Chinese snoop on Skype, but are they alone?, 2nd Ld-Writethru, TEC

By Anonymous  Add a new comment

NEW YORK (AP) _ A Canadian researcher has discovered that a Chinese version of eBay Inc.'s Skype communications software snoops on text chats that contain certain keywords, including "democracy."

The revelation is not only of interest to rights groups that monitor Internet censorship. The discovery also likely intrigues law enforcement and intelligence agencies in other countries, because they have been bothered by the growing use of Skype, which claims 338 million users across the world.

By its very nature, Skype is difficult to wiretap. Skype routes calls and chats between computers over the Internet, avoiding traditional phone networks. And the contents are supposedly encrypted, raising concerns in law enforcement that Skype could let criminals communicate without fear of eavesdropping.

The FBI has argued for applying U.S. wiretapping law to Internet phone calls. The bureau got a favorable court ruling in 2006, but it's not clear whether it applies to systems like Skype that skip telephone networks.

In the other camp, privacy advocates and security experts are concerned that Skype, while presented by the company as a secure channel of communication, has some kind of "back door" that allows eavesdropping. Whether Skypetapping is already going on in the U.S. and Europe is a matter that the company has equivocated on for years.

"For a couple of years, maybe more, people have had the suspicion ... that Skype pretends to be secure but actually isn't," said Bruce Schneier, the chief security technology officer of BT Group PLC, the British telecom carrier.

"The Chinese eavesdropping on Skype text messages only adds to the PR problems, the image problems, that Skype has among those who care about security," Schneier added.

On Wednesday, Nart Villeneuve at the University of Toronto revealed that a Chinese version of Skype's application is being used for wholesale surveillance of text messages.

The software is distributed by Skype's Chinese partner, Tom Online Inc. Skype has acknowledged since 2006 that this version looks for certain sensitive words in text chats, and blocks those messages from reaching their destination. The issue appears only to affect people using the Chinese software.

What Villeneuve found was that the Tom-Skype program also passes the messages caught by the filter to a cluster of servers on Tom's network. Because of poor security on those servers, he was able to retrieve more than a million stored messages. The filter appears to look for words like "Tibet," ''democracy" and "milk powder" ? China is in the throes of a food scandal involving tainted milk.

This directly contradicts a blog posting on Skype's Web site, which says that the software discards the filtered messages, and neither displays nor transmits them anywhere.

On Thursday, Skype president Josh Silverman said the company learned of the message diversion only Wednesday. It alerted Tom that the messages were insecurely stored, which was quickly fixed.

"In addition, we are currently addressing the wider issue of the uploading and storage of certain messages with Tom," Silverman wrote in a statement.

Skype has earlier given contradictory statements on the eavesdropping issue.

It has told The Associated Press that it "cooperates fully with all lawful requests from relevant authorities." But when asked by CNET's News.com in June whether it could accommodate a wiretapping request, it said it could not, because of the way its system works: Skype calls are encrypted, and only the two computers at each end have the keys to decrypt them.

Skype spokeswoman Jennifer Caukin said Thursday that "since its inception in 2003 Skype has never created a back door to the Skype software."

But both Schneier and Simson Garfinkel, an associate of the School of Engineering and Applied Sciences at Harvard University who has studied Skype's security, believe it would be trivial for the company to listen in on conversations.

"I can think of five or six different ways to eavesdrop on Skype. It's not that hard if you are the Skype company and want to provide legal access to law enforcement," Garfinkel said.

It's unclear whether Skype has an obligation to help law enforcement under U.S. law. Peter Swire, who served as the Clinton administration's privacy czar for two years and is now a professor of law at Ohio State University, said that while he knows of no U.S. court ruling that has required Skype to comply with wiretapping requests, it's conceivable that the company is voluntarily cooperating with law enforcement.

Skype told News.com that it had not received a subpoena or court order to perform eavesdropping.

Yet German technology site Heise Online reported in July that Austrian officials claimed to be able to listen to Skype conversations. The relative quietness of the law enforcement community on the issue in recent years could be the result of such cooperation.

The FBI did not return a call for comment Thursday.

___

On the Net:

http://www.skype.com

Villeneuve's site: http://www.nartv.org

ITworld reboot

Behind the changes!

We just completed a re-architecture of ITworld with loads of new social functionality! We're still tweaking, but please check it out, share your feedback and let us know if you have any problems.

Email us

ITworld LIVE

Minky's picture

Object

Posted by Minky

Anonymous's picture

Object

This paper describes HP ProLiant Gen8 servers, the technology on which they are based, and the way they address many of the causes of operational costs found at customer sites. The hardware and software capabilities of the HP servers were designed to be proactive, reducing the effort and knowledge required to run the server systems and leveraging automation to reduce maintenance costs and IT staff costs.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Posted by Anonymous

thesfmacman's picture

Object

Posted by thesfmacman

AddingBugs2Code's picture

Object

Posted by AddingBugs2Code

Anonymous's picture

Object

This video shows how Freightliner achieved mainframe integration using Attachmate® Verastream® to automate EDI messaging and roll out real-time online tracking for customers.

Posted by Anonymous

Anonymous's picture

Object

Small and midsize businesses can get the storage strategy advice they need in this issue of "Data Storage Insights." With a focus on managing data growth, expert articles include how tiered storage saves, tips to cost-effectively expand storage capacity and what to do once your business has outgrown its backup strategy.

Posted by Anonymous

Anonymous's picture

Object

The best way to take full advantage of server virtualization's powerful capabilities is with network-based storage. Dell EqualLogic FS7500 offers a flexible solution for VMware virtual workloads by consolidating both NAS and SAN storage in a unified, scale-out architecture.

Posted by Anonymous

Anonymous's picture

Object

As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.

Posted by Anonymous

stojanos's picture

Object

Posted by stojanos

Anonymous's picture

Object

In most companies, the needs of the business are outpacing what IT can deliver. Technology is the foundation and enabler of business innovation, but developing and implementing new solutions is resource-intensive. Integrating and optimizing islands of IT is complex, time-consuming and costly.However, implementing a private cloud can be complex and daunting. HP's solution, CloudSystem Matrix, helps you build a turnkey private cloud environment to deliver the benefits of the cloud to your business users. Read now to find out how the HP CloudSystem Matrix can enable you to move quickly to a private cloud model.

Posted by Anonymous

Ferniez's picture

Object

Posted by Ferniez

Anonymous's picture

Object

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Posted by Anonymous

dlgmex@gmail.com's picture

Object

Posted by dlgmex@gmail.com

Anonymous's picture

Object

A comprehensive backup and recovery solution is one supporting a tiered-recovery model. This IDC Vendor Spotlight examines the forces driving the advancements in data protection technologies. Discover the benefits of a solution that works across physical, virtual and cloud environments. Read it today.

Posted by Anonymous

wengweng's picture

Object

Posted by wengweng

johnyosborn@hotmail.com's picture

Object

Posted by johnyosborn@hot...

Anonymous's picture

Object

Learn how IT teams can protect against spear phishing tactics. Harry Sverdlove, chief technology officer of Bit9 offers a frank discussion about spear phishing - the most common technique used in today's advanced attacks. Learn how spear phishing works and three recommendations for IT to protect against modern threats.

Posted by Anonymous

Anonymous's picture

Object

Enterprises have successfully controlled their IT budgets and server sprawl issues with the help of virtualization technologies, but what's next? Increasingly, organizations are turning to storage consolidation for virtualized server environments in order to reduce data center costs and inefficiencies.

Posted by Anonymous

Anonymous's picture

Object

This report defines "tier-1" storage in the modern IT world and in the data centers and services that support it. What was a simple environment just a few years ago with mainframes or a few large servers to be supported has evolved into a complex web of virtual machines, clouds, and expanding user expectations -- factors which demand and create flexibility, but do so in a way that pushes a lack of predictability upon the storage infrastructure. Learn what your criteria should be for tier-1 storage.

Posted by Anonymous

Anonymous's picture

Object

The new HP ProLiant Gen8 server features capabilities that speed and simplify three critical phases of the server lifecycle: configuration and provisioning, daily operational health monitoring and ongoing updates and maintenance. Download this short paper to learn more.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Posted by Anonymous

Anonymous's picture

Object

Cascade Demo: With Cascade, you get visibility into network optimization and analysis, application performance management, IT consolidation, and security. Watch as Jack, the manager of the network team, deals with user complaints about application performance. See how he uses Riverbed Cascade to solve them.

Posted by Anonymous

Anonymous's picture

Object

In this white paper, IDC analyzes the ROI that customers can expect from Riverbed Cascade, based on interviews with Cascade customers. Additionally, IDC lays out the business case for proactively managing network and application performance. Get the visibility you need to achieve your IT objectives. Download this whitepaper today.

Posted by Anonymous

Anonymous's picture

Object

NSS Labs, a global leader of independent security product testing and certification, just released the results of an in-depth assessment involving seven Next-Generation Firewall products. Solutions from SonicWALL®, Check Point®, Palo Alto Networks®, Juniper Networks®, Fortinet®, Stonesoft® and Barracuda Networks® were rigorously tested. The result? SonicWALL's SuperMassive™ E10800 is the Highest Overall Protection Next-Gen Firewall to Earn NSS Labs "Recommend" Rating.

Posted by Anonymous

Anonymous's picture

Object

In this white paper, IDC analyzes the ROI that customers can expect from Riverbed Cascade, based on interviews with Cascade customers. Additionally, IDC lays out the business case for proactively managing network and application performance. Get the visibility you need to achieve your IT objectives. Download this whitepaper today.

Posted by Anonymous

Anonymous's picture

Object

The new HP ProLiant Gen8 server features capabilities that speed and simplify three critical phases of the server lifecycle: configuration and provisioning, daily operational health monitoring and ongoing updates and maintenance. Download this short paper to learn more.

Posted by Anonymous

AN4Mobile's picture

Object

Posted by AN4Mobile

Anonymous's picture

Object

The benefits of virtualization are unassailable: increased agility, scale, and cost savings to name a few. However, so too are the monitoring challenges posed by these environments-including complexities, lack of visibility and control, and inefficiency.

Posted by Anonymous

Anonymous's picture

Object

The convenient portability and high functionality of consumer devices combined with the ability to connect to the Internet almost anywhere and at any time are resulting in a growing mobile workforce realizing important productivity benefits - right at the point of contact with customers and partners.

Posted by Anonymous

Anonymous's picture

Object

Whether your data center is large or small, it faces a similar set of roadblocks to efficiency, uptime, and ROI. This white paper reveals the six most common and intractable problems facing the data center and explains how to rectify them while improving efficiency and uptime.

Posted by Anonymous

Anonymous's picture

Object

Layered security is the way to go when it comes to protecting Active Directory. This expert e-guide explains the best method to use when planning and designing a security solution. Find out why it is important to secure Group Policy settings and discover how managed service accounts boost server security in R2.

Posted by Anonymous

Ask a question

Ask a Question