Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

81–90 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#81

Most generous interpretation: this could easily be an old, deprecated API in an enormous, complicated codebase on an engineering team with high turnover.

The backdoor allows access to the Skype application which is running in the same environment as the process 'abusing' it.

It's stupid programming and perhaps could be used for convenience by a worm or virus but it does not allow privilege escalation.

Worst case scenario there is a bug in the API that allows privilege escalation, then it might be a sandbox escape, if it is possible to use the API from inside the sandbox which I doubt.

Re: A Backdoor in Skype for Mac OS X

#82

Earlier quoted context omitted.

> That and the fact that OS X security is not fantastic to begin with. Which OS do you use/prefer for better security?

There's always a tradeoff. Windows and Linux can be locked down fairly well but you usually end up wanting to install programs of dubious origin. High-profile Linux distros with security-conscious maintainers are good choices, like Fedora or Debian. I wouldn't touch Arch with a ten-foot pole, a combination of disastrous design decisions and maintainers that don't take reports of security vulnerabilities in default pa…

Arch is really the Libertarian's distro. Caveat Emptor :)

Re: A Backdoor in Skype for Mac OS X

#83
post #10
post #5

Earlier quoted context omitted.

If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

[deleted]

Re: A Backdoor in Skype for Mac OS X

#84
post #5
post #4

Earlier quoted context omitted.

more realistic interpretation: Intentional backdoor for NSA programs as skype has already been shown to be a part of. http://arstechnica.com/tech-policy/2014/12/newly-published-n...

If Skype wanted to give user data to the NSA, they would send it over from their servers instead of implementing a backdoor that requires the NSA to already already have software on the target's computer (at which point, assuming they managed to get root, they could circumvent whatever protections Skype was using anyway).

Skype used to be a peer-to-peer application and did not use nor require any "central" servers.

Then, Microsoft bought it and that all changed.

Re: A Backdoor in Skype for Mac OS X

#85
post #38

Earlier quoted context omitted.

Can you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?

First of all, Skype is Microsoft. Second, they're well known to collaborate already. If NSA wanted a Skype feed, they could have it server or client side. https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

Originally, and perhaps at the time this "backdoor" was created, Skype wasn't Microsoft.

Skype was around for along time before Microsoft bought it and changed its architecture and design.

Re: A Backdoor in Skype for Mac OS X

#86
post #75

The backdoor aside, but using Skype seems to be a real pain recently. It used to be something that offered unmatched quality and service, but with time passing it is lagging behind. Skype on Mac OS X now starts like in 10 seconds and even the shutdown takes 10-15 seconds (on SSD). Video calls are fine, but the fans are quickly 100%. It's funny but the (long unmaintened) Linux skype seems to be better at video calls.…

Skype for Business, the Lync replacement, is equally if not more of a mess. You can break conference calls just by muting people.

Re: A Backdoor in Skype for Mac OS X

#87
post #70
post #69

Earlier quoted context omitted.

Does any NSA surveillance vulnerability stand up to logical scrutiny? No, because introducing security vulnerabilities to keep us secure is inherently illogical.

If this comment made sense to someone else who could rephrase it for me, I'd be grateful.

I think he means 'if nsa were logical actors, they would patch vulnerabilities, not leave them to be exploited by anyone, and they would use NSLs/collaborators/special NSA Voodoo to get their data'.

This idea is built on the assumption that (1) they think their defensive role is as vital as their offensive one, (2) there is plenty of special NSA voodoo to go round. Which is false. In particular, it is better that a hack come from a vendor vuln that anybody could find than from crypto wizardry (e.g. Logjam or signed drivers with md5 collisions).

Re: A Backdoor in Skype for Mac OS X

#88
post #10

Earlier quoted context omitted.

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

Can you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?

How do you think that Juniper VPN compromise got inserted into the code?

Re: A Backdoor in Skype for Mac OS X

#89
post #38

Earlier quoted context omitted.

First of all, Skype is Microsoft. Second, they're well known to collaborate already. If NSA wanted a Skype feed, they could have it server or client side. https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

Originally, and perhaps at the time this "backdoor" was created, Skype wasn't Microsoft. Skype was around for along time before Microsoft bought it and changed its architecture and design.

This. It could well have been a backdoor that predates the "superpeer" change MS introduced right after acquisition. Skype was already under pressure from European authorities at the time, to provide intercept capabilities; European criminal networks (mafia etc) were early adopters and everybody knew it.

Re: A Backdoor in Skype for Mac OS X

#90
post #26

Earlier quoted context omitted.

Here is a recent article discussing the DEA doing this: https://www.washingtonpost.com/news/powerpost/wp/2016/09/30/... $600k to a particular airline employee, $1 million for a single parcel worker (this was over a few years). Also there is the various NSA efforts to insert people into the encryption standards process, as well as use cooperative sources within companies to insert vulnerabilities in the commercial enc…

The DEA program is pretty shocking and a great example, thanks for sharing! The second one sounds more like an interdiction program, where vulnerabilities are inserted into the devices (this is a thing that was in the Snowden documents). The document gives no details. The highlights on the side are from an NYT journalist, not source material. I disagree that the last example is an example of that. It's still unclear…

The Yahoo thing is a huge deal. Email providers do interception all of the time and have strong procedural controls.

The idea that people could bypass those processes and controls is a tremendous liability that no board would ever approve.

Post reply on HN