Live data from Hacker News

Skype replaces P2P supernodes with Linux boxes hosted by Microsoft

arstechnica.com

101–107 of 107 posts

Re: Skype replaces P2P supernodes with Linux boxes hosted by Microsoft

#101

Earlier quoted context omitted.

Unless a significant number of paying users decide that they don't want their calls going through a US company with a history of security and monopoly issues. So you should now assume that ALL your skype calls are being recorded and monitored and anything of interest to the US authorities is now available to them ? Are you doing anything in the US that might be considered naughty - like online gambling, tax 'optimiza…

The biggest change occurred when Skype sold to a US corporation. That ship has sailed. P2P or not, Skype became a US company when it sold to MS. Even before that, you never had any guarantees about where/who your calls were routed to/through. "So you should now assume that ALL your skype calls are being recorded and monitored and anything of interest to the US authorities is now available to them ?" Unless the networ…

Yes Skype was never exactly mil-spec but was generally regarded as safer than email or regular phones as far as routine interception was concerned.

IIRC with the original design the supernodes were only used to discover where users were and so tunnel through firewalls . Once the end points of a call had been discovered the voice traffic was direct caller-caller.

Assuming that Skype hasn't been a front for the illuminati all along, then the big change of having all the supernodes under one roof is that all the call endpoints can be routinely monitored and so if there was a future requirement to tap all the voice data it would be easier to pick which links to monitor.

Re: Skype replaces P2P supernodes with Linux boxes hosted by Microsoft

#102

Let me just make this very clear: you don't go from zero operating cost to multiple millions of hardware and colo space to do the very same thing, in a move so transparent that it needs security researchers to dig into your program to find out it has happened at all. I guess Skype (by extension, Microsoft) is growing interested in what people are speaking about. To get hold of that data you need to route it through y…

Isn't there some encryption involved?

Yes but: 1, the encryption algorithms are secret, so we don't know how good they are and 2, Skype have the keys

Re: Skype replaces P2P supernodes with Linux boxes hosted by Microsoft

#103
post #99

Earlier quoted context omitted.

Say what now? It always seemed to do that quite fine for me. If a client drops off, I can still send messages, and they'll sit in the window with the little "working" circle next to t hem. The partner picks them up when they reconnect. I've logged in more than once to have a metric ton of IM's waiting for me.

But if you send a message they won't see your message until you're both online again. So if you sign off before you sign on, it won't send until both clients are online again (could be days). If you use multiple computers it gets worse - if you send the message from your laptop it won't go through until the laptop and your friend are online again. Its not a huge problem with a 1 on 1 chat, but with groups its frustra…

Ahhhh, gotcha. I see what you're getting at now.

It's kind of odd that they don't - messages are stored server side (have a bunch of conversations and then sign into an empty skype elsewhere - open chats are synched). You'd think this would be trivial to add.

Re: Skype replaces P2P supernodes with Linux boxes hosted by Microsoft

#104

Earlier quoted context omitted.

The biggest change occurred when Skype sold to a US corporation. That ship has sailed. P2P or not, Skype became a US company when it sold to MS. Even before that, you never had any guarantees about where/who your calls were routed to/through. "So you should now assume that ALL your skype calls are being recorded and monitored and anything of interest to the US authorities is now available to them ?" Unless the networ…

Yes Skype was never exactly mil-spec but was generally regarded as safer than email or regular phones as far as routine interception was concerned. IIRC with the original design the supernodes were only used to discover where users were and so tunnel through firewalls . Once the end points of a call had been discovered the voice traffic was direct caller-caller. Assuming that Skype hasn't been a front for the illumin…

> Yes Skype was never exactly mil-spec but was generally regarded as safer than email or regular phones as far as routine interception was concerned.

And wrongly so. You still logged in through Skype servers (username/password is centrally managed) who would direct you to a supernode near you, and could equally direct you to an intercepting supernode.

You have just made the fallacious argument of security through obscurity.

> Once the end points of a call had been discovered the voice traffic was direct caller-caller.

Do you know that, or just assume that? Do you know that this hasn't changed with different versions?

> Assuming that Skype hasn't been a front for the illuminati all along,

Blackberry insisted that they can't decrypt end-user communication ... right until the Indian government threatened to make it illegal to use Blackberry in India, and magically it became possible to eavesdrop on BB comm.

Corrupt governments are enough, don't need to invoke the illuminati.

> then the big change of having all the supernodes under one roof is that all the call endpoints can be routinely monitored and so if there was a future requirement to tap all the voice data it would be easier to pick which links to monitor.

It's not any different. The voice links were (mostly) P2P, and I guess they still are. The supernodes (discovery/comm links) were centrally managed, and still are. The only difference is now they are both centrally managed and centrally owned - that's a very little difference.

Re: Skype replaces P2P supernodes with Linux boxes hosted by Microsoft

#106
post #79

Good to see the grsecurity patch getting a bit of publicity. I think for critical devices it's an essential patch, mostly because of it's integration with the PaX patch which is aimed at preventing many different types of memory overflow exploits.

You can use PaX standalone tho. I'd like to know if they used GrSecurity's RBAC or if they just used the patch and that was that.

Or downvoted for no reason. haha.

That's PaX standalone: http://grsecurity.net/~paxguy1/

Re: Skype replaces P2P supernodes with Linux boxes hosted by Microsoft

#107
post #62

Earlier quoted context omitted.

The brilliant and problematic property of the translation (and why I think it will catch up) is that it allows to easily make your today's problems someone else's problems five years down the road. Noone gives a ding about what happens in five years in one's network - let alone the larger internet. BTW, next time you talk with the "address-hiding security" fans, check what result they get from http://panopticlick.eff…

I'm one of those "address-hiding security" fans - I've architected and deployed more than 7 million (currently operational) IPv6 nodes, 100% of them in RFC 4193 space. We have many layers of security. Link Layer Security, Application Layer Security, Firewall Security, IPsec Security, App Transport Security in addition to the non-routability security. I've never understood security professional who turn their nose up…

> I would rather optimize for security than ease of two-way communication with external entities.

So in case of your networks Skype traffic will go though third-party servers ...

Post reply on HN