Live data from Hacker News

Skype protocol reverse engineered, source available

skype-open-source.blogspot.com

91–100 of 145 posts

Re: Skype protocol reverse engineered, source available

#91
post #20

How easy is it for skype to change the protocol?

Not very easy if they want to maintain compatibility with existing clients (especially considering they haven't updated their linux client for years now).

Backwards compatibility with linux clients probably isn't the top priority of Skype now that they're being rolled into MS, but I suspect embedded deployments on handheld devices might still keep them from deprecating.

Re: Skype protocol reverse engineered, source available

#92
post #78
post #70

Earlier quoted context omitted.

I think you actually want two answers, the question you asked and "why report it?" The IDA Pro disassembler and the Hex-Rays decompiler are not only very expensive tools, but they are very difficult to purchase. Due to constant problems with piracy, these days they will only sell their products to three areas; (1) governments/law enforcement, (2) very well established corporations (typically well known security resea…

Thanks for your insight. The spelling errors in the blog posts aren't the hallmark of professionalism either, but what about the information in comment header? /*\ |*| |*| Skype 4142 Decompression v1.002 by Sean O'Neil. |*| Copyright (c) 2004-2009 by VEST Corporation. |*| All rights reserved. Strictly Confidential! |*| |*| Date: 29.10.2009 |*| \*/ is this just a special brand of stupid? edit: some info about this cor…

yeah, the author of the blog post said the stuff he has came from VEST. so it's basically a POC based on the code released 2 years ago. if you google it there's a blog post by some other random guy who made a python plugin and some POC code from that stuff too

Re: Skype protocol reverse engineered, source available

#93
post #80

Earlier quoted context omitted.

> How about instead of trying to fruitlessly crack Skype, we spend the time making something that's both open and better? There's value in making an open client that works with the existing network (for example, Microsoft recently killed the Skype integration plug-in for Asterix).

"Asterisk"

yes, that.

Re: Skype protocol reverse engineered, source available

#96
post #94
post #88

Earlier quoted context omitted.

[deleted]

[deleted]

That is simply incorrect. I do not "know" Ilfak. I just emailed him, discussed the cost of a student license, provided proof of being a student, and filed an order form for IDA Pro Standard 6.0. The only thing that at all fits with your story is that a bank transfer was required, instead of paying by credit card, but I believe that is only for students.

Even so, Hex-Rays does sell to individuals. It's not even necessary to ask Ilfak: if copies are being sold to individuals, then they sell to individuals. And those copies are being sold. Here's a picture of my CD, purchased this year, as an individual: http://dl.dropbox.com/u/3177211/idaomg.png

Re: Skype protocol reverse engineered, source available

#98
post #46

Earlier quoted context omitted.

HN is an internationally read site. Things that are illegal in some countries are not illegal in others. As responsible citizens, it is up to the individual to not engage in illegal activities in the region said individual is in.

I think you misread my statement. I should have been more clear, but if you read it again, you'll see I agree with you. It is interesting and belongs here.

I don't have to not admit it, but your failure to not use double negatives caused me to not be unconfused.

Just a bit.

Re: Skype protocol reverse engineered, source available

#100
post #16

Earlier quoted context omitted.

I think it's fair to surmise that those intelligence agencies that care have probably had the algorithm for a long time and searched for weaknesses. Bear in mind that at one time they were complaining about it's use by criminals to avoid phonetaps.

There has been some speculation about a backdoor in Skype which it has shared with intelligence agencies. Never confirmed by Skype of course. But this could allow anyone to decrypt a Skype conversation stream. All you need is a Skype supernode to get started. Or some kind of spyware on the subject's computer which stores/transmits the data stream.

If it had a backdoor, it should be visible in the decompiles, right? Of course it could be rather obfuscated, but still, careful analysis could prove either way.
Post reply on HN