first time Microsoft has worked with the NSA https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

The article says the backdoor has been present for "5+ years". Microsoft's acquisition of Skype was completed in Oct. 2011 (just over 5 years ago). Based on the timing, that seems unlikely unless MS's first order of business was to backdoor Skype.

Re: A Backdoor in Skype for Mac OS X

#56

Earlier quoted context omitted.

> That and the fact that OS X security is not fantastic to begin with. Which OS do you use/prefer for better security?

Any not-too-common linux distribution with a recent kernel is probably a comparably good choice.

Less common = less attention to security.

Re: A Backdoor in Skype for Mac OS X

#57
post #56

Earlier quoted context omitted.

Any not-too-common linux distribution with a recent kernel is probably a comparably good choice.

Less common = less attention to security.

The train of thoughts here is that less common == smaller exposure, therefore less likely to be a target. Also, your statement isn't entirely true, for example, OpenBSD, albeit not being a linux distribution, is a project orders of magnitude smaller, yet with equal, if not greater, focus on security.

Re: A Backdoor in Skype for Mac OS X

#58
post #13

Calling this a backdoor is an extreme measure. I wasn't able to see any working example, nor any responsible disclosure which seems bad. Also, if somebody has the ability to run arbitrary code on your machine, I would think that it's game over at that point - backdoor or not. This is not a remote exploitable backdoor it seems.

This is unequivocally a backdoor, by definition. They backdoored their own API for the benefit of their own plugin being allowed to run unauthenticated.

What we can't say is whether this is a backdoor created for nefarious purposes. All we can say is that the backdoor exists and, if we accept that authentication on this API is valuable, then it's an egregious violation of security principles by effectively having some hardcoded credentials which bypass a security layer.

You can wave it away as local-only and claim that if you have code running on the box, it's already pwned, but this is rationalization: this backdoor bypasses a layer of security that is otherwise present. Can an otherwise unprivileged process (e.g. one from another user) call this API? The details are not specified.

I tend to think this looks more like incompetence perpetrated a long time ago and forgotten, but that doesn't make it any less of a back door.

Re: A Backdoor in Skype for Mac OS X

#59
post #24
post #6

Earlier quoted context omitted.

You mean more paranoid interpretation. Microsoft controls the servers, they don't need a client backdoor to access messages.

>You mean more paranoid interpretation. honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts. further, all the arguments against this interpre…

>further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic

Of course they do. You may disagree with the logic, but it's there. Vectors of intelligence gathering have to be both sufficiently covert and useful for an agency to consider. This vulnerability is neither.

Re: A Backdoor in Skype for Mac OS X

#60
post #5
post #4

Earlier quoted context omitted.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).

You forget that Skype used to be peer-to-peer.
Post reply on HN