Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



Ed Bott just doesn't get it, does he?

Skype was originally marketed as having end-to-end encryption. Now, we know that since Microsoft bought Skype they've added wiretapping support, which works by making themselves a man-in-the-middle. They claim they only do this temporarily for people they are actively wiretapping.

This, however, shows that Microsoft regularly MITMs you, for the purpose of evaluating whether links are dangerous. This means that basically all of Skype's former privacy claims are no longer true. They simply regularly look at your unencrypted traffic, which means that they are a target for attackers, governments, and pretty much anyone who wants to eavesdrop or read your messages.


How do you know if Microsoft is actually eavesdropping the entire conversation, or it's just the Skype client filtering out URLs in the conversation for additional screening? Sorry if I missed something in the article.


The URLs are being pinged by computers within Microsoft, so even if the filtering was only occurring on the client side (which I doubt) it still makes its way back to MS servers.


I wouldn't call this man-in-the-middle, they are the man at both ends and in the middle.

MITM usually refers to 3rd parties routing your traffic. So if your ISP or network admin was sniffing your Skype messages, that would be what is generally called MITM.


Its Ed Bott. A part of the Microsoft spin machine. Come on.


That article is very dismissive and pretty flimsy. "A single experiment"? No, it was replicated by multiple people. I’ve concluded that the reason for the mysterious visit is almost certainly innocent.... I’m reasonably certain that address is part of Microsoft’s SmartScreen infrastructure. First, that's not very reassuring. The data should not be readable by Microsoft. Second, since the traffic showed up hours after the message was sent, it is not useful as a screening service. The link would have been clicked long before the URL was checked out. The only mitigating piece of this mess is that the request was a HEAD and not a GET, so they're not fetching the whole contents of the page. But the damage is done long before.


Then again, some people have discovered that GET requests came in probably from the same person and with a google referrer after the HEAD request from the google bot:

http://seclists.org/fulldisclosure/2013/May/80

It's concerning.


The ZDNet do not say that Microsoft aren't reading and interpreting what people write in private chat. ZDNet just say its "almost certainly innocent" because its done automatically by a machine for the purpose of increased security.

I for once disagree here that such actions are innocent. When peoples private conversation is read and interpreted, even by a machine, most people still get a feeling of lost security. This in turn causes a real problem from lower personal security, increased mental stress, and social self-imposed restrictions.


So is a spell checker in an IM client equally a problem?


If a spell checker runs locally, you know that there is no physical way that information is being transmitted to someone else.

A server is a black box controlled by someone else. They may tell you it'd doing X but there's no way to verify that.


If it's on the server, yes. I don't want the server (or anyone other than the recipient) to be able to read my messages. Period.


[deleted]


You keep using that word. I do not think it means what you think it means.


In addition to sp332's well-taken points, there is the fact that what Microsoft sees, it cannot prevent the USA government and its allies from seeing. Many Skype customers would see that as an unacceptable threat.


The article concludes: There’s no evidence that anyone, human or machine, is reading your confidential messages.

Well obviously, a machine is reading your confidential messages, if only to scan them for links. In the most benign case, the link scanning could be done in the skype client (closed source software on your machine), and MS's servers are seeing a list of links + an encrypted message.

But we just don't know, do we?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: