Earlier quoted context omitted.
You can only encode credentials in a URL via GET. Therefore if people stop using GET and start using POST (aka forms) for authentication this issue goes away. Even just a simple pin. GET issues are primarily related to the fact that an attacker can automate their access. So they could trick a user into going to a specially crafted site, and then request content on that user's behalf via GET forgery, and return it to…
you are also ruling out HTTP auth, yes?
Skype backdoor confirmation
71–80 of 126 posts
Re: Skype backdoor confirmation
#72Earlier quoted context omitted.
Is it? Gmail reads and uses all mail and this doesn't seem to have generated a great outburst of controversy.
Yeah, right. While both Skype and Gmail store your messages (if you Skype across multiple devices, you'll see logs of conversations that happened on different devices), I don't think Gmail probes every URL you send in your messages. Also, SMTP is not always done under SSL, so, privacy cannot be assured. But that's easily testable. I'll get back to you in a couple hours.
One automatically scans your email to show related ads, another does a HTTP HEAD request to URLs for only the server headers, which they say is for malware scanning purposes. Both are automated jobs.
See my other post to see how Google employees have access to all your email, documents, chat transcripts, Google Voice calls, Youtube videos etc. and how a few abused it to stalk teens.
https://news.ycombinator.com/item?id=5728707
As usual, Google gets a free pass and Microsoft gets demonized(they should stop claiming it's end to end encrypted, though). Looking at your HN profile, it's not hard to understand why. Thanks for being honest about disliking Microsoft but please try not to let that color your objective opinions and playing favorites regardless of facts.
Re: Skype backdoor confirmation
#73Re: Skype backdoor confirmation
#74(from http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa...)
Retention of Instant Messages, Voicemail Messages, and Video Messages (Skype internet communications software application only)
Your instant messaging (IM), voicemail, and video message content (collectively “messages”) may be stored by Skype (a) to convey and synchronize your messages and (b) to enable you to retrieve the messages and history where possible. Depending on the message type, messages are generally stored by Skype for a maximum of between 30 and 90 days unless otherwise permitted or required by law. This storage facilitates delivery of messages when a user is offline and to help sync messages between user devices...
From Section 8 of that same document:
Skype may use automated scanning within Instant Messages and SMS to (a) identify suspected spam and/or (b) identify URLs that have been previously flagged as spam, fraud, or phishing links. In limited instances, Skype may capture and manually review instant messages or SMS in connection with Spam prevention efforts.
Re: Skype backdoor confirmation
#75Earlier quoted context omitted.
I think you are missing the point - the article proves (unless the author is flat out lying) that text chat through skype, which is claimed to be end-to-end encrypted, is not, as requests are being made to the URL. It may currently be for innocent purposes (check URLs, thumbnails etc as you said). However the fact is that they can make these requests at all show that the encryption is not end-to-end, otherwise they w…
Or maybe the client forwards the URL to a Microsoft service which accesses it.
Re: Skype backdoor confirmation
#76This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…
Considering there was an article just a few days ago in NYTimes [1] claiming that "Skype is so secure because of its decentralization" that law enforcement tries to pass laws against it, I'd say a lot of people aren't aware that Microsoft does have access to all the information at this point thanks to their "super-nodes", but even NYTimes writers aren't aware of it (or maybe it was just a cloaked advertorial for Skyp…
Re: Skype backdoor confirmation
#77This is totally nit-picky, but strange use of the word "backdoor." When I read "backdoor" I was expecting to read about some malware-like functionality within the Skype client itself, but instead this is just telling us that Microsoft can read content after it is sent to them via the client and decrypted. I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. acc…
A backdoor in their encryption protocol. They claim it is secure. "The Skype Security Policy is: ... 4. Messages transmitted through a Skype session are encrypted from Skype-end to Skype-end. No intermediary node, if any exist, has access to the meaning of these messages. [1]" [1]: http://download.skype.com/share/security/2005-031%20security... Aforementioned referenced on + additonal security overview/facade: http:/…
http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa...
(this apparently does not apply to voice calls, but either does the complaint that they are picking up URLs and visiting them).
Re: Skype backdoor confirmation
#78Earlier quoted context omitted.
I have reason to believe that the government cannot access all my mails. But if it could, I’d be even happier, as it would either prove a fault in GPG (unlikely) or a working quantum computer implementing e.g. Shor’s algorithm. And who wouldn’t want to hear of the latter?
I have reason to believe that you're wrong, because if you're under surveillance by the FBI or whatever, they will be able to read your mail. Unless you're the ultra-paranoid guy there are ways to get to your password physically :( (so, since you're coming up with GPG which i obviously was not referring to i can also come up with some unlikely scenario, ok?)
Re: Skype backdoor confirmation
#79Earlier quoted context omitted.
Why? I don't think it's encrypted in such a way that Google can't read it. References? I don't think you can trust Google with your chat and docs as well. From: http://www.wired.com/threatlevel/2010/09/google-spy/ >Google acknowledged Wednesday that two employees have been terminated after being caught in separate incidents allegedly spying on user e-mails and chats. >David Barksdale, 27, was fired in July after he r…
Shocking! You mean that nearly 3 years ago, a hosted service had employees that may have access to the databases of the services you're using? The difference being that Google doesn't play at being encrypted end-to-end.
"may have access"? That's some nice word play there. Please read the articles. Also, do you have any reason to believe that Google employees can't read your email and documents right now? i.e Have things changed in three years?
>The difference being that Google doesn't play at being encrypted end-to-end.
Agreed, but please read the comment I was replying to:
"westoque 4 hours ago | link | parent
I guess it's time for Google Hangouts to shine."
How does this article imply that it's time to switch to Hangouts?
Re: Skype backdoor confirmation
#80Earlier quoted context omitted.
Why? I don't think it's encrypted in such a way that Google can't read it. References? I don't think you can trust Google with your chat and docs as well. From: http://www.wired.com/threatlevel/2010/09/google-spy/ >Google acknowledged Wednesday that two employees have been terminated after being caught in separate incidents allegedly spying on user e-mails and chats. >David Barksdale, 27, was fired in July after he r…
That actually shows that Google has privacy policies that are to be taken seriously by their own employees