Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

61–70 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#61
post #46
post #10

Earlier quoted context omitted.

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

You didn't respond to the substance of his objection. The problem with the "NSA backdoor" hypothesis is that it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer . If the NSA has installed software on your machine that it can control, you are going to, in the parlance of our times, "get Mossad'd".

> it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer.

Well, if you have any of the closed-source companies' software on your system (and by definition, that is +/- 310mio citizens, in the US alone), you are sure to have NSA backdoors on your system. Such backdoors certainly do not require manual intervention for them to be exploited on large scale.

Re: A Backdoor in Skype for Mac OS X

#62
post #38

Earlier quoted context omitted.

First of all, Skype is Microsoft. Second, they're well known to collaborate already. If NSA wanted a Skype feed, they could have it server or client side. https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

That collaboration looks like the same mechanism used to adhere to warrants, subpoenas, and NSLs. Do you think that any internet service in the world doesn't have similar mechanisms to comply with law enforcement requests in their home country? I think you are misleadingly using the word "collaboration". I also think you have failed to understand the article correctly; there is no reference to client side collection.…

Agreed. I'm just suggesting if someone were to ask for a client backdoor they could have one, just like they could ask for a server feed.

Re: A Backdoor in Skype for Mac OS X

#63

I've heard rumors that the Skype codebase is a giant mass of unmaintainable code "approaching a singularity" and for this reason alone you wouldn't expect it to be terribly secure. At one time I wondered if I was too paranoid for adding another user account for the sole purpose of running Skype, but I no longer wonder. That and the fact that OS X security is not fantastic to begin with, and I don't want anything weir…

> That and the fact that OS X security is not fantastic to begin with. Which OS do you use/prefer for better security?

Windows?

Re: A Backdoor in Skype for Mac OS X

#64
post #61
post #46

Earlier quoted context omitted.

You didn't respond to the substance of his objection. The problem with the "NSA backdoor" hypothesis is that it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer . If the NSA has installed software on your machine that it can control, you are going to, in the parlance of our times, "get Mossad'd".

> it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer. Well, if you have any of the closed-source companies' software on your system (and by definition, that is +/- 310mio citizens, in the US alone), you are sure to have NSA backdoors on your system. Such backdoors certainly do not require manual intervention for them to be exploited on large scale.

Explain?

Re: A Backdoor in Skype for Mac OS X

#65
post #21

Earlier quoted context omitted.

> Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought. Are you addressing me personally? What does that have to do with what I said? > A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. Isn't that the case here?

- Not you personally. I have experience with HN comments. Just covering my bases. - No, it's not the case here. Unless you can prove it. There's no evidence it was done intentionally.

When I say it was done intentionally, I mean opening an authentication-less was intentional.

It could be disguised as an access for their own service and the real purpose be mass surveillance, or it could be a simple mistake in a big codebase, but the "door" is definitely not a bug.

Even though nowadays we keep hearing about nefarious backdoors, they used to simply refer to hidden service entrances for software creators, a completely legitimate use.

Re: A Backdoor in Skype for Mac OS X

#66

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

The problem with this interpretation is Snowden.

If Snowden didn't happen I would most likely believe that this was just bad engineering or something.

Post Snowden your interpretation sounds like extremely naive.

Re: A Backdoor in Skype for Mac OS X

#67

I've heard rumors that the Skype codebase is a giant mass of unmaintainable code "approaching a singularity" and for this reason alone you wouldn't expect it to be terribly secure. At one time I wondered if I was too paranoid for adding another user account for the sole purpose of running Skype, but I no longer wonder. That and the fact that OS X security is not fantastic to begin with, and I don't want anything weir…

> That and the fact that OS X security is not fantastic to begin with. Which OS do you use/prefer for better security?

There's always a tradeoff. Windows and Linux can be locked down fairly well but you usually end up wanting to install programs of dubious origin. High-profile Linux distros with security-conscious maintainers are good choices, like Fedora or Debian.

I wouldn't touch Arch with a ten-foot pole, a combination of disastrous design decisions and maintainers that don't take reports of security vulnerabilities in default package configurations seriously has really soured any love I had for the distro once I got past the obnoxious fans and overtly hostile user experience. Arch is the only distro where I've made bug reports for security vulnerabilities and gotten asinine responses like "users should only install this package on trusted networks."

Re: A Backdoor in Skype for Mac OS X

#68
post #5
post #4

Earlier quoted context omitted.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).

In the "Athens" affair, most commentators dismissed CIA involvement saying that if the US gov needed the data, they could just ask.

Well after the investigation went through and some data came out regarding the Vodafone server hack it was clear that the organizations that could pull something like this, there like ... Maybe 5 with CIA the most likely candidate.

So, we like to oversimplify but life is way more complicated.

BTW I think that the Athens affair is one of the top 3 hacking stories that I know of.

Re: A Backdoor in Skype for Mac OS X

#69
post #54
post #52

Earlier quoted context omitted.

sure! Oh except for the fact that i linked an articule documenting skype specifically catering to NSA surveillance programs, and the NSA having a history of getting software to introduce vulnerabilities they can exploit... but hey, why not throw out the facts to pile on?

It's the facts that are the problem with your weird theory: this doesn't even make sense as an NSA backdoor. It only works if they've already backdoored your computer.

Does any NSA surveillance vulnerability stand up to logical scrutiny?

No, because introducing security vulnerabilities to keep us secure is inherently illogical.

Re: A Backdoor in Skype for Mac OS X

#70
post #69
post #54

Earlier quoted context omitted.

It's the facts that are the problem with your weird theory: this doesn't even make sense as an NSA backdoor. It only works if they've already backdoored your computer.

Does any NSA surveillance vulnerability stand up to logical scrutiny? No, because introducing security vulnerabilities to keep us secure is inherently illogical.

If this comment made sense to someone else who could rephrase it for me, I'd be grateful.
Post reply on HN