Live data from Hacker News

A Backdoor in Skype for Mac OS X

trustwave.com

71–80 of 112 posts

Re: A Backdoor in Skype for Mac OS X

#71
post #57
post #56

Earlier quoted context omitted.

Less common = less attention to security.

The train of thoughts here is that less common == smaller exposure, therefore less likely to be a target. Also, your statement isn't entirely true, for example, OpenBSD, albeit not being a linux distribution, is a project orders of magnitude smaller, yet with equal, if not greater, focus on security.

OpenBSD has a much larger market share than most fringe Linux distributions. They also have a focus on security and many high-profile experts.

Example: http://blog.linuxmint.com/?p=2994

Re: A Backdoor in Skype for Mac OS X

#72
post #56

Earlier quoted context omitted.

Any not-too-common linux distribution with a recent kernel is probably a comparably good choice.

Less common = less attention to security.

Less common = smaller number of victims for the same attack. The attacker has to make it work for the software combination one is using. That's more rewarding if more people use the same software.

Re: A Backdoor in Skype for Mac OS X

#73

I've heard rumors that the Skype codebase is a giant mass of unmaintainable code "approaching a singularity" and for this reason alone you wouldn't expect it to be terribly secure. At one time I wondered if I was too paranoid for adding another user account for the sole purpose of running Skype, but I no longer wonder. That and the fact that OS X security is not fantastic to begin with, and I don't want anything weir…

> That and the fact that OS X security is not fantastic to begin with. Which OS do you use/prefer for better security?

Qubes OS ;)

Re: A Backdoor in Skype for Mac OS X

#74

I've heard rumors that the Skype codebase is a giant mass of unmaintainable code "approaching a singularity" and for this reason alone you wouldn't expect it to be terribly secure. At one time I wondered if I was too paranoid for adding another user account for the sole purpose of running Skype, but I no longer wonder. That and the fact that OS X security is not fantastic to begin with, and I don't want anything weir…

It seems to get worse every release for a long time now. People around me insist on using it but I prefer WhatsApp, Slack and Hangouts for various tasks Skype tries to do.

Re: A Backdoor in Skype for Mac OS X

#75
The backdoor aside, but using Skype seems to be a real pain recently. It used to be something that offered unmatched quality and service, but with time passing it is lagging behind. Skype on Mac OS X now starts like in 10 seconds and even the shutdown takes 10-15 seconds (on SSD). Video calls are fine, but the fans are quickly 100%. It's funny but the (long unmaintened) Linux skype seems to be better at video calls.

This news only proves that the Skype codebase must be an unmanageable mess. I can undetsrand that. But also it seems that MS is moving to the web version of skype, in the meantime not taking care too much about the native clients.

Re: A Backdoor in Skype for Mac OS X

#76
post #70
post #69

Earlier quoted context omitted.

Does any NSA surveillance vulnerability stand up to logical scrutiny? No, because introducing security vulnerabilities to keep us secure is inherently illogical.

If this comment made sense to someone else who could rephrase it for me, I'd be grateful.

[deleted]

Re: A Backdoor in Skype for Mac OS X

#77
post #46
post #10

Earlier quoted context omitted.

Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what the…

You didn't respond to the substance of his objection. The problem with the "NSA backdoor" hypothesis is that it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer . If the NSA has installed software on your machine that it can control, you are going to, in the parlance of our times, "get Mossad'd".

Of course, of course, this is unlikely to be an NSA backdoor. But maybe ....

i dabbled in this api way back in the past so i may be wrong about its capabilities.

skype used to be EXCELLENT at working in most networks, including "locked down" corporate ones. Network admins used to find it notoriously difficult to "ban" on networks.

so relying on skype to exfiltrate info may serve two purposes:

1) use another program's capabilities instead of reinventing the wheel.

2) hide the fact that some random program is doing network access.

skype could be one of a range of data exfiltration mechanisms with different levels of obfuscation.

Re: A Backdoor in Skype for Mac OS X

#78
post #34

This wouldn't be the first time Microsoft has worked with the NSA https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

Why would Microsoft be working with the NSA on this?

On this specifically, I'm doubtful. The 'backdoor' isn't very high value.

In many other cases technology transfer, joint management/ownership, market access, political favors, lucrative contracts, direct infiltration, nationalist instincts, and bribery are all reasons for Microsoft to work with the NSA and other intelligence agencies. They were caught providing backdoor access along with Google to all outlook (and gmail) emails to the FBI, for example.

Re: A Backdoor in Skype for Mac OS X

#79
post #65

Earlier quoted context omitted.

- Not you personally. I have experience with HN comments. Just covering my bases. - No, it's not the case here. Unless you can prove it. There's no evidence it was done intentionally.

When I say it was done intentionally, I mean opening an authentication-less was intentional. It could be disguised as an access for their own service and the real purpose be mass surveillance, or it could be a simple mistake in a big codebase, but the "door" is definitely not a bug. Even though nowadays we keep hearing about nefarious backdoors, they used to simply refer to hidden service entrances for software creat…

Indeed, this is a valid definition of backdoor.

Re: A Backdoor in Skype for Mac OS X

#80

This wouldn't be the first time Microsoft has worked with the NSA https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

I respond to this link earlier in these comments. The so-called collaboration is of the same nature as any other communications company in the world responds to warrants, subpoenas, etc in their home country.

Despite the tone of the article, there is nothing to suggest that anyone at Microsoft was doing anything more than creating the most cost-effective method to handle requests it was coerced to fulfill.

Alternatives to "collaboration":

1. Deny all requests. Get held in contempt of court. Go out of business.

2. Have dedicated staff to manually dig through every data repository to handle each request in a bespoke manner.

Post reply on HN