A Backdoor in Skype for Mac OS X
trustwave.com
trustwave.com
http://arstechnica.com/tech-policy/2014/12/newly-published-n...
Isn't it already disclosed in the Snowden documents that Skype has received NSLs?
$600k to a particular airline employee, $1 million for a single parcel worker (this was over a few years).
Also there is the various NSA efforts to insert people into the encryption standards process, as well as use cooperative sources within companies to insert vulnerabilities in the commercial encryption systems:
http://www.nytimes.com/interactive/2013/09/05/us/documents-r...
Also the FBI/Yahoo email program was apparently done by just the CEO, a lawyer, and a few members of the email team. The security team wasn't informed, nor the board.
https://www.theguardian.com/technology/2016/oct/04/yahoo-sec...
The second one sounds more like an interdiction program, where vulnerabilities are inserted into the devices (this is a thing that was in the Snowden documents). The document gives no details. The highlights on the side are from an NYT journalist, not source material.
I disagree that the last example is an example of that. It's still unclear what the scanning was doing.
The idea that people could bypass those processes and controls is a tremendous liability that no board would ever approve.
https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...
I think you are misleadingly using the word "collaboration".
I also think you have failed to understand the article correctly; there is no reference to client side collection. Take another look.
Skype was around for along time before Microsoft bought it and changed its architecture and design.
Well, if you have any of the closed-source companies' software on your system (and by definition, that is +/- 310mio citizens, in the US alone), you are sure to have NSA backdoors on your system. Such backdoors certainly do not require manual intervention for them to be exploited on large scale.
But more to the point, you don't know what's going on in closed source code. It's trust. However the trust can, and has been violated in the past (whether by the provider or by a third party is immaterial). You just don't know. Now that doesn't mean that open source software is immune. I seem to remember there was a backdoor found in the Linux kernel a few years ago. These things happen, but at least it's easier to audit.
i dabbled in this api way back in the past so i may be wrong about its capabilities.
skype used to be EXCELLENT at working in most networks, including "locked down" corporate ones. Network admins used to find it notoriously difficult to "ban" on networks.
so relying on skype to exfiltrate info may serve two purposes:
1) use another program's capabilities instead of reinventing the wheel.
2) hide the fact that some random program is doing network access.
skype could be one of a range of data exfiltration mechanisms with different levels of obfuscation.
Well after the investigation went through and some data came out regarding the Vodafone server hack it was clear that the organizations that could pull something like this, there like ... Maybe 5 with CIA the most likely candidate.
So, we like to oversimplify but life is way more complicated.
BTW I think that the Athens affair is one of the top 3 hacking stories that I know of.
Then, Microsoft bought it and that all changed.
The old Skype for Windows was really locked and obfuscated. I remember that it would not even start on my PC with a debugger installed, even though it was not running in the debugger.
While this simple reasoning is appealing, I have to disagree. Both its premises (Skype was peer to peer before MS) and conclusion (MS made it a client-server system because Evil).
- Real peer to peer on internet is not really possible, since most end users are behind NAT. Skype resorts to a number of hole punching techniques, but really only uses STUN/ICE, effectively using super-nodes as relay for sessions. This directly means that all these communication are transiting through a third party, and not peer to peer.
- Super-nodes used to be regular end users (with some simple algorithm to elect as supernode users with high up-time, high throughput. Fun fact: only windows client users were possible super-nodes). This model proved to be too fragile. In case the network falls down (which happened some years ago), then the super-nodes are no longer available, and get instantly DoS when coming back up due to every other node trying to get back. This is a vicious cycle in which the network cannot get back up. So for a long time now (before MS) super-nodes are just backed by Skype-hosted servers in data-centers.
- Thin clients are a real thing in e.g. the african market, where a lot of very old phones are still in circulation, no "apps" are possible. Think of your old Nokia 3310.
- Persistent group chats. Users wanted it.
- And on a more "political" aspect: MS needed to promote its cloud infrastructure (Azure), lower its physical resources fingerprint (get rid of Skype datacenters), and unify its technical stack (Linux/C++ now Windows/C#)
Microsoft controls the servers, they don't need a client backdoor to access messages.
honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application
Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts.
further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic - which by the very nature of such activities they demonstrate that they do not. They (3 letter agencies) want every possible vector of information gathering regardless of the privacy, security, and legal issues that arise.
Secondly, this is a pretty stupid way of doing it. 'If you use this client identifier than anything goes' seems vastly more like a stupid coding mistake than it does a sneaky covert backdoor into accessing Skype from the local machine.
but hey, why not throw out the facts to pile on?
No, because introducing security vulnerabilities to keep us secure is inherently illogical.
This idea is built on the assumption that (1) they think their defensive role is as vital as their offensive one, (2) there is plenty of special NSA voodoo to go round. Which is false. In particular, it is better that a hack come from a vendor vuln that anybody could find than from crypto wizardry (e.g. Logjam or signed drivers with md5 collisions).
Of course they do. You may disagree with the logic, but it's there. Vectors of intelligence gathering have to be both sufficiently covert and useful for an agency to consider. This vulnerability is neither.
Now, everything goes through Microsoft servers where it can be conveniently wiretapped.
EDIT: Also: http://www.cs.unc.edu/~fabian/papers/foniks-oak11.pdf
If Snowden didn't happen I would most likely believe that this was just bad engineering or something.
Post Snowden your interpretation sounds like extremely naive.
It's stupid programming and perhaps could be used for convenience by a worm or virus but it does not allow privilege escalation.
Worst case scenario there is a bug in the API that allows privilege escalation, then it might be a sandbox escape, if it is possible to use the API from inside the sandbox which I doubt.
Why the rest of it? Is it overengineered? Am I missing something?
This news only proves that the Skype codebase must be an unmanageable mess. I can undetsrand that. But also it seems that MS is moving to the web version of skype, in the meantime not taking care too much about the native clients.
Also, if somebody has the ability to run arbitrary code on your machine, I would think that it's game over at that point - backdoor or not. This is not a remote exploitable backdoor it seems.
How else would you call the possibility to sidestep access controls by setting a specific string as identifier?
> I wasn't able to see any working example, nor any responsible disclosure which seems bad. First, those two statements kind of contradict each other. Second, from the advisory linked from the article:
10/13/2016 - Vulnerability disclosed to vendor
10/26/2016 - Patch released by vendor
12/12/2016 - Advisory published
> Also, if somebody has the ability to run arbitrary code on your machine, I would think that it's game over at that point.Yes, it has been game over all the time: People execute arbitrary code on their machines by installing free programs they downloaded from somewhere. But that's not the point. The point is that some application that has control over very sensitive data includes a possibility (to avoid the word "backdoor") to access that data without user-confirmation and alarms, which are otherwise built into the application on a design level.
What we can't say is whether this is a backdoor created for nefarious purposes. All we can say is that the backdoor exists and, if we accept that authentication on this API is valuable, then it's an egregious violation of security principles by effectively having some hardcoded credentials which bypass a security layer.
You can wave it away as local-only and claim that if you have code running on the box, it's already pwned, but this is rationalization: this backdoor bypasses a layer of security that is otherwise present. Can an otherwise unprivileged process (e.g. one from another user) call this API? The details are not specified.
I tend to think this looks more like incompetence perpetrated a long time ago and forgotten, but that doesn't make it any less of a back door.
Well, something with its name.
"Curiously, the actual Skype Dashboard widget does not seem to utilize the backdoor into the Skype Desktop API despite the name "Skype Dashbd Wdgt Plugin"."
Sure people who build it from source would be protected, but that's still not the majority of users for a product like Skype. I don't get the OSS cause being shoehorned into every conversation.
That would protect the users of those binaries.
Generally, we rely on signed binaries.
That and the fact that OS X security is not fantastic to begin with, and I don't want anything weird showing up in screen sharing with job interviews (say, in search history).
Which OS do you use/prefer for better security?
Example: http://blog.linuxmint.com/?p=2994
I wouldn't touch Arch with a ten-foot pole, a combination of disastrous design decisions and maintainers that don't take reports of security vulnerabilities in default package configurations seriously has really soured any love I had for the distro once I got past the obnoxious fans and overtly hostile user experience. Arch is the only distro where I've made bug reports for security vulnerabilities and gotten asinine responses like "users should only install this package on trusted networks."
https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...
In many other cases technology transfer, joint management/ownership, market access, political favors, lucrative contracts, direct infiltration, nationalist instincts, and bribery are all reasons for Microsoft to work with the NSA and other intelligence agencies. They were caught providing backdoor access along with Google to all outlook (and gmail) emails to the FBI, for example.
If the NSA wanted to intercept or forge Skype conversations and had access to Microsoft to do so, they would have a much easier time doing so on the server side.
Despite the tone of the article, there is nothing to suggest that anyone at Microsoft was doing anything more than creating the most cost-effective method to handle requests it was coerced to fulfill.
Alternatives to "collaboration":
1. Deny all requests. Get held in contempt of court. Go out of business.
2. Have dedicated staff to manually dig through every data repository to handle each request in a bespoke manner.
Where it could instead be a bug or mistake that was not intentionally included.
If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not.
Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.
Are you addressing me personally? What does that have to do with what I said?
> A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access.
Isn't that the case here?
- No, it's not the case here. Unless you can prove it. There's no evidence it was done intentionally.
It could be disguised as an access for their own service and the real purpose be mass surveillance, or it could be a simple mistake in a big codebase, but the "door" is definitely not a bug.
Even though nowadays we keep hearing about nefarious backdoors, they used to simply refer to hidden service entrances for software creators, a completely legitimate use.
As the two can't be distinguished at first blush, the wise approach is to adopt an innocent-until-proven-guilty approach. Which is to say assume it's an accident until it can be proven intentional. This way, both possibilities are taken seriously without jumping from zero all the way to tinfoil at the drop of a hat.
I tire of the logic such as "well...what IF...someone...did that intentionally!" Then people think they're smarter than everyone else, using words like sheeple and such.
Shit happens. Merges fail. Teams miss stuff. I once randomly discovered a hole in a web app where data was being leaked from an ajax call without logging in. No conspiracy.
Yes, if I were a 1337 haxxor and I wanted to disguise a commit to, say, Linux for my backdoor I would disguise it as a mistake. Totally right, that would be smart and awesome. I'd have something to say on the next HN post of "What makes a Senior Software Engineer", because a junior engineer would not be this smart.
As an aside, long before the NSA reveals of 2013 there had been reports of back doors in skype. My clock skew causes me to forget how many years ago that was, but I'm gonna say somewhere 2005-2008. As 2013 passed, I thought back on that and laughed.
So yeah, Skype is backdoored. Is this one of them? Perhaps. Or it's yet another big corp fail. Orrrr...getting crazy now....it's a bug, but then it was discovered long ago by smart people and has been exploited. So it wasn't internal conspiracy, just a good find by some NSA dude.
Anyway. Back to my code.