Live data from Hacker News

Skype backdoor confirmation

lists.randombit.net

21–30 of 126 posts

Re: Skype backdoor confirmation

#21

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

Isn't it only a problem if they actually use it to identify you.

If they just use it the same way that google uses gmail I fail to see the problem.

Re: Skype backdoor confirmation

#22

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

If you provide means for private communication, it's not preferred that it's private - it's a requirement.

Gentlemen don't read each others mail.

Re: Skype backdoor confirmation

#23

Earlier quoted context omitted.

Besides this hair-on-fire title and intro, this is pretty much just yet another rehashing that Skype visits URLs in chats? (Honestly, if you'd just asked, I would have been assumed this would have been the case anyway)

You are aware that many popular services allow to share stuff privately using URL encoded credentials?

Indeed.

Add this to the 1,000,000 other reasons why you should never use GET requests for authentication/verification.

Re: Skype backdoor confirmation

#24

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

Considering there was an article just a few days ago in NYTimes [1] claiming that "Skype is so secure because of its decentralization" that law enforcement tries to pass laws against it, I'd say a lot of people aren't aware that Microsoft does have access to all the information at this point thanks to their "super-nodes", but even NYTimes writers aren't aware of it (or maybe it was just a cloaked advertorial for Skype).

I'll also continue to say how extremely disappointed I am that none of the major IM players (not Google, not Apple, not Microsoft, not Yahoo, not Facebook) wants to implement OTR encryption in their chat apps. Google even removed their fake "OTR" from the new Hangouts app, which I believe only hid your logs from yourself, not from Google themselves.

[1] - http://www.nytimes.com/2013/05/17/business/concerns-arise-on...

Re: Skype backdoor confirmation

#25

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

I don't think it's nitpicky at all - it would be different if Skype, Microsoft or anyone else had actually made a promise that messages that pass through their service are unreadable to them.

While it's technically possible it's not the norm and it's hard to come up with examples of services that actually do make this promise - tarsnap is one that comes to mind.

Re: Skype backdoor confirmation

#26

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

A backdoor in their encryption protocol. They claim it is secure. "The Skype Security Policy is: ... 4. Messages transmitted through a Skype session are encrypted from Skype-end to Skype-end. No intermediary node, if any exist, has access to the meaning of these messages. [1]" [1]: http://download.skype.com/share/security/2005-031%20security... Aforementioned referenced on + additonal security overview/facade: http:/…

Oh, that quote from the security policy finally explains why this is so big news. MSN still doesn't use SSL and that's not big news in anyway. But MSN never promised to use end-to-end encryption...

Re: Skype backdoor confirmation

#27

Earlier quoted context omitted.

Besides this hair-on-fire title and intro, this is pretty much just yet another rehashing that Skype visits URLs in chats? (Honestly, if you'd just asked, I would have been assumed this would have been the case anyway)

You are aware that many popular services allow to share stuff privately using URL encoded credentials?

I'm thinking of building a WebRTC-based service to do just that, can you point me to an existing service that does similar things, so I don't waste my time? Thanks!

Re: Skype backdoor confirmation

#28
post #13

Very strange article. It only re-does what all other news sources already stated.. plus, i think that commonly a backdoor is understood as something in the software itself that let's someone get access from the outside, which doesn't appear to be the case. Plus, to think that skype would be exempt from the governments claim to get access to all communications and messaging data is very simple-minded. The guy does rea…

I have reason to believe that the government cannot access all my mails. But if it could, I’d be even happier, as it would either prove a fault in GPG (unlikely) or a working quantum computer implementing e.g. Shor’s algorithm. And who wouldn’t want to hear of the latter?

Re: Skype backdoor confirmation

#29
post #19

This is the company currently running ads positioning itself as a company that holds privacy dear. "At Microsoft, we take our responsibilities for protecting your privacy very seriously. It’s a priority across all our businesses, and an area where we continue to work closely with others throughout academia, government and industry." http://blogs.windows.com/ie/b/ie/archive/2013/04/22/consumer... "Your Privacy is Our…

That's the most annoying thing about Microsoft's campaigns. Sure they may be slightly better in some areas than Google, but overall they are just as bad, or worse than Google when it comes to privacy.

Maybe I'd get it if those campaigns came from Mozilla or DuckDuckGo (even though they are still done in poor taste, and resemble too much negative political campaigns), but Microsoft? I just can't take them seriously in regards to that. Microsoft is throwing stones from a glass house, and they should stop.

Re: Skype backdoor confirmation

#30

Earlier quoted context omitted.

You are aware that many popular services allow to share stuff privately using URL encoded credentials?

I'm thinking of building a WebRTC-based service to do just that, can you point me to an existing service that does similar things, so I don't waste my time? Thanks!

Everything?

Sharepoint, DropBox, Owncloud, LogMeIn, Flickr, Google Docs, et al.

Private/one-time-use URLs have been a "thing" since practically forever and they're all over the place.

Post reply on HN