Open Letter to Skype from Internet Activists, Journalists and Academics
31–40 of 70 posts
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#32Earlier quoted context omitted.
Skype has always relied on a central authentication server, which means that anyone with control of that server would be able to MITM any conversation. The recent changes of ownership and centralization of the service have nothing to do with this. Presumably the US government has been able to tap into any Skype conversation they want for a long time.
> would be able to MITM any conversation Sure, in theory. In practice, eavsdropping on two Skype users required presence on a network route between the callers, which might have been entirely in some random country's Internet segment.
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#33Whats the deal with Google voice and Google talk on this issue?
Not available in most countries in the world, perhaps?
personally i stopped using skype because i had issues on linux recently. google talk worked out of the box for me, and much much better
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#34Open comment to Internet Activists, Journalists and Academics: You're not going to get what you want by piggy-backing on Microsoft's proprietary platform. Specifically if you're an Internet Activists you shouldn't be relying on some company's proprietary tool for disguising your communications. There's plenty of open and secure VoIP clients which coupled with open encryption standards, VPN's etc. will suit your purpo…
I only know about Tor ( https://www.torproject.org ) which could help. I hope someone else can recommend any others.
Disclosure: I work there.
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#35Folks please try Discretio for Android ( https://play.google.com/store/apps/details?id=com.discretio.... ) Open source (GPLv3) secure VOIP solution. For the moment only Android version is available but iOS and desktop vresions are in the queue...
You can use the already-available ZRTP, that requires each user to speak a phrase to the other, so you can verify by hearing the other person's voice. Discretio doesn't do any of that, so how does it know you're not talking to some random attacker?
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#36Earlier quoted context omitted.
I only know about Tor ( https://www.torproject.org ) which could help. I hope someone else can recommend any others.
https://silentcircle.com/ aims to do just that, secure communications. Disclosure: I work there.
Although I remember reading about the lack of open source and the odd terms of service wording. http://log.nadim.cc/?p=89
Is that still being addressed?
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#37Earlier quoted context omitted.
skype just uses an http tunnel cause mostly the 80 port is open so no magic here(it does some more tricks but this is on). I dont think skype is easy just look at the UI... i dont like skype for linux it never works on my laptop...
I'm not keen on some of the recent changes to Skype but I don't really consider "Skype for Linux" to actually be Skype. Skype is actually the only reason beyond dev testing that I keep MS Windows. Skype for Linux is the only software I've installed in at least 8 years, AFAIR, that has crashed my desktop session.
It's the worst sort of bug, because it leads you to believe it's working fine, when it isn't. Skype for Linux is the reason I don't use Skype any more.
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#38Earlier quoted context omitted.
skype just uses an http tunnel cause mostly the 80 port is open so no magic here(it does some more tricks but this is on). I dont think skype is easy just look at the UI... i dont like skype for linux it never works on my laptop...
It's a bit smarter than just using an http tunnel. Skype is capable of direct client-to-client connections, despite intervening NAT. It's pretty clever -- with the server's help as coordinator, the clients both initiate the connection, causing their own NAT routers to accept the inbound packets from the other side.
Re: Open Letter to Skype from Internet Activists, Journalists and Academics
#39Earlier quoted context omitted.
https://silentcircle.com/ aims to do just that, secure communications. Disclosure: I work there.
Phil Zimmermann founded this? Nice. Although I remember reading about the lack of open source and the odd terms of service wording. http://log.nadim.cc/?p=89 Is that still being addressed?
I couldn't really respond about either, because I don't know, but I know that the Silent Text sources are on GitHub: https://github.com/SilentCircle/silent-text
The rest of the clients's code is probably being cleaned up, but I guess we're trying to build more functionality and are very busy with other stuff, and publishing the code has fallen behind a bit. That's just my guess, as, as I said, I don't work on that.
From what I've seen in my time there, though, everyone is extremely capable (I have yet to see a single thing that wasn't done correctly) and very focused on security (again, I have yet to find fault with something, and I'm really paranoid).
From what I've seen (and this probably comes off a bit too PR-y, but it's true), I have absolutely no problem trusting SC with my communications, everyone takes every precaution to safeguard users' data (even in the web part, we don't want to use third-party services, our analytics are hosted by us) to avoid compromising users' data.
Anyway, I've raved too long about this. I'll just say I'm very happy to work there.