Live data from Hacker News

Microsoft says it's prepared to hand over Skype users' data to Russia

globalpost.com

51–54 of 54 posts

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#52

Earlier quoted context omitted.

Since there is no key exchange and end-to-end encryption, anyone can always listen, if on a network through which a Skype stream passes. There's merely a higher opportunity to do so when running a supernode. If a government does intercept all ISP traffic, they can listen in anyway.

I'm not sure there is no key exchange... Last I looked into Skype's security, not only was the traffic encrypted, the binary itself was also heavily obfuscated, so nobody knew what was going on. This was half a decade ago, though, and lots of things have changed since then.

That still doesn't change anything. There is (and never was) secure key exchange between contacts: if there was, it would be have to be explicit and you would've noticed.

The traffic might be encrypted, but the receiving party isn't the only one with the key. At the very least, the Skype service intermediated the key exchange.

Re: Microsoft says it's prepared to hand over Skype users' data to Russia

#53

Earlier quoted context omitted.

It is less likely you will receive calls over Skype when Skype isn't connected and notifying the network of its location. On a desktop device notifications can be infrequent. Mobile devices are mobile, however. I haven't installed Skype on Android because of the permissions it requests and for the reason that I rarely use it. But at least it's not preinstalled as are many Google apps similarly privileged.

A keep-alive TCP connection, or bunch of UDP packets is enough for that.

Or just Android's push service, which lets apps handle the notification and decide what to do (unlike iOS).
Post reply on HN