Live data from Hacker News

Skype backdoor confirmation

lists.randombit.net

111–120 of 126 posts

Re: Skype backdoor confirmation

#111

Checking URLs passed in messages isn't incompatible with secure communication. It's easy enough to look at a text message that's going to be sent and break it into parts (URL and non-URL). Encrypt point-to-point the non-URL parts, and encrypt the URL parts such that the central servers can read them (and verify that they're not pointing to bad stuff, which is a very valuable service to provide to the vast number of r…

"Checking URLs passed in messages isn't incompatible with secure communication"

I guess that depends on your definition of "security," and perhaps of "practicality." Where I'm from (i.e. a grad student whose research is on practical secure multiparty computation), a practical system for checking URLs in a privacy-preserving fashion is still very much a research topic.

"It's easy enough to look at a text message that's going to be sent and break it into parts (URL and non-URL). Encrypt point-to-point the non-URL parts, and encrypt the URL parts such that the central servers can read them"

How is that secure? Now the third party knows what URLs you are sending in your messages.

"The URL checks could also be anonymized."

Sure, but that is not what you are seeing here. You would need a mix-net of some kind, one in which the users themselves are participating (to ensure that there is at least one honest party). It is technically possible...but you're not going to see it happen, not any time soon. With the FBI talking about building back doors into everything, what incentive is there for a company like Microsoft to actually make such a secure system?

When it comes down to it, most Skype users are too uninformed to even know how their software might betray them. On the other hand, the Justice Department could create plenty of difficulty for Microsoft if they failed to cooperate. Whose side do you think Microsoft will choose?

Re: Skype backdoor confirmation

#112
post #32

Earlier quoted context omitted.

I have reason to believe that the government cannot access all my mails. But if it could, I’d be even happier, as it would either prove a fault in GPG (unlikely) or a working quantum computer implementing e.g. Shor’s algorithm. And who wouldn’t want to hear of the latter?

I have reason to believe that you're wrong, because if you're under surveillance by the FBI or whatever, they will be able to read your mail. Unless you're the ultra-paranoid guy there are ways to get to your password physically :( (so, since you're coming up with GPG which i obviously was not referring to i can also come up with some unlikely scenario, ok?)

It doesn't take all that much effort:

https://en.wikipedia.org/wiki/Smartcard

Re: Skype backdoor confirmation

#113
post #104
post #92

Earlier quoted context omitted.

NSA was already ready to pay billions of dollars for a Skype eavesdropping solution [1]. One could wonder if that's one way Microsoft wanted to recover some of the cost of their investment, and why they were so willing to pay twice as much as Google wanted to pay. I mean what company outbids another by 2x/$4 billion for a company with not that much revenue and profit? [1] - http://www.theregister.co.uk/2009/02/12/nsa…

| One could wonder if that's one way Microsoft | wanted to recover some of the cost of their | investment You could wonder, but it would seem difficult to hide $1 billion in revenue for a publicly traded company.

No need to hide anything. An extra billion or two per year going forward would provide a respectable ROI on $8 billion. Surely there are countless wholly open ways to accomplish that with a customer the size of the US gov't.

Re: Skype backdoor confirmation

#114
post #32

Earlier quoted context omitted.

I have reason to believe that the government cannot access all my mails. But if it could, I’d be even happier, as it would either prove a fault in GPG (unlikely) or a working quantum computer implementing e.g. Shor’s algorithm. And who wouldn’t want to hear of the latter?

I have reason to believe that you're wrong, because if you're under surveillance by the FBI or whatever, they will be able to read your mail. Unless you're the ultra-paranoid guy there are ways to get to your password physically :( (so, since you're coming up with GPG which i obviously was not referring to i can also come up with some unlikely scenario, ok?)

All of our intra-company email is accessed via terminal, with pine - and since it is intra-company, it doesn't generate network traffic - it is just an append operation on different files (mail spools).

So I have reason to believe, even if we were being surveilled[1] by the (insert TLA), that they would not be able to read our email.

[1] Network only. If they're videotaping our screens, all bets are off.

Re: Skype backdoor confirmation

#115

I'm not sure how this or the original article are "discoveries". Per the skype privacy policy, they are receiving and storing just about everything: (from http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa... ) Retention of Instant Messages, Voicemail Messages, and Video Messages (Skype internet communications software application only) Your instant messaging (IM), voicemail, and video message content (coll…

The article is fear-mongering with a drip of reality, too much like commercial news.

If someone didn't think all of their personal electronic interactions: SMS, gmail (if you still have one), banking info weren't being cursorily evaluated by echelon or other tinfoil hat system ... blackball the moron.

I'm interested in by-invite-only HN alternatives w/ lower noise and higher signal. (I'm no longer using HN as a primary news source and refuse to disclose which I do use.)

Re: Skype backdoor confirmation

#116
post #103
post #98

Earlier quoted context omitted.

Enough alcohol will leave me unable to recall several of my longer passwords. I find it hard to believe that they have a drug that will 1) not trigger that, 2) not leave a hangover of any sorts, 3) render me entirely unable to remember the incident, 4) make me inclined to tell them the password. That would basically be a wonder drug, the ultimate truth serum.

There are drugs for some of those things... 1) Barbiturates induce a hypnotic state that has widely been reported to improve subjects ability to recall details. Published work on human subjects more or less dried up in the early 70s for ethical grounds (cf. http://ist-socrates.berkeley.edu/~kihlstrm/exhumed.htm "There is, unfortunately, a virtual lack of controlled clinical studies on the accuracy of hypnotically ref…

Speaking of passwords, or: how I detest them so...

Passwords ... other people can watch you enter them, even at distance, and are easily forged, once known.

Pen & ink signatures ... the results can be replicated and are hard to verify algorithmically.

Other solutions ... meh.

Hand gesture inside a box, more inventive than the bird, determined by cameras. 3D gestures like if android unlock worked in augmented reality.

The "box," not of the Dune kind, would start folded flat and open to be sure nothing else were inside of it. Sadly, not even Thing. Folds up to create a completely discrete puppetry stage for god knows what, but sadly it wouldn't be all that interesting.

The point being that it's harder to fake or compel a performance that would basically be impossible to observe (assume trust of the system, of course, like anything... imperfect) rather than something tangible like an iris, print, voice, etc.

I'm sure the DDR ATM will be next at airports, but passwords still suck.

Re: Skype backdoor confirmation

#117

I'm not sure how this or the original article are "discoveries". Per the skype privacy policy, they are receiving and storing just about everything: (from http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa... ) Retention of Instant Messages, Voicemail Messages, and Video Messages (Skype internet communications software application only) Your instant messaging (IM), voicemail, and video message content (coll…

The article is fear-mongering with a drip of reality, too much like commercial news. If someone didn't think all of their personal electronic interactions: SMS, gmail (if you still have one), banking info weren't being cursorily evaluated by echelon or other tinfoil hat system ... blackball the moron. I'm interested in by-invite-only HN alternatives w/ lower noise and higher signal. (I'm no longer using HN as a prima…

How about a GMAIL backdoor? oh no!! NOT GOOGLE!

Anyone remember this?

"A US government-mandated backdoor allowed China to hack into Gmail"

"In order to comply with government search warrants on user data, Google created a backdoor access system into Gmail accounts. This feature is what the Chinese hackers exploited to gain access."

http://www.cnn.com/2010/OPINION/01/23/schneier.google.hackin...

Re: Skype backdoor confirmation

#118
post #98
post #90

Earlier quoted context omitted.

If you wouldn't be drugged :(

Enough alcohol will leave me unable to recall several of my longer passwords. I find it hard to believe that they have a drug that will 1) not trigger that, 2) not leave a hangover of any sorts, 3) render me entirely unable to remember the incident, 4) make me inclined to tell them the password. That would basically be a wonder drug, the ultimate truth serum.

So when you say you actually have to type a password you're screwed in our hyptothetic scenario anyway. You think it's hard to sniff what you type into your keyboard[1]? To install a camera watching you enter a password? And now don't tell me you're using Wifi, that'd be a security nightmare then ;)

[1] like http://www.keelog.com/ only in small and unrecognizable

Re: Skype backdoor confirmation

#119
post #24

This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…

Considering there was an article just a few days ago in NYTimes [1] claiming that "Skype is so secure because of its decentralization" that law enforcement tries to pass laws against it, I'd say a lot of people aren't aware that Microsoft does have access to all the information at this point thanks to their "super-nodes", but even NYTimes writers aren't aware of it (or maybe it was just a cloaked advertorial for Skyp…

I believe the differentiation is that Skype routes calls p2p by default, so wiretapping them is hard. It may be possible for Skype to record calls, but only when it's routed through Supernodes - a mode usually reserved for when firewalls prevent a p2p connection.

Call metadata like to/from, time, and call length are stored - as is all text.

Re: Skype backdoor confirmation

#120
post #98
post #90

Earlier quoted context omitted.

If you wouldn't be drugged :(

Enough alcohol will leave me unable to recall several of my longer passwords. I find it hard to believe that they have a drug that will 1) not trigger that, 2) not leave a hangover of any sorts, 3) render me entirely unable to remember the incident, 4) make me inclined to tell them the password. That would basically be a wonder drug, the ultimate truth serum.

There is a drug called Scopolamine, which pretty much does that. Vice made a documentary about it called "World's Scariest Drug" - http://youtu.be/ToQ8PWYnu04
Post reply on HN