Contributor

Skype’s security invalidated for 69 million users

Opinion
Oct 2, 20082 mins

discovered that eBay’s Chinese partner, Tom Group, has modified the version of Skype they distribute to their customers. The Trojan version of Skype identifies key words like Falun Gong, democracy, milk, and earthquake.  It then encrypts the conversation containing those key words and sends them off to a central server within Tom’s network.  Source and destination of calls and text conversations are recorded as well.

Add eBay to the list of tech giants that have become complicit in Chinese government control and monitoring of its people.  Nart Villeneuve, a senior research fellow at Citizen Lab, a consumer advocate group in Toronto, has

  While it is no surprise that this type of surveillance occurs inside China what is disturbing is that  Skype is widely regarded as a secure way to communicate.  Millions of people depend on it for free and open conversation across the public Internet.  Even the much covered NSA/ATT wire tapping of the ‘Net cannot easily break the encryption techniques used by Skype.  Thanks to the built in security (described in detail here by respected independent researcher Tom Berson ) Skype is now associated with safe communications.

From Dr. Berson’s evaluation:

Skype uses only standard cryptographic primitives to meet its ends, which is a sound engineering approach. These primitives include the AES block cipher, the RSA public-key cryptosystem, the ISO 9796-2 signature padding scheme, the SHA-1 hash function, and the RC4 stream cipher. I looked at the Skype implementation of each of these, and verified that each implementation conforms to its standard and interoperates with reference implementations.

For eBay to allow a Chinese company to abuse that trusted brand in this manner will do untold damage to Skype and eBay.

Update: Nart Villeneuve’s report is here. 

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author