Wednesday, 8 June 2011

Some thoughts

Why security and trust is important.


[politics on]

I rethinking all of this.

In other words, Skype got caught in Egypt to provide not SAME level of security for all skype users.

Think something about not viruses or trojans or local audio channel compromise.

But about MITM attack with uncorrected signed by skype CA suspected users 'skypename' certificate. For allow Man-in-the-middle attacks.

Or better way.
Signed by Skype 'minor update' which contain government spyware code for monitor dissident activity(and stealing they private keys and/or skype passwords). Even more, it not should be a 'signed spyware', but voice codec, with security hole, or something like that. Big brother calling you. Oops. You got owned. Ha-ha!

This is major security breach in encryption infrastructure. Which apparently they allow it. And now was down for this 'unfair' action.

C'est la vie.

P.S. I bet what they 'playing to the end'(endgame) with they 'high prices' eyesdropping solutions.
Which they start providing since Facebook and Twitter revolutions or even more early.

[politics off]

P.S.

So, yet some facts to thinks about Skype Inc(main RSA secret of PKI) - Certificate Authority private key - Compromised.

Compromised by owners.

For money.

24 comments:

  1. you are too clever to been russian hacker from village... how drives you?

    ReplyDelete
  2. Yes, there must be a reason why MS wanted to pay 2x what Facebook and Google offered.

    ReplyDelete
  3. hahaha... some time ago Google got Gizmo. And now Gizmo closed. Its just for client database ;)

    ReplyDelete
  4. May be we should think about zfone..

    ReplyDelete
  5. I like this. Eyesdrop on eyesdroppers.

    ReplyDelete
  6. Skype was not approved to run on Linux Debian because itś 'black box' kind libraries and not well behaviored code. Linux deserves a program that can handle that protocol safely.

    ReplyDelete
  7. Someone? http://jitsi.org/

    ReplyDelete
  8. This one looks nice - http://ekiga.org/

    ReplyDelete
  9. Ekiga also have zfone. So, calls can be easy encrypted via pgp.

    See this:
    https://help.ubuntu.com/community/Ekiga#line-338

    ReplyDelete
  10. GNU free call

    ReplyDelete
  11. Making ekiga support skype's protocol would quite awesome !

    ReplyDelete
  12. if you’re so smart and awesome, why don’t you create your own open source YAVIPS (Yet Another VoIP Service)?
    stop fucking with skype

    ReplyDelete
  13. There wasn't any news for almost one month. Are you going to continue working on this project?

    ReplyDelete
  14. There are not uch people capable of doing such hard work, I wish you the best luck. Beeing able to rely completely on open-source software is always a great thing, in order to be a little bit more secure from government repression.

    ReplyDelete
  15. Port Ekiga to iPhone and Android, and make it work without playing with firewall settings, then people will switch.

    Also, censorship is bad, so keep reverse engineering their protocol. The DMCA was unconstitutional, and was a greedy, corporate law. If it were around in 1980, there'd be no PC at your desk. :)

    ReplyDelete
  16. EA reverse engineered the Sega Genesis, without EA doing that they would have never become the gaming company they are today. Keep up the good work.

    ReplyDelete
  17. @Zach
    @Anonymous

    Thanks. Nice to hear.

    ReplyDelete
  18. Reverse engineering Skype was something I've thought of doing myself but never got the time to do it. I probably wasn't motivated enough either.
    I really hope you manage to see it through so we can have open source Skype and open source clients for everyone.
    I might even be able to help but I need to quit my job for that... We'll see.
    Best of luck to you.

    ReplyDelete
  19. @Purple

    >"but I need to quit my job for that"
    Oh, this is not need. Just donate some bucks if you want to help. Or try to learn code at weekends.

    ReplyDelete
  20. Congrats, do not give up reverse engineering is difficult and complicated.

    ReplyDelete
  21. Why don't you try the moneybookers donate button ( you can find links on google ).
    Or even with that webmoney you have, couldn't it be simpler ? Like a button or something ? So that I can enter the sum and just send it ? While I do like reverse engineering in real life I like KISS :D

    ReplyDelete
  22. @Purple

    Thanks for you comment. I added moneybookers now.

    ReplyDelete