Live data from Hacker News

Skype backdoor confirmation

lists.randombit.net

1–10 of 126 posts

Re: Skype backdoor confirmation

#2
This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted.

I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. accessing URLs) is a problem (and arguably illegal, given the recent case about someone accessing insecured AT&T URLs and going to jail).

Just think the original title could have been more clear.

Re: Skype backdoor confirmation

#6

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

Seconded. It's more a man in the middle to me. Still a problem, though.

Re: Skype backdoor confirmation

#7
post #4

Could someone help me understand why the password changed from "bar" to "yeahright"? Or is that just a mistake on the authors side?

He probably typed out the string in the paragraph and copy-pasted the logs, so likely it is just a mistake on the author’s side.

Re: Skype backdoor confirmation

#8

That article was nonsensical. English probably isn't their first language, but I have no idea what they're saying.

The slang is very common in crypto* newsgroups of these sorts, I didn't find anything unusual or un-parseable in the message.

Re: Skype backdoor confirmation

#9

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

A backdoor in their encryption protocol. They claim it is secure.

"The Skype Security Policy is: ... 4. Messages transmitted through a Skype session are encrypted from Skype-end to Skype-end. No intermediary node, if any exist, has access to the meaning of these messages. [1]"

[1]: http://download.skype.com/share/security/2005-031%20security...

Aforementioned referenced on + additonal security overview/facade: http://www.skype.com/en/security/#encryption

Their hybrid peer-to-peer/client–server implementation allows for eavesdropping. This is now confirmed to be in practice.

Re: Skype backdoor confirmation

#10
Don't be surprised. While I can see 2 sides to this argument (it was discussed earlier here on HN, link below), we shouldn't be too surprised by what some companies do to "optimize," their products. Microsoft autocrawling http(s) links could be either for obtaining new bing search results (and it could make that result relative to your conversation), or it could be for security to screen links.

I don't know, but I agree that if you have a secret conversation, take steps like PGP to keep it secret. Big Brother is ALWAYS listening :: usually a good preventative security motivation ;)

https://news.ycombinator.com/item?id=5721006

Post reply on HN