Live data from Hacker News

Skype backdoor confirmation

lists.randombit.net

61–70 of 126 posts

Re: Skype backdoor confirmation

#61
The main problem is most of my friends (even those who are programmers) cannot be bothered to spend the 20 minutes picking up alternative software so I'm stuck with Skype and Facebook as my primary means of talking to people.

Re: Skype backdoor confirmation

#63

Earlier quoted context omitted.

No. No. No, no, no, no. These are two different things. One is a feature designed to allow them to check URLs, fetch thumbnails, etc. The other is a very pivotal core decision in how Skype works. Skype has always been primarily node-to-node. Doing p2p connections like that required signaling/directory services. In the past, users' computers were used for that functionality. After their purchase, Microsoft transitione…

I think you are missing the point - the article proves (unless the author is flat out lying) that text chat through skype, which is claimed to be end-to-end encrypted, is not, as requests are being made to the URL. It may currently be for innocent purposes (check URLs, thumbnails etc as you said). However the fact is that they can make these requests at all show that the encryption is not end-to-end, otherwise they w…

Or maybe the client forwards the URL to a Microsoft service which accesses it.

Re: Skype backdoor confirmation

#64
post #61

The main problem is most of my friends (even those who are programmers) cannot be bothered to spend the 20 minutes picking up alternative software so I'm stuck with Skype and Facebook as my primary means of talking to people.

Convenience for privacy. :)

Re: Skype backdoor confirmation

#65
post #42
post #25

Earlier quoted context omitted.

I don't think it's nitpicky at all - it would be different if Skype, Microsoft or anyone else had actually made a promise that messages that pass through their service are unreadable to them. While it's technically possible it's not the norm and it's hard to come up with examples of services that actually do make this promise - tarsnap is one that comes to mind.

Readable is one thing. Read and used is a completely different thing.

Is it? Gmail reads and uses all mail and this doesn't seem to have generated a great outburst of controversy.

Re: Skype backdoor confirmation

#66

I guess it's time for Google Hangouts to shine.

Why? I don't think it's encrypted in such a way that Google can't read it. References? I don't think you can trust Google with your chat and docs as well. From: http://www.wired.com/threatlevel/2010/09/google-spy/ >Google acknowledged Wednesday that two employees have been terminated after being caught in separate incidents allegedly spying on user e-mails and chats. >David Barksdale, 27, was fired in July after he r…

That actually shows that Google has privacy policies that are to be taken seriously by their own employees

Re: Skype backdoor confirmation

#67

I guess it's time for Google Hangouts to shine.

Why? I don't think it's encrypted in such a way that Google can't read it. References? I don't think you can trust Google with your chat and docs as well. From: http://www.wired.com/threatlevel/2010/09/google-spy/ >Google acknowledged Wednesday that two employees have been terminated after being caught in separate incidents allegedly spying on user e-mails and chats. >David Barksdale, 27, was fired in July after he r…

Shocking! You mean that nearly 3 years ago, a hosted service had employees that may have access to the databases of the services you're using?

The difference being that Google doesn't play at being encrypted end-to-end.

Re: Skype backdoor confirmation

#68
post #65
post #42

Earlier quoted context omitted.

Readable is one thing. Read and used is a completely different thing.

Is it? Gmail reads and uses all mail and this doesn't seem to have generated a great outburst of controversy.

Yeah, right.

While both Skype and Gmail store your messages (if you Skype across multiple devices, you'll see logs of conversations that happened on different devices), I don't think Gmail probes every URL you send in your messages. Also, SMTP is not always done under SSL, so, privacy cannot be assured.

But that's easily testable. I'll get back to you in a couple hours.

Re: Skype backdoor confirmation

#69
Checking URLs passed in messages isn't incompatible with secure communication. It's easy enough to look at a text message that's going to be sent and break it into parts (URL and non-URL). Encrypt point-to-point the non-URL parts, and encrypt the URL parts such that the central servers can read them (and verify that they're not pointing to bad stuff, which is a very valuable service to provide to the vast number of readers).

We might find somewhere in Skype's ToS a reference to URL checking, for any URLs you send through the service.

The URL checks could also be anonymized.

Re: Skype backdoor confirmation

#70
post #32

Earlier quoted context omitted.

I have reason to believe that you're wrong, because if you're under surveillance by the FBI or whatever, they will be able to read your mail. Unless you're the ultra-paranoid guy there are ways to get to your password physically :( (so, since you're coming up with GPG which i obviously was not referring to i can also come up with some unlikely scenario, ok?)

I can't really think of how one gets around that link. I'm not sure what you mean.

The point is that noone should act surprised because the laws already demand that communications can be intercepted and read.

Of course that excludes GPG (or pasting encrypted text into your skype chat). And that is only true as long as your law enforcement doesn't have you on surveillance. Or unless you can be 100% sure that the NSA really really really can't crack your encryption. And even Bruce Schneier isn't sure about that: https://www.schneier.com/blog/archives/2012/03/can_the_nsa_b...

Post reply on HN