Slashdot Mirror


Russian FSB Can Reportedly Tap Skype Calls

An anonymous reader writes "Previous reports of a Microsoft provided backdoor to Skype has been unconfirmed. However, there are now reports that Russian federal security service FSB is able to tap call and locate users. 'FSB and the Internal Affairs Ministry (MVD) have been capable to wiretap and locate Skype users for some years already, reported Vedomosti on Thursday [Google translation of Russian original]. The newspaper is citing experts on information security. "Special services have been capable for several years not only to wiretap but also to locate a Skype user. That's why, for instance, employees of our company are forbidden to discuss business-related topics on Skype," General Director of Group-IB, Ilya Sachkov, says to Vedomosti. "After Microsoft acquired Skype in May 2011, it updated the software with technology allowing legitimate wiretapping," says Maksim Emm, Director of Peak Systems.'"

19 of 136 comments (clear)

  1. Ah, the consequences of closed-source by staltz · · Score: 5, Insightful

    The Skype P2P protocol has always been an issue to worry about. It's hard to break/understand, and I've seen research papers that just scratched the surface of the protocol.

    I never doubted that really smart minds (like Russians) would eventually crack it and exploit it. This would never happen with an open-source protocol.

    1. Re:Ah, the consequences of closed-source by iggymanz · · Score: 4, Interesting

      no one with a smart mind cracked it, microsoft just rolled over for the russian government

    2. Re:Ah, the consequences of closed-source by Pi1grim · · Score: 3, Insightful

      Ofcource if I worked for FSB and was unable to tap into Skype, I'd start spreading FUD about how well I can tap into it. To make them more over to less secure means of communication.
      Anyway, I hope this will lead to boost in developing a solution with good crypto. Like jingle or SIP with encyption and it's wide adoption. Not that it's happening anytime soon, but a man can dream...

    3. Re:Ah, the consequences of closed-source by LordLimecat · · Score: 3, Funny

      Since when has "knowing what youre talking about" been a requirement to post on slashdot?

    4. Re:Ah, the consequences of closed-source by gl4ss · · Score: 3, Interesting

      they're acting as if they were a phone company and russkies are probably asking them to comply as if they were one.. to provide taps.
      and they're just locating the ip address of course. it's not like their tap is made of magic sauce.

      +they would spread fud about it anyways.
      the big problem with it if you're discussing sensitive things is plain and simply that it has centralized control.

      SECOND OPTION: it's entirely possible the russkies are tapping them on client side. if not by other means then by bugging the headsets. that would certainly explain how they know EXACTLY where the call is taking place since they're spying the site in person. it's fsb/kgb after all.

      --
      world was created 5 seconds before this post as it is.
    5. Re:Ah, the consequences of closed-source by benjfowler · · Score: 3, Informative

      Microsoft regularly rolls over for the Chinese government too.

      Microsoft has never met a dictator or despot they didn't like.

    6. Re:Ah, the consequences of closed-source by fustakrakich · · Score: 5, Insightful

      Microsoft has never met a dictator or despot they didn't like.

      Nor has any other business approaching the size of Microsoft. In fact, nobody can get that big without 'assistance' from the authorities. Despotism is big business, the rewards are well worth the collateral damages.

      --
      “He’s not deformed, he’s just drunk!”
    7. Re:Ah, the consequences of closed-source by K.+S.+Kyosuke · · Score: 3, Funny

      Microsoft has never met a dictator or despot they didn't like.

      What about Steve Jobs? *ducks*

      --
      Ezekiel 23:20
    8. Re:Ah, the consequences of closed-source by camperdave · · Score: 3, Informative

      Microsoft regularly rolls over for the Chinese government too.

      Microsoft has never met a dictator or despot they didn't like.

      Microsoft has never met an entity with a boatload of cash they didn't like.

      FTFY

      --
      When our name is on the back of your car, we're behind you all the way!
    9. Re:Ah, the consequences of closed-source by Anonymous Coward · · Score: 3, Informative

      Why not? If a protocol was open source, writing backdoors into it would be even easier. I mean, how many people know how to inspect code and remove the parts that are malicious?

      You obviously do not understand open source. If a protocol or software gets big enough that a lot of people use it, it will also get a lot of developers looking at it. If a backdoor is written in, eventually someone will find it and report/patch it.

    10. Re:Ah, the consequences of closed-source by RabidReindeer · · Score: 3, Interesting

      This would never happen with an open-source protocol.

      Why not? If a protocol was open source, writing backdoors into it would be even easier. I mean, how many people know how to inspect code and remove the parts that are malicious?

      Not many, I'm sure. But even one is sufficient. And unlike closed-source, that one person may pop up any time, anywhere in the world, including places where it's not possible for interested governments to muzzle him in time to raise the alert.

      One of the reasons WHY open-source is so popular is that things like that can occur, hence open-source people are more likely to pay attention to how secure the stuff they're using is. And conversely, paranoid people will prefer open-source.

      The best time to worry about security is before you need to. Afterwards, it may be too late.

    11. Re:Ah, the consequences of closed-source by bruce_the_loon · · Score: 3, Informative

      Yeah, MS rolled over for the Russian government six years before they bought Skype. Good future planning on Balmer's part.

      The reading comprehension skills here astound me.

      --
      Trying to become famous by taking photos. Visit my homepage please.
  2. Closed source. Closed standards by Albanach · · Score: 3, Insightful

    And therein we learn the lesson about closed source software and proprietary methods. If folk had adopted something based on SIP, XMPP, IAX or any other open and documented protocol, we'd be able to communicate using a tried and tested security mechanism.

    For something like communications, if you're totally and absolutely reliant upon a third party then you also need to have total and absolute trust in that third party or you should consider all your communications using them to be public.

  3. How shocking! by Rosco+P.+Coltrane · · Score: 4, Insightful

    Closed source software with obscure network protocol, now owned by a corporation whose main concern isn't the users' best interest, turns out to be not so nice after all. News at 10...

    The best way to do use Skype for anything more important than saying hello to your grandmother for free on the internet is not to use Skype. Everybody with half a brain has known that for many years.Duh...

    --
    "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
  4. Re:A reminder. by RabidReindeer · · Score: 5, Insightful

    Soviet Union was disbanded in the 90's

    And????

    Russia still remains. The KGB is now the FSB. Russia is more open, but it's still not the USA.

    And speaking of the USA, you do realize that Project Echelon and similar efforts have been busily tapping into communications in the Land of the Free for longer than there was a Skype?

  5. Maybe they should tell the French? by Eunuchswear · · Score: 3, Funny

    Would save a lot of trouble.

    --
    Watch this Heartland Institute video
  6. Re:A reminder. by Nerdfest · · Score: 4, Insightful

    You speak of the US as if they wouldn't do exactly the same thing (and almost certainly are). This is why there should be an open implementation that supports proper security.

  7. Special services by ls671 · · Score: 3, Insightful

    Special services have been capable for several years not only to wiretap but also to locate a Skype user.

    Special services have been capable for several years not only to wiretap but also to locate cellular phone and landline users.

    --
    Everything I write is lies, read between the lines.
  8. Re:Jitsi by bill_mcgonigle · · Score: 3, Insightful

    aka "The Path to Idiocracy". It's true, though, and it should be an object lesson that technically sound software needs to be trivially easy to install and configure as well if it's to do much societal good.

    --
    My God, it's Full of Source!
    OUTSIDE_IP=$(dig +short my.ip @outsideip.net)