4 ms·
248 percent: The increase in 2012 in the number of Skype communications intercepted via PRISM Is Skype no longer end-to-end encrypted? I'm surprised to see it
by uvdiv 13y ago
248 percent: The increase in 2012 in the number of Skype communications intercepted via PRISM
Is Skype no longer end-to-end encrypted? I'm surprised to see it confirmed (?) that NSA is siphoning up Skype video. How does this MITM work technically?
- nallerooth 13y agoYou might be interested in this article. http://www.h-online.com/security/news/item/Skype-with-care-Microsoft-is-reading-everything-you-write-1862870.html http://www.h-online.com/security/news/item/Skype-with-care-M... (Microsoft visiting all HTTPS-links sent over skype). They do, however, still tell you that the connection is end-to-end encrypted http://download.skype.com/share/security/2005-031%20security%20evaluation.pdf http://download.skype.com/share/security/2005-031%20security... (See section 1.2, Security Policy). Now, if they can read all your links using https, they can read anything else too. Edited: Spelling
- tetha 13y agoJust pondering wordplays: Assume I implement a messenger, and I want to obtain full access to messages, but I also want to be able to put "end-to-end encrypted" on my product. Couldn't I go ahead and encrypt everything with an encryption system where I know all the keys? It end-to-end encrypted, since your client encrypts and my client decryptys and hey, it might even be some good asymmetric encryption, but nothing matters as long as I don't disclose my key management or, even better, put all key management into your hands. And even worse, if I don't give my transmission servers access to these keys, "no intermediate node" has access to this information, because only secondary nodes have access to the information. It's a scary twist of words, but I dunno... I could probably convince a lot of standard users with such smoke and mirrors.
- nallerooth 13y agoI completely agree. For a couple of years, I've been living by the rule "If it's supposed to be secret, don't put it anywhere near the Internet". The problem is that a lot of people trust statements like "unbreakable encryption" and "your password cannot be recovered, by any means". My biggest issue, in a way, is the stupidity of claiming to have end-to-end encryption and then visit https-URIs sent via Skype.
- ghshephard 13y agoThey can intercept your meta data (when, who, how long) you communicated without getting access to content.
- uvdiv 13y agoI understand it's the content, not "merely" metadata, that's being siphoned. That's what I got from the WaPo article.
- flyinRyan 13y agoSkype was p-t-p until MS bought it and made it more centralized. Wonder why they would do something like, i.e. make it more expensive to maintain and provide less service.