Earlier quoted context omitted.
How does Skype's key exchange work? If the supernode hands out an address for a server that intercepts the call, would the Skype client still accept it and connect?
The protocol itself is highly obfuscated, but from my understanding of what has been published it works something like this: (lots of disclaimers here that nobody outside of Microsoft/Skype really knows for sure) When logging in an RSA public/private key pair is generated and the public key is sent up to the server. The username to public key mapping is seeded to supernodes and inserted into the global address book.…
>If you are a government agency with a private key that matches one of the observer public keys (Russia, China, and India have openly claimed to have these
I am not calling bullshit, I just want to know more.