EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS


Microsoft Skype Messaging Surveillance Not the Main Issue, Audio Recording (Bugging) and Computer Hijacking Are

Posted in GNU/Linux, Microsoft, Windows at 12:03 pm by Dr. Roy Schestowitz

Nokia phone

Summary: Debates about the dangers of Skype focus on one of the least dangerous aspects of Skype

THE PROBLEM with Skype is not quite what The H focuses on. Microsoft claims to be scanning people’s conversations to mitigate the threat of phishing scams and such, but this doesn’t quite compute unless they only ever test for redirections in HEAD. To say that Skype is tracking people’s conversations would not be shocking because even years ago (before Skype was taken up by Microsoft and the NSA) China was given access to text conversations for censorship purposes (similar to security purposes in the practical sense). This is well documented in news sites, especially in Western news sites that like to berate China over practices that the West too harbours, but always under plausible denial clauses.

For those who have not seen the widely-syndicated and discussed report from Heise (or The H), in English the summary says: “A Microsoft server accesses URLs sent in Skype chat messages, even if they are HTTPS URLs and contain account information. A reader of Heise publications notified Heise Security (link to German website, Google translation). They replicated the observation by sending links via Skype, including one to a private file storage account, and found that these URLs are shortly after accessed from a Microsoft IP address. When confronted, Microsoft claimed that this is part of an effort to detect and filter spam and phishing URLs.”

“The H and heise Security believe that, having consented to Microsoft using all data transmitted over the service pretty much however it likes, all Skype users should assume that this will actually happen and that the company is not going to reveal what exactly it gets up to with this data.”
      –The H
As the article in The H puts it: “Anyone who uses Skype has consented to the company reading everything they write. The H’s associates in Germany at heise Security have now discovered that the Microsoft subsidiary does in fact make use of this privilege in practice. Shortly after sending HTTPS URLs over the instant messaging service, those URLs receive an unannounced visit from Microsoft HQ in Redmond.

“A reader informed heise Security that he had observed some unusual network traffic following a Skype instant messaging conversation. The server indicated a potential replay attack. It turned out that an IP address which traced back to Microsoft had accessed the HTTPS URLs previously transmitted over Skype. Heise Security then reproduced the events by sending two test HTTPS URLs, one containing login information and one pointing to a private cloud-based file-sharing service.”

Microsoft’s excuses didn’t pass muster (the security excuse for surveillance, where all they can really test for is a redirection). “In summary,” says the author, “The H and heise Security believe that, having consented to Microsoft using all data transmitted over the service pretty much however it likes, all Skype users should assume that this will actually happen and that the company is not going to reveal what exactly it gets up to with this data.”

And from the comments we learn it’s worse than The H originally put it: “We tested it at mooncascade.com. I can confirm there is correlation between URL-s in Skype chats and web server access logs with traces from Redmond. There are both https and http accesses.”

Another commenter says:

So much about the “AES encryption” Skype promisses:

> All Skype-to-Skype voice, video, and instant message conversations
> are encrypted. This protects you from potential eavesdropping by
> malicious users.
> (https://support.skype.com/en/faq/FA31/does-skype-use-encryption)

Aparently, this falls into the same category as “McDonalds food is
healty and tastes good”.

This whole debate, unfortunately, misses a key point; not just text conversations are being tracked but voice ones (relayed through US infrastructure) — the bread and butter of Skype — are also being tracked and Skype as a binary ensures not only that Windows is hijackable, as we showed before, but that all platforms are rendered hijackable when Skype is running in the background (Skype has no intention of addressing these issues). The debate should be altered to take account of these much greater threats. By the way, on Windows it doesn’t even take Skype to hijack a computer; Microsoft has just admitted that exploits in the wild exist that help hijack Windows through a built-in program and there is also software that lets people’s Facebook accounts get hijacked through Windows, including on Vista 8 (the operating system which hardly sells, leading Microsoft to lies and inexcusable disinformation).

“A much rarer event, however, is one of Redmond’s own unloading publicly on the faults of not only Windows, but Microsoft’s company culture.”
The Free Software Foundation has long been campaigning against Skype, even before Microsoft took over. GNU/Linux with SKype binaries is just about as compromisable as other platforms. The weakest link counts. It is worth noting that even a Windows developer admits that Windows is inferior to Linux, stirring up further debate. As Gizmodo put it: “Right now, somewhere on the internet, there is a flame war occurring between devotees of Linux and Windows. It’s just the nature of passionate software evangelism. A much rarer event, however, is one of Redmond’s own unloading publicly on the faults of not only Windows, but Microsoft’s company culture.”

At Microsoft, backdoors are not a bug; sometimes they are a feature. Since nobody among the users can inspect the code or thoroughly interpret the binaries, it’s hard to remove the backdoors, let alone prove their existence.

“You assist an evil system most effectively by obeying its orders and decrees. An evil system never deserves such allegiance. Allegiance to it means partaking of the evil. A good person will resist an evil system with his or her whole soul.”Mahatma Gandhi

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New

  1. Željko Topić Tries to Do to EPO Staff What He Did in Croatia, Now Crushes Staff Assembly in The Hague

    Reminder to European Patent Office (EPO) staff that the EPO's management has a history of union-busting and serious violations of the rules; a call to join protests later today and later this week

  2. The Spanish EPO Scandal - Part I

    How García-Escudero Marquez, the sister of a Spanish Senate speaker, got controversially appointed to succeed the (now) EPO's Vice-President Alberto Casado Cerviño

  3. Media Alert: IAM 'Magazine' Does Not Protect Sources

    An important discussion regarding the role of IAM (Intellectual Asset Management) in the debate about EPO abuses

  4. Richard Stallman and Eben Moglen on the Microsoft-Red Hat Deal

    Founder of Free software and author of the GPL (respectively) comment on what Microsoft and Red Hat have done regarding patents

  5. Links 30/11/2015: Linux 4.4 RC3, Zaragoza Moving to FOSS

    Links for the day

  6. Public Protests by European Patent Office (EPO) Staff Weaken the EPO's Attacks on the Media

    Where things stand when it comes to the EPO's standoff against publications and why it's advisable for EPO staff to stage standoffs against their high-level management, which is behind a covert crackdown on independent media (while greasing up corporate media)

  7. Why the European Patent Office Cannot Really Sue and Why It's All -- More Likely Than Not -- Just SLAPP

    Legal analysis by various people explains why the EPO's attack dogs are all bark but no bite when it comes to threats against publishers

  8. How the EPO Twisted Defamation Law in a Failed Bid to Silence Techrights

    Using external legal firms (not the EPO's own lawyers), the EPO has been trying -- and failing -- to silence prominent critics

  9. East Texas and Its Cautionary Tale: Software Patents Lead to Patent Trolls

    Lessons from US media, which focuses on the dire situation in Texas courts, and how these relate to the practice of granting patents on software (the patent trolls' favourite weapon)

  10. The Latest EPO Spin: Staff Protesters Compared to 'Anti-Patent Campaigners' or 'Against UPC'

    Attempts to characterise legitimate complaints about the EPO's management as just an effort to derail the patent office itself, or even the patent system (spin courtesy of EPO and its media friends at IAM)

  11. The Serious Implication of Controversial FTI Consulting Contract: Every Press Article About EPO Could Have Been Paid for by EPO

    With nearly one million dollars dedicated in just one single year to reputation laundering, one can imagine that a lot of media coverage won't be objective, or just be synthetic EPO promotion, seeded by the EPO or its peripheral PR agents

  12. EPO: We Have Always Been at War With Europe (or Europeans)

    The European Patent Office (EPO) with its dubious attacks on free speech inside Europe further unveiled for the European public to see (as well as the international community, which oughtn't show any respect to the EPO, a de facto tyranny at the heart of Europe)

  13. What Everyone Needs to Know About the EPO's New War on Journalism

    A detailed list of facts or observations regarding the EPO's newfound love for censorship, even imposed on outside entities, including bloggers (part one of several to come)

  14. EPO Did Not Want to Take Down One Techrights Article, It Wanted to Take Down Many Articles Using Intimidation, SLAPPing, and Psychological Manipulation Late on a Friday Night

    Recalling the dirty tactics by which the European Patent Office sought to remove criticism of its dirty secret deals with large corporations, for whom it made available and was increasingly offering preferential treatment

  15. The European Private Office: What Was Once a Public Service is Now Crony Capitalism With Private Contractors

    The increasing privatisation of the European Patent Office (EPO), resembling what happens in the UK to the NHS, shows that the real goal is to crush the quality of the service and instead serve a bunch of rich and powerful interests, in defiance of the original goals of this well-funded (by taxpayers) organisation

  16. Microsoft Once Again Disregards People's Settings and Abuses Them, Again Pretends It's Just an Accident

    A conceited corporation, Microsoft, shows not only that it exploits its botnet to forcibly download massive binaries without consent but also that it vainly overrides people's privacy settings to spy on these people, sometimes with help from malicious hardware vendors such as Dell or Lenovo

  17. When the EPO Liaised With Capone (Literally) to Silence Bloggers, Delete Articles

    A dissection of the EPO's current media strategy, which involves not only funneling money into the media but also actively silencing opposing views

  18. Blogger Who Wrote About the EPO's Abuses Retires

    Bloggers' independent rebuttal capability against a media apparatus that is deep in the EPO's pocket is greatly diminished as Jeremy Phillips suddenly retires

  19. Leaked: EPO Award of €880,000 “in Order to Address the Media Presence of the EPO” (Reputation Laundering)

    The European Patent Office, a public body, wastes extravagant amounts of money on public relations (for 'damage control', like FIFA's) in an effort to undermine critics, not only among staff (internally) but also among the media (externally)

  20. Links 27/11/2015: KDE Plasma 5.5 Plans, Oracle Linux 7.2

    Links for the day

  21. Documents Needed: Contract or Information About EPO PR/Media Campaign to Mislead the World

    Rumour that the EPO spends almost as much as a million US dollars “with some selected press agencies to refurbish the image of the EPO”

  22. Guest Post: The EPO, EPC, Unitary Patent and the Money Issue

    Remarks on the Unitary Patent (UP) and the lesser-known aspects of the EPO and EPC, where the “real issue is money, about which very little is discussed in public...”

  23. Saving the Integrity of the European Patent Office (EPO)

    Some timely perspective on what's needed at the European Patent Office, which was detabilised by 'virtue' of making tyrants its official figureheads

  24. A Call for Bloggers and Journalists: Did EPO Intimidate and Threaten You Too? Please Speak Out.

    An effort to discover just how many people out there have been subjected to censorship and/or self-censorship by EPO aggression against the media

  25. European Patent Office (EPO) a “Kingdom Above the EU Countries, a Tyranny With ZERO Accountability”

    Criticism of the EPO's thuggish behaviour and endless efforts to crush dissenting voices by all means available, even when these means are in clear violation of international or European laws

  26. Links 26/11/2015: The $5 Raspberry Pi Zero, Running Sans Systemd Gets Hard

    Links for the day

  27. EPO Management Needs to Finally Recognise That It Itself is the Issue, Not the Staff or the Unions

    A showing of dissent even from the representatives whom the EPO tightly controls and why the latest union-busting goes a lot further than most people realise

  28. Even the EPO Central Staff Committee is Unhappy With EPO Management

    The questions asked by the Central Staff Committee shared for the public to see that not only a single union is concerned about the management's behaviour

  29. The Broken Window Economics of Patent Trolls Are Already Coming to Europe

    The plague which is widely known as patent trolls (non-practicing entities that prey on practicing companies) is being spread to Europe, owing in part to misguided policies and patent maximalists

  30. Debunking the EPO's Latest Marketing Nonsense From Les Échos and More on Benoît Battistelli's Nastygram to French Politician

    Our detailed remarks about French brainwash from the EPO's media partner (with Benoît Battistelli extensively quoted) and the concerns increasingly raised by French politicians, who urge for national or even continental intervention


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time


Recent Posts