Open Letter to Skype from Internet Activists, Journalists and Academics
skypeopenletter.com
skypeopenletter.com
There's plenty of open and secure VoIP clients which coupled with open encryption standards, VPN's etc. will suit your purposes. Use those things, not Skype.
Disclosure: I work there.
Although I remember reading about the lack of open source and the odd terms of service wording. http://log.nadim.cc/?p=89
Is that still being addressed?
I couldn't really respond about either, because I don't know, but I know that the Silent Text sources are on GitHub: https://github.com/SilentCircle/silent-text
The rest of the clients's code is probably being cleaned up, but I guess we're trying to build more functionality and are very busy with other stuff, and publishing the code has fallen behind a bit. That's just my guess, as, as I said, I don't work on that.
From what I've seen in my time there, though, everyone is extremely capable (I have yet to see a single thing that wasn't done correctly) and very focused on security (again, I have yet to find fault with something, and I'm really paranoid).
From what I've seen (and this probably comes off a bit too PR-y, but it's true), I have absolutely no problem trusting SC with my communications, everyone takes every precaution to safeguard users' data (even in the web part, we don't want to use third-party services, our analytics are hosted by us) to avoid compromising users' data.
Anyway, I've raved too long about this. I'll just say I'm very happy to work there.
Silent Circle has repeatedly told untruths in the media regarding the open source nature of their software. Their software remains largely closed and not open for public review (except for Silent Text, which has only released incomplete source code.)
All the same, Silent Circle has been consciously targeting activists in life-or-death situations. They have repeatedly told activist and the media that their tools are open source and transparently and publicly reviewed. Silent Circle has been lying to those in life and death situations for four months. Their software, except for portions of Silent Text, is not publicly reviewed and closed source software. Furthermore, they claim to have servers based in Canada whereas most of their network is in the U.S., subject to U.S. surveillance laws.
I have written about this here:
https://github.com/SilentCircle/silent-text
Do you have any references of anyone saying the code of the other clients has been released? I'm curious.
Here's one article out of many where Silent Circle makes claims of complete open source. http://www.lemonde.fr/sciences/article/2012/12/13/le-cryptag...
(I think both Silent Circle and the Skype open letter initiative are great and I'm not affiliated with any of them. Just wanted to point out that not being able to comment on something because it's the first time one hears it sounds weird.)
However, the letter also tries to make Skype a safer platform for everyone else. For example they are asking for a regular transparency report, the way Google has with Gmail and Google searches. Is that really too much to ask from Microsoft? And don't you think it would benefit a lot of those 600 million people if they found out just how much Skype is being monitored? While (most) people here can be sure Skype is unsafe, do you really get the same impression from "regular" people? Or are they completely unaware of it? I think transparency would help raise awareness about it.
The NSA put out a $1 billion RFP to crack the encryption of skype - their inability to listen in on this huge communication channel was really a bummer for the NSA. Microsoft says "Hmm" and buys Skype for $8 billion, re-engineers the archtecture of Skype so that it is centralized rather than P2P and easily decrypted by Law Enforcement.
Or is this only another juicy rumor? Is there any citation for this RFP from the NSA, for example?
Sure, in theory. In practice, eavsdropping on two Skype users required presence on a network route between the callers, which might have been entirely in some random country's Internet segment.
Skype's architecture is changing to match the changes in user base. As more and more tablets, phones, televisions and other devices which can't act as a supernode are added - and will be added in future - Skype needs to run more servers to pick up the slack. The notion that this is for eavesdropping purposes at the behest of the NSA is best left to the tinfoil hat brigade.
That said, you'd be ill advised to depend on Skype being more secure than a regular phone call. As a commercial service it is subject to all the kinds of pressures telco's face.
So any eavesdropping Microsoft lets law enforcement do is voluntary, whereas telcos have a legal requirement in this regards.
Metadata (call logs and such) is another story and are equally unprotected in practice.
My situation:
- I use Linux on all my desktops/laptops.
- I have an Android phone.
- My mobile phone bill is usually in excess of £100 per month.
- I am usually located in the UK, sometimes elsewhere but almost never in the US.
My use cases:
- I want to make cheap calls to mobile phone numbers in Ireland, Austria and Australia
- I want to make landline calls to the same countries.
- I want to send SMS messages to the same countries.
- I want to make free person to person VOIP calls.
- I want to make video calls.
- Security and privacy is a factor.
Currently, I have Skype working reasonably well on my 64-bit Debian based Linux machines. However, call quality can be very patchy when calling mobile phone numbers. Video quality is often poor and the call drops out when communicating with others in Australia.
I have tried Ekiga, Jitsi, SflPhone and a few others. I have a Diamondcard.us account for making chargeable calls. Almost always the call-out quality of these services is poor. I've been told it sounds like "I'm talking through a pillow."
I have been using Google Voice recently. It does work from my UK registered Google Account for making calls to mobile phones and landlines. The call quality is very good. The mobile phone pricing is generally a little more expensive than Skype. Unfortunately, landline calls are significantly more expensive that Skype and the full Google Voice experience (SMS messages, registering a number and thus using on my Android device) isn't available outside the US.
Is there any other single unified service worth considering, which does meet at least the majority of my use cases?
Lebara charge £39 a month for "unlimited" calls to 39 countries, including Ireland, and Australia, and cheap(ish) calls to Austria (and other places). Their call charges are pretty comparable to most VOIP services.
It's certainly worth considering if you're spending >£100 a month on calls.
Unfortunately for Austria mobiles (all rates include VAT):
Lebara: 19p/min
Skype: 11.2p/min (in the £38.99/month for 400 minutes package)
Google Voice: 8.4p/min
Out of the three countries I listed, Austria is the only one I call daily, usually for a minimum of 10 minutes, up to about 20 minutes. Ireland I call infrequently, but SMS up to 10 times per day. Australia I usually call once or twice per week, up to about 45 minutes.
Their rate is "unlimited" for 10EUR a month (you can setup auto payment).
The nice feature is that they give you about 200 so called "free days", which means that landlines to most countries will be totally free of charge (mobiles have low rate but you have to pay) up to 200 days from the moment of your purchase. I can confirm this works as I have called my home country in Europe every weekend for couple hours a day talking with family on multitude occasions. They have Android and iPhone app as well. If your folks oversees have landlines, this is a clearly best choice (I do not work for them, just been happy with their service).
[1] http://sflphone.org/ [2] http://www.savoirfairelinux.com/en/ [3] https://projects.savoirfairelinux.com/projects/sflphone/wiki...
There is nothing that you can do about it. Your only safety is that you are completely irrelevant for them and they keep their mouth shut unless they have a very good reason not to do so.
Such irrational defeatism.
You can use the already-available ZRTP, that requires each user to speak a phrase to the other, so you can verify by hearing the other person's voice. Discretio doesn't do any of that, so how does it know you're not talking to some random attacker?
personally i stopped using skype because i had issues on linux recently. google talk worked out of the box for me, and much much better
I dont think skype is easy just look at the UI... i dont like skype for linux it never works on my laptop...
Skype for Linux is the only software I've installed in at least 8 years, AFAIR, that has crashed my desktop session.
It's the worst sort of bug, because it leads you to believe it's working fine, when it isn't. Skype for Linux is the reason I don't use Skype any more.
Skype is capable of direct client-to-client connections, despite intervening NAT. It's pretty clever -- with the server's help as coordinator, the clients both initiate the connection, causing their own NAT routers to accept the inbound packets from the other side.
For small chat yes, Skype works, but when selling weapons and weed, no no.
Stories like this are driven mostly by unverified rumors and sensationalist journalism that is JUST as rampant in the tech industry as it is in politics, economics, or any other topic covered in mass media today.