Live data from Hacker News

Skype backdoor confirmation

lists.randombit.net

71–80 of 126 posts

Re: Skype backdoor confirmation

#71

Earlier quoted context omitted.

You can only encode credentials in a URL via GET. Therefore if people stop using GET and start using POST (aka forms) for authentication this issue goes away. Even just a simple pin. GET issues are primarily related to the fact that an attacker can automate their access. So they could trick a user into going to a specially crafted site, and then request content on that user's behalf via GET forgery, and return it to…

you are also ruling out HTTP auth, yes?

In the context of this discussion I am.

Re: Skype backdoor confirmation

#72
post #68
post #65

Earlier quoted context omitted.

Is it? Gmail reads and uses all mail and this doesn't seem to have generated a great outburst of controversy.

Yeah, right. While both Skype and Gmail store your messages (if you Skype across multiple devices, you'll see logs of conversations that happened on different devices), I don't think Gmail probes every URL you send in your messages. Also, SMTP is not always done under SSL, so, privacy cannot be assured. But that's easily testable. I'll get back to you in a couple hours.

I am struggling to under the distinction you're trying to portray.

One automatically scans your email to show related ads, another does a HTTP HEAD request to URLs for only the server headers, which they say is for malware scanning purposes. Both are automated jobs.

See my other post to see how Google employees have access to all your email, documents, chat transcripts, Google Voice calls, Youtube videos etc. and how a few abused it to stalk teens.

https://news.ycombinator.com/item?id=5728707

As usual, Google gets a free pass and Microsoft gets demonized(they should stop claiming it's end to end encrypted, though). Looking at your HN profile, it's not hard to understand why. Thanks for being honest about disliking Microsoft but please try not to let that color your objective opinions and playing favorites regardless of facts.

Re: Skype backdoor confirmation

#74
I'm not sure how this or the original article are "discoveries". Per the skype privacy policy, they are receiving and storing just about everything:

(from http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa...)

Retention of Instant Messages, Voicemail Messages, and Video Messages (Skype internet communications software application only)

Your instant messaging (IM), voicemail, and video message content (collectively “messages”) may be stored by Skype (a) to convey and synchronize your messages and (b) to enable you to retrieve the messages and history where possible. Depending on the message type, messages are generally stored by Skype for a maximum of between 30 and 90 days unless otherwise permitted or required by law. This storage facilitates delivery of messages when a user is offline and to help sync messages between user devices...

From Section 8 of that same document:

Skype may use automated scanning within Instant Messages and SMS to (a) identify suspected spam and/or (b) identify URLs that have been previously flagged as spam, fraud, or phishing links. In limited instances, Skype may capture and manually review instant messages or SMS in connection with Spam prevention efforts.

Re: Skype backdoor confirmation

#75
post #63

Earlier quoted context omitted.

I think you are missing the point - the article proves (unless the author is flat out lying) that text chat through skype, which is claimed to be end-to-end encrypted, is not, as requests are being made to the URL. It may currently be for innocent purposes (check URLs, thumbnails etc as you said). However the fact is that they can make these requests at all show that the encryption is not end-to-end, otherwise they w…

Or maybe the client forwards the URL to a Microsoft service which accesses it.

If it did this, then it can forward the chat conversation as well

Re: Skype backdoor confirmation

#76
post #24

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

Considering there was an article just a few days ago in NYTimes [1] claiming that "Skype is so secure because of its decentralization" that law enforcement tries to pass laws against it, I'd say a lot of people aren't aware that Microsoft does have access to all the information at this point thanks to their "super-nodes", but even NYTimes writers aren't aware of it (or maybe it was just a cloaked advertorial for Skyp…

But the whole purpose of the new handouts app is that all clients are syncd. That's kind of hard if 3rd party apps don't have the same ability. Then all you're left with is useless encrypted messages.

Re: Skype backdoor confirmation

#77

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

A backdoor in their encryption protocol. They claim it is secure. "The Skype Security Policy is: ... 4. Messages transmitted through a Skype session are encrypted from Skype-end to Skype-end. No intermediary node, if any exist, has access to the meaning of these messages. [1]" [1]: http://download.skype.com/share/security/2005-031%20security... Aforementioned referenced on + additonal security overview/facade: http:/…

The document you are referring to is from 2005. It is no longer end-to-end encrypted. Microsoft not only can intercept your communications, but in fact stores them for 30-90 days per their publicly posted privacy policy.

http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa...

(this apparently does not apply to voice calls, but either does the complaint that they are picking up URLs and visiting them).

Re: Skype backdoor confirmation

#78
post #32

Earlier quoted context omitted.

I have reason to believe that the government cannot access all my mails. But if it could, I’d be even happier, as it would either prove a fault in GPG (unlikely) or a working quantum computer implementing e.g. Shor’s algorithm. And who wouldn’t want to hear of the latter?

I have reason to believe that you're wrong, because if you're under surveillance by the FBI or whatever, they will be able to read your mail. Unless you're the ultra-paranoid guy there are ways to get to your password physically :( (so, since you're coming up with GPG which i obviously was not referring to i can also come up with some unlikely scenario, ok?)

Obligatory xkcd comic. http://xkcd.com/538/

Re: Skype backdoor confirmation

#79

Earlier quoted context omitted.

Why? I don't think it's encrypted in such a way that Google can't read it. References? I don't think you can trust Google with your chat and docs as well. From: http://www.wired.com/threatlevel/2010/09/google-spy/ >Google acknowledged Wednesday that two employees have been terminated after being caught in separate incidents allegedly spying on user e-mails and chats. >David Barksdale, 27, was fired in July after he r…

Shocking! You mean that nearly 3 years ago, a hosted service had employees that may have access to the databases of the services you're using? The difference being that Google doesn't play at being encrypted end-to-end.

>You mean that nearly 3 years ago, a hosted service had employees that may have access to the databases of the services you're using?

"may have access"? That's some nice word play there. Please read the articles. Also, do you have any reason to believe that Google employees can't read your email and documents right now? i.e Have things changed in three years?

>The difference being that Google doesn't play at being encrypted end-to-end.

Agreed, but please read the comment I was replying to:

"westoque 4 hours ago | link | parent

I guess it's time for Google Hangouts to shine."

How does this article imply that it's time to switch to Hangouts?

Re: Skype backdoor confirmation

#80
post #66

Earlier quoted context omitted.

Why? I don't think it's encrypted in such a way that Google can't read it. References? I don't think you can trust Google with your chat and docs as well. From: http://www.wired.com/threatlevel/2010/09/google-spy/ >Google acknowledged Wednesday that two employees have been terminated after being caught in separate incidents allegedly spying on user e-mails and chats. >David Barksdale, 27, was fired in July after he r…

That actually shows that Google has privacy policies that are to be taken seriously by their own employees

Is there anything to show Microsoft does not? All we have here is a server making HEAD requests, not even GET.
Post reply on HN