Live data from Hacker News

Microsoft says it's prepared to hand over Skype users' data to Russia

globalpost.com

41–50 of 54 posts

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#41

Anyone who cares about being spied on abandoned Skype long, long ago. So now governments have tools that let them spy on ordinary people, but not their purported legal targets, who have moved on to more secure methods of communication directly in response to dragnet-style surveillance, while if it was kept low-key and appropriately targeted and selective, many would likely not even know.

Before reading this thread, I was one of those unfortunate chaps who still assumed Skype was P2P. What's the preferred alternative that's actually secure?

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#43
post #2

"if required by law." How's that different from any other company? Even "secure" companies like Fastmail and others comply if they receive a court order for information on specific users. Looks like an attempt to capitalize on the recent events by implicitly saying Microsoft will share everything about every user in bulk. What a surprise.

"Even "secure" companies like Fastmail and others comply if they receive a court order for information on specific users." Your quotes are appropriate. It is not secure if there is a man in the middle who can turn my mail over to the government, even when they are presented with a court order.

[deleted]

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#44

Earlier quoted context omitted.

Is that supposed to make us feel better? There was a time when Skype actually was secure, before they changed it to allow "legal intercept", but even after they did that they still refused to admit that they allow governments to have access to people's conversations. I'll never forget reading in the damn New York Times a week before Snowden leaks came out about how secure Skype was for dissidents and journalists, and…

It was never secure. Closed source and with no end-to-end encryption, so supernodes could always listen. The supernode design isn't compatible with having lots of mobile devices, that's why it was changed. It's only marginally easier to intercept.

Supernodes could not always listen. The actual traffic was always direct P2P unless a direct connection could not be established due to e.g. NATs or firewalls, in which case supernodes would be used as relays. Research into NAT traversal and P2P connectivity a few years ago indicated that about 85% of peers could be connected to directly, so most traffic was not via supernodes.

Even now the majority of non-mobile traffic seems to be direct P2P. I know because I checked using packet sniffers. In fact, even supernode traffic is P2P. Checking my router logs, I can see a number of connections made to Skype even when I'm not using it, which I presume is my machine being used as a supernode.

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#45
post #17
post #9

Earlier quoted context omitted.

Why don't you move to a real corrupt & totalitarian country - say Russia - that will make you feel better about living in the UK quickly.

Good old "something out there is worse" excuse.

Well, I find it to be no worse than the "why aren't we in utopia" whine ;-)

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#46

Earlier quoted context omitted.

It was never secure. Closed source and with no end-to-end encryption, so supernodes could always listen. The supernode design isn't compatible with having lots of mobile devices, that's why it was changed. It's only marginally easier to intercept.

Supernodes could not always listen. The actual traffic was always direct P2P unless a direct connection could not be established due to e.g. NATs or firewalls, in which case supernodes would be used as relays. Research into NAT traversal and P2P connectivity a few years ago indicated that about 85% of peers could be connected to directly, so most traffic was not via supernodes. Even now the majority of non-mobile tra…

Since there is no key exchange and end-to-end encryption, anyone can always listen, if on a network through which a Skype stream passes. There's merely a higher opportunity to do so when running a supernode.

If a government does intercept all ISP traffic, they can listen in anyway.

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#47

Russia and the US have similar approaches to communications metadata. News at 11.

The recent NSA slides mention "metacontent" and "metadata." After some consideration I decided the use of "meta" is horse-shit. Evidence for this is how the "meta" has been touted as "not being the content." Well it doesn't really matter when both the (header)data and (body)content of things like SMS or email are both snooped.

Yet more wiggly phrases made to try to shift the goal posts that is privacy. Let's drop the meta.

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#48
post #4
post #2

"if required by law." How's that different from any other company? Even "secure" companies like Fastmail and others comply if they receive a court order for information on specific users. Looks like an attempt to capitalize on the recent events by implicitly saying Microsoft will share everything about every user in bulk. What a surprise.

Even a law in a corrupt, totalitarian country?

You know you can't get in jail for twitter jokes in Russia, whatever they are. In fact you can do almost whatever you want here. I'm so tired of that negative image of Russia in the Western media...

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#49

Earlier quoted context omitted.

Supernodes could not always listen. The actual traffic was always direct P2P unless a direct connection could not be established due to e.g. NATs or firewalls, in which case supernodes would be used as relays. Research into NAT traversal and P2P connectivity a few years ago indicated that about 85% of peers could be connected to directly, so most traffic was not via supernodes. Even now the majority of non-mobile tra…

Since there is no key exchange and end-to-end encryption, anyone can always listen, if on a network through which a Skype stream passes. There's merely a higher opportunity to do so when running a supernode. If a government does intercept all ISP traffic, they can listen in anyway.

I'm not sure there is no key exchange... Last I looked into Skype's security, not only was the traffic encrypted, the binary itself was also heavily obfuscated, so nobody knew what was going on. This was half a decade ago, though, and lots of things have changed since then.

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#50

This shit is already a spyware (at least for Android, where it even has a permission to modify system settings). I had 40Mb of background data usage for a 5 day (in a roaming in India, that's why I have noticed) while I never switched to it .

It is less likely you will receive calls over Skype when Skype isn't connected and notifying the network of its location. On a desktop device notifications can be infrequent. Mobile devices are mobile, however. I haven't installed Skype on Android because of the permissions it requests and for the reason that I rarely use it. But at least it's not preinstalled as are many Google apps similarly privileged.

A keep-alive TCP connection, or bunch of UDP packets is enough for that.
Post reply on HN