http://arstechnica.com/tech-policy/2014/12/newly-published-n...
http://arstechnica.com/tech-policy/2014/12/newly-published-n...
Isn't it already disclosed in the Snowden documents that Skype has received NSLs?
$600k to a particular airline employee, $1 million for a single parcel worker (this was over a few years).
Also there is the various NSA efforts to insert people into the encryption standards process, as well as use cooperative sources within companies to insert vulnerabilities in the commercial encryption systems:
http://www.nytimes.com/interactive/2013/09/05/us/documents-r...
Also the FBI/Yahoo email program was apparently done by just the CEO, a lawyer, and a few members of the email team. The security team wasn't informed, nor the board.
https://www.theguardian.com/technology/2016/oct/04/yahoo-sec...
The second one sounds more like an interdiction program, where vulnerabilities are inserted into the devices (this is a thing that was in the Snowden documents). The document gives no details. The highlights on the side are from an NYT journalist, not source material.
I disagree that the last example is an example of that. It's still unclear what the scanning was doing.
The idea that people could bypass those processes and controls is a tremendous liability that no board would ever approve.
https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...
I think you are misleadingly using the word "collaboration".
I also think you have failed to understand the article correctly; there is no reference to client side collection. Take another look.
Skype was around for along time before Microsoft bought it and changed its architecture and design.
Well, if you have any of the closed-source companies' software on your system (and by definition, that is +/- 310mio citizens, in the US alone), you are sure to have NSA backdoors on your system. Such backdoors certainly do not require manual intervention for them to be exploited on large scale.
But more to the point, you don't know what's going on in closed source code. It's trust. However the trust can, and has been violated in the past (whether by the provider or by a third party is immaterial). You just don't know. Now that doesn't mean that open source software is immune. I seem to remember there was a backdoor found in the Linux kernel a few years ago. These things happen, but at least it's easier to audit.
i dabbled in this api way back in the past so i may be wrong about its capabilities.
skype used to be EXCELLENT at working in most networks, including "locked down" corporate ones. Network admins used to find it notoriously difficult to "ban" on networks.
so relying on skype to exfiltrate info may serve two purposes:
1) use another program's capabilities instead of reinventing the wheel.
2) hide the fact that some random program is doing network access.
skype could be one of a range of data exfiltration mechanisms with different levels of obfuscation.
Well after the investigation went through and some data came out regarding the Vodafone server hack it was clear that the organizations that could pull something like this, there like ... Maybe 5 with CIA the most likely candidate.
So, we like to oversimplify but life is way more complicated.
BTW I think that the Athens affair is one of the top 3 hacking stories that I know of.
Then, Microsoft bought it and that all changed.
The old Skype for Windows was really locked and obfuscated. I remember that it would not even start on my PC with a debugger installed, even though it was not running in the debugger.
While this simple reasoning is appealing, I have to disagree. Both its premises (Skype was peer to peer before MS) and conclusion (MS made it a client-server system because Evil).
- Real peer to peer on internet is not really possible, since most end users are behind NAT. Skype resorts to a number of hole punching techniques, but really only uses STUN/ICE, effectively using super-nodes as relay for sessions. This directly means that all these communication are transiting through a third party, and not peer to peer.
- Super-nodes used to be regular end users (with some simple algorithm to elect as supernode users with high up-time, high throughput. Fun fact: only windows client users were possible super-nodes). This model proved to be too fragile. In case the network falls down (which happened some years ago), then the super-nodes are no longer available, and get instantly DoS when coming back up due to every other node trying to get back. This is a vicious cycle in which the network cannot get back up. So for a long time now (before MS) super-nodes are just backed by Skype-hosted servers in data-centers.
- Thin clients are a real thing in e.g. the african market, where a lot of very old phones are still in circulation, no "apps" are possible. Think of your old Nokia 3310.
- Persistent group chats. Users wanted it.
- And on a more "political" aspect: MS needed to promote its cloud infrastructure (Azure), lower its physical resources fingerprint (get rid of Skype datacenters), and unify its technical stack (Linux/C++ now Windows/C#)
Microsoft controls the servers, they don't need a client backdoor to access messages.
honestly it amazes me that people still call such interpretations paranoid in a world where information about the rampancy of such programs is readily available, including for this specific application
Edit: it's not paranoia if there's demonstrable history of such things. It's making a reasonable assumption from available facts.
further, all the arguments against this interpretation assume that those introducing security vulnerabilities for surveillance purposes abide by some kind of logic - which by the very nature of such activities they demonstrate that they do not. They (3 letter agencies) want every possible vector of information gathering regardless of the privacy, security, and legal issues that arise.
Secondly, this is a pretty stupid way of doing it. 'If you use this client identifier than anything goes' seems vastly more like a stupid coding mistake than it does a sneaky covert backdoor into accessing Skype from the local machine.
but hey, why not throw out the facts to pile on?
No, because introducing security vulnerabilities to keep us secure is inherently illogical.
This idea is built on the assumption that (1) they think their defensive role is as vital as their offensive one, (2) there is plenty of special NSA voodoo to go round. Which is false. In particular, it is better that a hack come from a vendor vuln that anybody could find than from crypto wizardry (e.g. Logjam or signed drivers with md5 collisions).
Of course they do. You may disagree with the logic, but it's there. Vectors of intelligence gathering have to be both sufficiently covert and useful for an agency to consider. This vulnerability is neither.
Now, everything goes through Microsoft servers where it can be conveniently wiretapped.
EDIT: Also: http://www.cs.unc.edu/~fabian/papers/foniks-oak11.pdf