Author Topic: CNN: Questions arise on Skype snooping  (Read 1453 times)

Offline linear

  • High Priest of Operations
  • OMG Mod
  • PLA Army
  • *****
  • Posts: 558
  • 1337 13V3L: +47/-79
  • United Phone Losers
    • United Phone Losers
CNN: Questions arise on Skype snooping
« on: October 03, 2008, 09:33:35 PM »
Questions arise on Skype snooping
updated 9:55 a.m. EDT, Fri October 3, 2008

Story Highlights
* A Chinese version of eBay's Skype communications software snoops on text chats
* Filter looks for certain sensitive keywords, including "democracy" and "Tibet"
* Revelation is of interest to rights groups that monitor Internet censorship
* It also raises questions about whether Skype enables eavesdropping elsewhere

NEW YORK (AP) -- A Canadian researcher has discovered that a Chinese version of eBay Inc.'s Skype communications software snoops on text chats that contain certain keywords, including "democracy."

The revelation is not only of interest to rights groups that monitor Internet censorship. The discovery also likely intrigues law enforcement and intelligence agencies in other countries, because they have been bothered by the growing use of Skype, which claims 338 million users across the world.

By its very nature, Skype is difficult to wiretap. Skype routes calls and chats between computers over the Internet, avoiding traditional phone networks. And the contents are supposedly encrypted, raising concerns in law enforcement that Skype could let criminals communicate without fear of eavesdropping.

The FBI has argued for applying U.S. wiretapping law to Internet phone calls. The bureau got a favorable court ruling in 2006, but it's not clear whether it applies to systems like Skype that skip telephone networks.

In the other camp, privacy advocates and security experts are concerned that Skype, while presented by the company as a secure channel of communication, has some kind of "back door" that allows eavesdropping. Whether Skypetapping is already going on in the U.S. and Europe is a matter that the company has equivocated on for years.

"For a couple of years, maybe more, people have had the suspicion ... that Skype pretends to be secure but actually isn't," said Bruce Schneier, the chief security technology officer of BT Group PLC, the British telecom carrier.

"The Chinese eavesdropping on Skype text messages only adds to the PR problems, the image problems, that Skype has among those who care about security," Schneier added.

On Wednesday, Nart Villeneuve at the University of Toronto revealed that a Chinese version of Skype's application is being used for wholesale surveillance of text messages.

The software is distributed by Skype's Chinese partner, Tom Online Inc. Skype has acknowledged since 2006 that this version looks for certain sensitive words in text chats and blocks those messages from reaching their destination. The issue appears only to affect people using the Chinese software.

What Villeneuve found was that the Tom-Skype program also passes the messages caught by the filter to a cluster of servers on Tom's network. Because of poor security on those servers, he was able to retrieve more than a million stored messages. The filter appears to look for words like "Tibet," "democracy" and "milk powder" -- China is in the throes of a food scandal involving tainted milk.

This directly contradicts a blog posting on Skype's Web site, which says that the software discards the filtered messages and neither displays nor transmits them anywhere.

On Thursday, Skype president Josh Silverman said the company learned of the message diversion only Wednesday. It alerted Tom that the messages were insecurely stored, which was quickly fixed.

"In addition, we are currently addressing the wider issue of the uploading and storage of certain messages with Tom," Silverman wrote in a statement.

Skype has earlier given contradictory statements on the eavesdropping issue.

It has told The Associated Press that it "cooperates fully with all lawful requests from relevant authorities." But when asked by CNET's News.com in June whether it could accommodate a wiretapping request, it said it could not because of the way its system works: Skype calls are encrypted, and only the two computers at each end have the keys to decrypt them.

Skype spokeswoman Jennifer Caukin said Thursday that "since its inception in 2003 Skype has never created a back door to the Skype software."

Yet both Schneier and Simson Garfinkel, an associate of the School of Engineering and Applied Sciences at Harvard University who has studied Skype's security, believe it would actually be trivial for the company to listen in on conversations.

"I can think of five or six different ways to eavesdrop on Skype. It's not that hard if you are the Skype company and want to provide legal access to law enforcement," Garfinkel said.

It's unclear whether Skype has an obligation to help law enforcement under U.S. law. Peter Swire, a professor of law at Ohio State University, said that while he knows of no U.S. court ruling that has required Skype to comply with wiretapping requests, it's conceivable that the company is voluntarily cooperating with law enforcement. Swire served as the Clinton administration's privacy czar for two years.

Skype told News.com that it had not received a subpoena or court order to perform eavesdropping.

Yet German technology site Heise Online reported in July that Austrian officials claimed to be able to listen to Skype conversations. The relative quietness of the law enforcement community on the issue in recent years could be the result of such cooperation.

The FBI did not return a call for comment Thursday.


Offline ApprenticePhreak

  • PLA Junkie
  • *****
  • Posts: 825
  • 1337 13V3L: +48/-12
Re: CNN: Questions arise on Skype snooping
« Reply #1 on: October 03, 2008, 10:05:13 PM »
tl;dr

Tell me what happened.

Offline Tachyon

  • Minister of Defence
  • OMG Mod
  • Ninja Phone Loser
  • *****
  • Posts: 1875
  • 1337 13V3L: +125/-62
Re: CNN: Questions arise on Skype snooping
« Reply #2 on: October 03, 2008, 10:10:01 PM »
The ruling powers are watching for dissidents to silence, business as usual.
Do you speak two languages?

"Detective Don Gombo: IM AFRAID THE ONLY ONE "F" IS "U" MY FRIEND. WELCOME TO THE CRIMINAL JUSTICE WEB!"

Offline linear

  • High Priest of Operations
  • OMG Mod
  • PLA Army
  • *****
  • Posts: 558
  • 1337 13V3L: +47/-79
  • United Phone Losers
    • United Phone Losers
Re: CNN: Questions arise on Skype snooping
« Reply #3 on: October 03, 2008, 10:11:00 PM »
tl;dr

Tell me what happened.

that's why CNN includes the handy "Story Highlights" bullet points at the begining of the article.


Offline ApprenticePhreak

  • PLA Junkie
  • *****
  • Posts: 825
  • 1337 13V3L: +48/-12
Re: CNN: Questions arise on Skype snooping
« Reply #4 on: October 03, 2008, 11:55:15 PM »
Oh. We're being watched over by big brother. I'd honestly assumed it was in the EULA when I agreed and installed it.

I prefer sending messages to my brothers through IRC. mIRC is for champions and filth alike.

Offline rbcp

  • Head Custodian
  • Administrator
  • Ninja Phone Loser
  • *****
  • Posts: 5259
  • 1337 13V3L: +454/-81
  • I'm not stupid! I'm not stupid! Hematology!
    • Homepage
Re: CNN: Questions arise on Skype snooping
« Reply #5 on: October 03, 2008, 11:57:28 PM »
I'd be surprised if any kind of communications wasn't monitored by The Man.

Offline linear

  • High Priest of Operations
  • OMG Mod
  • PLA Army
  • *****
  • Posts: 558
  • 1337 13V3L: +47/-79
  • United Phone Losers
    • United Phone Losers
Re: CNN: Questions arise on Skype snooping
« Reply #6 on: October 04, 2008, 01:24:54 AM »
I'd be surprised if any kind of communications wasn't monitored by The Man.

quoted for truth.