Skype backdoor confirmation
lists.randombit.net
lists.randombit.net
I would prefer Microsoft stopped scanning/reading my conversations, and I agree that what they're doing (e.g. accessing URLs) is a problem (and arguably illegal, given the recent case about someone accessing insecured AT&T URLs and going to jail).
Just think the original title could have been more clear.
"The Skype Security Policy is: ... 4. Messages transmitted through a Skype session are encrypted from Skype-end to Skype-end. No intermediary node, if any exist, has access to the meaning of these messages. [1]"
[1]: http://download.skype.com/share/security/2005-031%20security...
Aforementioned referenced on + additonal security overview/facade: http://www.skype.com/en/security/#encryption
Their hybrid peer-to-peer/client–server implementation allows for eavesdropping. This is now confirmed to be in practice.
http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa...
(this apparently does not apply to voice calls, but either does the complaint that they are picking up URLs and visiting them).
One is a feature designed to allow them to check URLs, fetch thumbnails, etc. The other is a very pivotal core decision in how Skype works.
Skype has always been primarily node-to-node. Doing p2p connections like that required signaling/directory services. In the past, users' computers were used for that functionality. After their purchase, Microsoft transitioned those signaling/directory services to the cloud.
At worst, this gives Microsoft the ability to see who is calling who, I'll grant that. Worst case scenario, you can't negotiate via STUN and UDP hole punching or UPnP port forwarding, then you will get stuck with TURN and that will route through Microsoft's servers.
So, unless someone has proof of a connection that should have established peer-to-peer and instead the call itself was routed through MS's servers TURN style.... then can we ALL please stop repeating this obnoxious rumor about MS eavesdropping on all Skype calls. Or worse yet tying it to some URL lookup service?
It may currently be for innocent purposes (check URLs, thumbnails etc as you said). However the fact is that they can make these requests at all show that the encryption is not end-to-end, otherwise they wouldn't know the URL to make a request to at all! The request isn't being made from the client, the IP shows it comes from Microsoft's servers.
So, you're talking about voice, but this is proof that the textual chat connection that should be secure end-to-end is decrypted and routed through Microsoft's servers.
I'll also continue to say how extremely disappointed I am that none of the major IM players (not Google, not Apple, not Microsoft, not Yahoo, not Facebook) wants to implement OTR encryption in their chat apps. Google even removed their fake "OTR" from the new Hangouts app, which I believe only hid your logs from yourself, not from Google themselves.
[1] - http://www.nytimes.com/2013/05/17/business/concerns-arise-on...
I was thinking about MTUA, mail, crypto/privacy and bitsync yesterday and was wondering if there could be a new mail system that would be encrypted and decentralized by default (à la bitsync/bittorrent).
Bitmessage seems to closely match what I had in mind.
Call metadata like to/from, time, and call length are stored - as is all text.
Gentlemen don't read each others mail.
While it's technically possible it's not the norm and it's hard to come up with examples of services that actually do make this promise - tarsnap is one that comes to mind.
While both Skype and Gmail store your messages (if you Skype across multiple devices, you'll see logs of conversations that happened on different devices), I don't think Gmail probes every URL you send in your messages. Also, SMTP is not always done under SSL, so, privacy cannot be assured.
But that's easily testable. I'll get back to you in a couple hours.
One automatically scans your email to show related ads, another does a HTTP HEAD request to URLs for only the server headers, which they say is for malware scanning purposes. Both are automated jobs.
See my other post to see how Google employees have access to all your email, documents, chat transcripts, Google Voice calls, Youtube videos etc. and how a few abused it to stalk teens.
https://news.ycombinator.com/item?id=5728707
As usual, Google gets a free pass and Microsoft gets demonized(they should stop claiming it's end to end encrypted, though). Looking at your HN profile, it's not hard to understand why. Thanks for being honest about disliking Microsoft but please try not to let that color your objective opinions and playing favorites regardless of facts.
If they just use it the same way that google uses gmail I fail to see the problem.
(Honestly, if you'd just asked, I would have been assumed this would have been the case anyway)
Add this to the 1,000,000 other reasons why you should never use GET requests for authentication/verification.
GET issues are primarily related to the fact that an attacker can automate their access. So they could trick a user into going to a specially crafted site, and then request content on that user's behalf via GET forgery, and return it to the web-server you control.
It is very convenient, but fairly insecure.
Sharepoint, DropBox, Owncloud, LogMeIn, Flickr, Google Docs, et al.
Private/one-time-use URLs have been a "thing" since practically forever and they're all over the place.
Would anyone here use a WebRTC-based service that also encrypted the file in transit, thus making it pretty hard for anyone other than the recipients to see it?
Then you have to give the URL to the recipient (over a secure channel), but the app will optionally allow you to not automatically send the file, but tell you how many people are connected (e.g. if there are two when you're expecting one) and begin transfer manually.
Also, I'm planning to make it all a single HTML file so you can download/verify it and store it somewhere to use whenever you like.
Of course, Skype's bot won't implement WebRTC.
They'll implement the proprietary blend that they told no one they were working on until everyone else was making serious progress with the implementation that everyone else collaborated on...
http://html5labs.interoperabilitybridges.com/prototypes/cu-r... [hm, they've actually put some money where their proposal is, I'll have to check into this more]
Obviously it's not going to be secure against coordinated attacks by governments (which I will also make clear), but my intention is to have it be secure enough for 99% of people while being easy to use. It'll at least be more secure than Dropbox/Box/Skype/whatever, which aren't secure in the slightest.
Mega, for example, might be secure, but I haven't personally seen their implementation, don't trust them not to implement any backdoors, and don't trust them not to change it. I'm aiming to make mine as small as possible, so you can verify it at pretty much a glance.
(from http://www.skype.com/en/legal/privacy/#retentionOfPersonalDa...)
Retention of Instant Messages, Voicemail Messages, and Video Messages (Skype internet communications software application only)
Your instant messaging (IM), voicemail, and video message content (collectively “messages”) may be stored by Skype (a) to convey and synchronize your messages and (b) to enable you to retrieve the messages and history where possible. Depending on the message type, messages are generally stored by Skype for a maximum of between 30 and 90 days unless otherwise permitted or required by law. This storage facilitates delivery of messages when a user is offline and to help sync messages between user devices...
From Section 8 of that same document:
Skype may use automated scanning within Instant Messages and SMS to (a) identify suspected spam and/or (b) identify URLs that have been previously flagged as spam, fraud, or phishing links. In limited instances, Skype may capture and manually review instant messages or SMS in connection with Spam prevention efforts.
If someone didn't think all of their personal electronic interactions: SMS, gmail (if you still have one), banking info weren't being cursorily evaluated by echelon or other tinfoil hat system ... blackball the moron.
I'm interested in by-invite-only HN alternatives w/ lower noise and higher signal. (I'm no longer using HN as a primary news source and refuse to disclose which I do use.)
Anyone remember this?
"A US government-mandated backdoor allowed China to hack into Gmail"
"In order to comply with government search warrants on user data, Google created a backdoor access system into Gmail accounts. This feature is what the Chinese hackers exploited to gain access."
http://www.cnn.com/2010/OPINION/01/23/schneier.google.hackin...
"At Microsoft, we take our responsibilities for protecting your privacy very seriously. It’s a priority across all our businesses, and an area where we continue to work closely with others throughout academia, government and industry."
http://blogs.windows.com/ie/b/ie/archive/2013/04/22/consumer...
"Your Privacy is Our Priority" "The lines between public and private may never be perfect, but at Microsoft we are going to keep on trying, because your privacy is our priority." https://www.youtube.com/watch?v=bt51MWll1oY
Maybe I'd get it if those campaigns came from Mozilla or DuckDuckGo (even though they are still done in poor taste, and resemble too much negative political campaigns), but Microsoft? I just can't take them seriously in regards to that. Microsoft is throwing stones from a glass house, and they should stop.
Seriously, outside of politics they are the most negative ads I've ever seen. Even rival dishsoap or gym ads never get that extreme; nothing else compares. Did they actually hire a political advertising team or something?
The simplest explanation is that reliable incumbent Microsoft was hired in some way to conveniently consolidate Skype. With as many channels through which Microsoft does business with the US government, favorable contract terms here and elsewhere could easily make the whole package worthwhile.
[1] - http://www.theregister.co.uk/2009/02/12/nsa_offers_billions_...
| One could wonder if that's one way Microsoft
| wanted to recover some of the cost of their
| investment
You could wonder, but it would seem difficult to hide $1 billion in revenue for a publicly traded company.Really? Nothing else explains why Microsoft wanted to buy talented development staff and software that was becoming the defacto name brand for video communication in homes and businesses, and which was taking market share away from Microsoft's own suite of communications solutions?
Plus, to think that skype would be exempt from the governments claim to get access to all communications and messaging data is very simple-minded. The guy does realize that today governments can access all his mails, right? SSL/TLS or not.
(so, since you're coming up with GPG which i obviously was not referring to i can also come up with some unlikely scenario, ok?)
That would basically be a wonder drug, the ultimate truth serum.
1) Barbiturates induce a hypnotic state that has widely been reported to improve subjects ability to recall details. Published work on human subjects more or less dried up in the early 70s for ethical grounds (cf. http://ist-socrates.berkeley.edu/~kihlstrm/exhumed.htm "There is, unfortunately, a virtual lack of controlled clinical studies on the accuracy of hypnotically refreshed memories."), but I bet the military have classified knowledge. Also, there's been quite a bit of published work on recall under barbiturates in dogs and rats.
2) So, you wake up with a hangover, a blackout, some bruises, and an attractive stranger in your bed. What do you assume?
3) There are drugs to suppress memories. Barbiturates, again, make it hard to recall details of the trance. Also, see http://mbldownloads.com/0205CNS_Pitman.pdf
4) Barbiturates, yet again, are well-documented to improve compliance, though at the expense of an apparent willingness to cause you to believe what you think will please the interrogator rather than what you would normally believe to be true.
Unless I was out clubbing, taking drugs without knowing what they were, (I am not in the habit of doing this...), I would get myself to a hospital and probably call the police. I'm fairly familiar with what truly excessive amounts of alcohol will do to me and that list of symptoms does not include truly blacking out without the presence of some other pretty extreme symptoms. Of course I have not gotten this drunk in years because I am an adult who knows how to moderate my own drink intake, so I would assume I was drugged regardless (if nothing else, had my drinks spiked)...
Regardless, any drug-induced blackouts that leave you coherent enough to participate in complex tasks (including recall) are unreliable at best; there is a strong chance that the victim will remember that something bad happened. Honestly it would be better to just give up on the "black out" part, drug the guy conventionally, then beat the password out of him. You will undoubtedly have better results by giving yourself fewer restrictions.
Passwords ... other people can watch you enter them, even at distance, and are easily forged, once known.
Pen & ink signatures ... the results can be replicated and are hard to verify algorithmically.
Other solutions ... meh.
Hand gesture inside a box, more inventive than the bird, determined by cameras. 3D gestures like if android unlock worked in augmented reality.
The "box," not of the Dune kind, would start folded flat and open to be sure nothing else were inside of it. Sadly, not even Thing. Folds up to create a completely discrete puppetry stage for god knows what, but sadly it wouldn't be all that interesting.
The point being that it's harder to fake or compel a performance that would basically be impossible to observe (assume trust of the system, of course, like anything... imperfect) rather than something tangible like an iris, print, voice, etc.
I'm sure the DDR ATM will be next at airports, but passwords still suck.
[1] like http://www.keelog.com/ only in small and unrecognizable
So I have reason to believe, even if we were being surveilled[1] by the (insert TLA), that they would not be able to read our email.
[1] Network only. If they're videotaping our screens, all bets are off.
Of course that excludes GPG (or pasting encrypted text into your skype chat). And that is only true as long as your law enforcement doesn't have you on surveillance. Or unless you can be 100% sure that the NSA really really really can't crack your encryption. And even Bruce Schneier isn't sure about that: https://www.schneier.com/blog/archives/2012/03/can_the_nsa_b...
I have read people speculating if it's for spam/malware protection. They screen the urls to see if it's a redirect to known malware.
GOOG would do the same, but then sell ads against the data and everyone would say the ads are ok, because they're also operating a free, and very useful service.
We might find somewhere in Skype's ToS a reference to URL checking, for any URLs you send through the service.
The URL checks could also be anonymized.
I guess that depends on your definition of "security," and perhaps of "practicality." Where I'm from (i.e. a grad student whose research is on practical secure multiparty computation), a practical system for checking URLs in a privacy-preserving fashion is still very much a research topic.
"It's easy enough to look at a text message that's going to be sent and break it into parts (URL and non-URL). Encrypt point-to-point the non-URL parts, and encrypt the URL parts such that the central servers can read them"
How is that secure? Now the third party knows what URLs you are sending in your messages.
"The URL checks could also be anonymized."
Sure, but that is not what you are seeing here. You would need a mix-net of some kind, one in which the users themselves are participating (to ensure that there is at least one honest party). It is technically possible...but you're not going to see it happen, not any time soon. With the FBI talking about building back doors into everything, what incentive is there for a company like Microsoft to actually make such a secure system?
When it comes down to it, most Skype users are too uninformed to even know how their software might betray them. On the other hand, the Justice Department could create plenty of difficulty for Microsoft if they failed to cooperate. Whose side do you think Microsoft will choose?
Which "betrayal" is worse -- Skype being able to look at messages, or compromised systems?
In terms of implementation, it's interesting to think about the design space.
There's a good way to do this though - give the users a local URL classifier and push updates to it. Then the client software is free to block dangerous URLs by default without hurting anyone's privacy. This works, and is used by many AV companies.
In fact, because of the way the system is centralized they could be sure the updates would reach users before another message did - providing the same level of safety as scanning the users' messages for them.
chrome://settings/
The difference here is that Chrome doesn't pretend to be a secure communication channel like Microsoft claims Skype is.
They're probably just checking them for Malware was my first thought and is still my only.
They also claim it's a secure communciations platform. If it was actually secure, why would microsoft be able to see it?
If the URL is sent from the receiving client to Microsoft for analysis, then Microsoft has a list of all URLs that have been communicated to you via Skype.
Either of these scenarios chips away at / tears down the idea that Skype is a 'secure' communications platform.
* Can you please recommend a cross-platform alternative?
I only know of Gnome-Empathy/KDE-Telepathy and Pidgin that utilize XMPP's voice and video features.I've found this: http://octro.com/octrotalk.php which lacks a linux client, but appears to be solid and has a web-client too.
I hope they do more marketing and seo. I didn't find Yate, even after extended web searches.
Congrats to the developers, I'll definitely try this one out!
I don't know, but I agree that if you have a secret conversation, take steps like PGP to keep it secret. Big Brother is ALWAYS listening :: usually a good preventative security motivation ;)
And best of all it's a shameless ad for a story submitted by myself. ;)
"You are correct, Skype chats and conversations are encrypted. Your chat can only be read when you sign in using your Skype name and password. Not even Skype or Microsoft has access to your chat history. "
You can see the full transcript here: http://pastebin.com/bbiSWtrz
I don't think you can trust Google with your chat and docs as well.
From:http://www.wired.com/threatlevel/2010/09/google-spy/
>Google acknowledged Wednesday that two employees have been terminated after being caught in separate incidents allegedly spying on user e-mails and chats.
>David Barksdale, 27, was fired in July after he reportedly accessed the communications of at least four minors with Google accounts, spying on Google Voice call logs, chat transcripts and contact lists, according to Gawker, which broke the story Wednesday.
http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
The difference being that Google doesn't play at being encrypted end-to-end.