Skype Goes After Reverse-Engineering
phoronix.com
phoronix.com
I would argue that the opcodes in the binary are covered by copyright, but if you reverse-engineer those into C, that's your own creative work. Apparently Skype's lawyers did not see it this way, but why would they? If you're going to lie, you have to first convince yourself.
You could create an original novel that was not a derivative work by taking once sentience from every book in a library and trying to create a meaningful work of art from it. Doing the same thing using a single book would probably not fly.
Even if it was against the law for him to reverse engineer the protocol, they don't own copyright to the source files he created.
The other problem is that by looking at the decompiled source, his source is tainted. He will have a hard time showing that it isn't a derivative work. Especially if he wasn't really careful writing the source from scratch and not cleaning up the decompiled source.
This survived a legal challenge, but that was in the IP environment of the early '80s, so who knows what would fly now.
Plus, I don't get why companies care if someone reverse engineers their super secret [read: crappy] protocol.
A long time ago, I recall having a conversation with the CTO of a company that made BBS software. We wanted to integrate with his servers, so we wanted the proprietary protocol. We advised him to build an API so that his software would become an ecosystem and thrive.
He smiled and metaphorically patted us on the head like a parent explaining the world to children.
“If we publish the API for people to write new clients, people can also write new servers that talk to the clients we write, and we’d be out of business.”
Skype’s motivation is obvious: If the protocol is public, while some people will write software that enhances the Skype ecosystem, others will compete with Skype, and that isn’t what they want.
Their system operates under an assumption that all its parts are genuine, and so it places implicit trust into every client and expects it to operate fairly for the system's overall benefit. You open this thing up and there will be 3rd party nodes that do not comply with system's semantics -- supernodes become few and far between (why the hell would anyone be willingly relaying the traffic while on any sort of metered connection?), someone would add an encryption overlay disabling any "lawful interception" provisions they have in place (which they most certainly have or they would've been simply blocked all over the world), someone else would find a weakness in their p2p encryption and start eavesdropping on relayed calls, etc. Does Skype needs this sort of headache? No. Hence the highly obfuscated and encrypted binary with numerous anti-debugging and anti-reversing traps, and their very active suppression of reverse engineering attempts. Skype would basically stop working if it is ever open.
Unless of course they actually implemented the security system properly and have a secure method for identifying each end of the call - but they wouldn't have needed to do that because it's all secret.
That's what I thought too - can anyone address this question?
https://www.eff.org/issues/coders/reverse-engineering-faq#fo...
HOWEVER the skype terms of use read:
4.2 Restrictions. You may not and you agree not to.
(a) sub-license, sell, assign, rent, lease, export, import, distribute or transfer or otherwise grant rights to any third party in the Software;
(b) undertake, cause, permit or authorize the modification, creation of derivative works or improvements, translation, reverse engineering, decompiling, disassembling, decryption, emulation, hacking, discovery or attempted discovery of the source code or protocols of the Software or any part or features thereof (EXCEPT TO THE EXTENT PERMITTED BY LAW); (emphasis mine)
http://skype.ivo.so/ http://thepiratebay.org/torrent/6442887