7 ms·
Open Letter to Skype from Internet Activists, Journalists and Academics
- lampe 14y agothere alternatives to skype that are open sourced and you can look up what security features they got. http://en.wikipedia.org/wiki/Comparison_of_VoIP_software http://en.wikipedia.org/wiki/Comparison_of_VoIP_software
- nodata 14y agoSkype is popular because it just worked, even through funky firewalls. The replacement would need to be better than Skype to gain traction with non-technical users.
- lampe 14y agoskype just uses an http tunnel cause mostly the 80 port is open so no magic here(it does some more tricks but this is on). I dont think skype is easy just look at the UI... i dont like skype for linux it never works on my laptop...
- pbhjpbhj 14y agoI'm not keen on some of the recent changes to Skype but I don't really consider "Skype for Linux" to actually be Skype. Skype is actually the only reason beyond dev testing that I keep MS Windows. Skype for Linux is the only software I've installed in at least 8 years, AFAIR, that has crashed my desktop session.
- StavrosK 14y agoI wish all it did would be to crash my session. Mine would go into an endless loop or something, consuming 100% CPU. Everything would still appear to be working fine, only I couldn't make any calls, my chats wouldn't be delivered, etc. This happens around once every five minutes, and I have missed important meetings because Skype had hung and I was wondering why the person I was waiting for hadn't logged in yet, only to be asked where I was later. It's the worst sort of bug, because it leads you to believe it's working fine, when it isn't. Skype for Linux is the reason I don't use Skype any more.
- ef4 14y agoIt's a bit smarter than just using an http tunnel. Skype is capable of direct client-to-client connections, despite intervening NAT. It's pretty clever -- with the server's help as coordinator, the clients both initiate the connection, causing their own NAT routers to accept the inbound packets from the other side.
- 0x0 14y agoThat's also called STUN, I believe http://en.wikipedia.org/wiki/STUN http://en.wikipedia.org/wiki/STUN (or probably a variant)
- BrokenPipe 14y agoI think that's called hole punching http://en.wikipedia.org/wiki/Hole_punching http://en.wikipedia.org/wiki/Hole_punching
- huhtenberg 14y agoSkype's overall quality has been on a very steady decline recently. From call quality, to call drops, to offline contacts showing as online and vice versa, to privacy concerns - Skype's position has never been weaker. It still got an obvious momentum, but it is actively pissing of a lot of its users.
- decourl 14y agoHow did the internet get so dumbed down? Cloud this and web app that and now nobody knows how to research or install any normal software. Or do anything that isn't shiny packaged at $10+ a month?
- LatvjuAvs 14y agoHuman creativity sees no walls. Tor this, tor that, onions on the rise! For small chat yes, Skype works, but when selling weapons and weed, no no.
- nakedrobot2 14y agoHas there been any confirmation of the very juicy rumor about Skype and the NSA? Brieftly it is this: The NSA put out a $1 billion RFP to crack the encryption of skype - their inability to listen in on this huge communication channel was really a bummer for the NSA. Microsoft says "Hmm" and buys Skype for $8 billion, re-engineers the archtecture of Skype so that it is centralized rather than P2P and easily decrypted by Law Enforcement. Or is this only another juicy rumor? Is there any citation for this RFP from the NSA, for example?
- pieter 14y agoSkype has always relied on a central authentication server, which means that anyone with control of that server would be able to MITM any conversation. The recent changes of ownership and centralization of the service have nothing to do with this. Presumably the US government has been able to tap into any Skype conversation they want for a long time.
- pandog 14y agoI'm not sure if it makes it easier to listen in on calls but Microsoft have made changes to the skype infrastructure: http://arstechnica.com/business/2012/05/skype-replaces-p2p-supernodes-with-linux-boxes-hosted-by-microsoft/ http://arstechnica.com/business/2012/05/skype-replaces-p2p-s...
- eps 14y ago> would be able to MITM any conversation Sure, in theory. In practice, eavsdropping on two Skype users required presence on a network route between the callers, which might have been entirely in some random country's Internet segment.
- pieter 14y agoNot really -- the directory server can just direct a user to connect to a MITM server. There's no need to control the entire network, you only need access to Skype's servers.
- 14y ago
- avar 14y agoOpen comment to Internet Activists, Journalists and Academics: You're not going to get what you want by piggy-backing on Microsoft's proprietary platform. Specifically if you're an Internet Activists you shouldn't be relying on some company's proprietary tool for disguising your communications. There's plenty of open and secure VoIP clients which coupled with open encryption standards, VPN's etc. will suit your purposes. Use those things, not Skype.
- magikarp 14y agoIf you're someone who reads Hacker News then sure, you already know better than to rely on a closed platform. But many in Syria don't.
- polymatter 14y agoI only know about Tor (https://www.torproject.org https://www.torproject.org) which could help. I hope someone else can recommend any others.
- StavrosK 14y agohttps://silentcircle.com/ https://silentcircle.com/ aims to do just that, secure communications. Disclosure: I work there.
- dmix 14y agoPhil Zimmermann founded this? Nice. Although I remember reading about the lack of open source and the odd terms of service wording. http://log.nadim.cc/?p=89 http://log.nadim.cc/?p=89 Is that still being addressed?
- StavrosK 14y agoOkay, before I say anything, this isn't official in any way, as I only work on the web-facing side, so this is just my experience: I couldn't really respond about either, because I don't know, but I know that the Silent Text sources are on GitHub: https://github.com/SilentCircle/silent-text https://github.com/SilentCircle/silent-text The rest of the clients's code is probably being cleaned up, but I guess we're trying to build more functionality and are very busy with other stuff, and publishing the code has fallen behind a bit. That's just my guess, as, as I said, I don't work on that. From what I've seen in my time there, though, everyone is extremely capable (I have yet to see a single thing that wasn't done correctly) and very focused on security (again, I have yet to find fault with something, and I'm really paranoid). From what I've seen (and this probably comes off a bit too PR-y, but it's true), I have absolutely no problem trusting SC with my communications, everyone takes every precaution to safeguard users' data (even in the web part, we don't want to use third-party services, our analytics are hosted by us) to avoid compromising users' data. Anyway, I've raved too long about this. I'll just say I'm very happy to work there.
- vadiml 14y agoFolks please try Discretio for Android (https://play.google.com/store/apps/details?id=com.discretio.android https://play.google.com/store/apps/details?id=com.discretio....) Open source (GPLv3) secure VOIP solution. For the moment only Android version is available but iOS and desktop vresions are in the queue...
- StavrosK 14y agoThat doesn't sound very convincing. You can't just have some icons tell you that you're secure, how do they know if someone's MITMing you? You can use the already-available ZRTP, that requires each user to speak a phrase to the other, so you can verify by hearing the other person's voice. Discretio doesn't do any of that, so how does it know you're not talking to some random attacker?
- vadiml 14y agoThe client side source code is available: https://bitbucket.org/repo/all?name=discretio https://bitbucket.org/repo/all?name=discretio
- StavrosK 14y agoI saw that, but I didn't see any explanation on how it works, and I'm pretty sure it's impossible to have security without verification. I can't read the code to verify that, sadly.
- Discretio 14y agoCurious to hear from someone working in a company who says things but not show it's true. In fact, if i say i am rich, tall, blond with a famous sense of humour, you are ready to believe me, but if i don't say anything but i prove it, you refuse to believe me... strange. Discretio doesn't say anything of this kind but show the entire client software source code. Do the same please.
- 14y ago
- dhimes 14y agoWhat is the best linux-compatibile open source with encryption alternative at the moment? The wiki page shows that many haven't been updated in quite some time (Twinkle). Does anybody have experience with Blink?
- aw3c2 14y agoJitsi is amazing!
- zorlem 14y agoI personally like SFLPhone [1]. It's developed by the fine folks from Savoir-faire Linux [2] and supports encryption. Here is a guide how to configure it to encrypt traffic between the client and an Asterisk server [3]. [1] http://sflphone.org/ http://sflphone.org/ [2] http://www.savoirfairelinux.com/en/ http://www.savoirfairelinux.com/en/ [3] https://projects.savoirfairelinux.com/projects/sflphone/wiki/Security https://projects.savoirfairelinux.com/projects/sflphone/wiki...
- phillc73 14y agoI have searched and searched for an alternative to Skype, but so far have mostly failed. My situation: - I use Linux on all my desktops/laptops. - I have an Android phone. - My mobile phone bill is usually in excess of £100 per month. - I am usually located in the UK, sometimes elsewhere but almost never in the US. My use cases: - I want to make cheap calls to mobile phone numbers in Ireland, Austria and Australia - I want to make landline calls to the same countries. - I want to send SMS messages to the same countries. - I want to make free person to person VOIP calls. - I want to make video calls. - Security and privacy is a factor. Currently, I have Skype working reasonably well on my 64-bit Debian based Linux machines. However, call quality can be very patchy when calling mobile phone numbers. Video quality is often poor and the call drops out when communicating with others in Australia. I have tried Ekiga, Jitsi, SflPhone and a few others. I have a Diamondcard.us account for making chargeable calls. Almost always the call-out quality of these services is poor. I've been told it sounds like "I'm talking through a pillow." I have been using Google Voice recently. It does work from my UK registered Google Account for making calls to mobile phones and landlines. The call quality is very good. The mobile phone pricing is generally a little more expensive than Skype. Unfortunately, landline calls are significantly more expensive that Skype and the full Google Voice experience (SMS messages, registering a number and thus using on my Android device) isn't available outside the US. Is there any other single unified service worth considering, which does meet at least the majority of my use cases?
- EwanToo 14y agoThe first 3 of your requirements would possibly be better served with just a good International calling package on your mobile. Lebara charge £39 a month for "unlimited" calls to 39 countries, including Ireland, and Australia, and cheap(ish) calls to Austria (and other places). Their call charges are pretty comparable to most VOIP services. It's certainly worth considering if you're spending >£100 a month on calls.
- phillc73 14y agoWorth considering for sure and a good idea to investigate similar services more thoroughly. Unfortunately for Austria mobiles (all rates include VAT): Lebara: 19p/min Skype: 11.2p/min (in the £38.99/month for 400 minutes package) Google Voice: 8.4p/min Out of the three countries I listed, Austria is the only one I call daily, usually for a minimum of 10 minutes, up to about 20 minutes. Ireland I call infrequently, but SMS up to 10 times per day. Australia I usually call once or twice per week, up to about 45 minutes.
- verdverm 14y agoWhats the deal with Google voice and Google talk on this issue?
- josteink 14y agoNot available in most countries in the world, perhaps?
- verdverm 14y agoi read somewhere that their video chat can run on 380kbs connections, i would assume its in the works. they did buy drones for Africa personally i stopped using skype because i had issues on linux recently. google talk worked out of the box for me, and much much better
- gesman 14y agoOpen reply from Ballmer to *ists: "My way or highway"
- jjoergensen 14y agoThe governments in many countries are monitoring everything that you are doing. It is no longer a fictitious idea about what could be done. They collect and correlate sets of data and they use it for monitoring for abnormal behaviour and find potential threats. There is nothing that you can do about it. Your only safety is that you are completely irrelevant for them and they keep their mouth shut unless they have a very good reason not to do so.
- Karunamon 14y ago>There is nothing that you can do about it. Such irrational defeatism.
- nathan_long 14y agoApparently they weren't briefed on the business model: http://www.youtube.com/watch?v=w8c_m6U1f9o http://www.youtube.com/watch?v=w8c_m6U1f9o
- Nordichacker 14y agoYou just need to assume that everything you do on skype can be intercepted. If you want secure communications, choose something else.
- marme 14y agoThe problem with complain to microsoft about this is they are locked into some of these things with deal skype setup before they were bought out. Microsoft is contractually obligated to only supply skype TOM in china, this is the reason why they wont shutdown MSN in china because they are unable to control the skype network within china. You cant expect microsoft to reveal all these things while they are trying to clean house and get skype in order. Dont hold your breath on microsoft revealing anything
- shaaaaawn 14y agoWould love to see something similar as what google does for transparency. Even better an common standard for transparency
- decourl 14y agoPretty sure Google will remain the oddball in the bunch. Nobody wants to reveal all that.
- arindone 14y agoRecurring transparency report? Have you ever asked Google for such things when it reads your emails to sell you ads? Have you ever asked Target or Walmart for this when they track your credit card purchases and sell the ACTUAL data to other parties? Stories like this are driven mostly by unverified rumors and sensationalist journalism that is JUST as rampant in the tech industry as it is in politics, economics, or any other topic covered in mass media today.
- deleted 14y ago[deleted]