More Skype Back Door Speculation
An anonymous reader writes "According to reports, there may be a back door built into Skype, which allows connections to be bugged. The company has declined to expressly deny the allegations. At a meeting with representatives of ISPs and the Austrian regulator on lawful interception of IP based services held on 25th June, high-ranking officials at the Austrian interior ministry revealed that it is not a problem for them to listen in on Skype conversations."
Two words: Network Effect. All the alternatives I have reviewed are harder than skype. Harder to download, setup, use, the list goes on.
Result: Skype is popular - they nailed delivery to the "masses". No screwing around with the microphone, NAT/firewalls, SIP providers, names etc etc. The average joe can just download and install it in just two url clicks, type in a name and begin to use it. Done deal.
All the open source VOIP (most of them SIP) I have seen completely miss this most important point, and so all their development effort is ultimately wasted - walled themselves off to the technically proficient crowd and not benefiting from the network effect.
Why must EVERY conversation on privacy boil down to a few tired questions about "open source" alternatives ?
Because open source alternatives shouldn't have backdoors. And if it does they can be identified and closed. The only reason the conversation is tiresome is because proprietary software seems to have a perpetual stream of backdoors that keep keep bringing it up.
What, like if the source code is open, then that will prevent backdoors ? Erm hello, the client software isn't the problem, it's the network of Skype servers the bloody data passes through that is the weak point in the equation.
Nobody intelligent is asking for an oss skype client. They are asking for an oss replacement to the entire skype service. For precisely the reason you stated.
So who do you trust more with your privacy ? A multi million dollar company, or some nerd in his moms basement, acting as a VOIP connectivity server.
If that nerd is just hosting as a connection service, and the voip data stream itself is end-to-end encrypted and is actually transmitted directly to the recipient, then I trust the nerd in the basement more, because he never even sees the stream, and even if he did, its encrypted.
At least as long as I know I'm -really- using the public key of the called party to encrypt it, that is. But that is biggest weakness of almost all internet uses of encryption.
In my case, I'd chose option "none of the above", but really ... open source is not the answer to ALL the worlds ills.
Not all of them. But it is the answer to this one.
Therefore, if the Chinese have no problem with Skype, Skype must have a back door.