The Tech Herald

Ignored Skype flaw enables hackers to steal sensitive user details

by Steven Mostyn - Oct 25 2011, 10:24

Image: Skype.

What’s not to like about Skype? It spans the world, it enables us to chat instantly with friends and family, it supports video communication, and it’s completely free. What’s not to like?

Well, how about the potential for having your computer’s security compromised because Skype can allow nefarious online criminals to access your identity, physical movements and personal documents?

That’s according to a paper published by a research team from New York University’s Polytechnic Institute, which claims hackers can take a Skype user’s IP address and use it to track activity through P2P services such as BitTorrent—where community users regularly share their personal details.

“These findings have real security implications for the hundreds of millions of people around the world who use VoIP or P2P file-sharing services,” commented Keith Ross of the Polytechnic Institute.

“A hacker anywhere in the world could easily track the whereabouts and file-sharing habits of a Skype user—from private citizens to celebrities and politicians—and use the information for purposes of stalking, blackmail or fraud,” he added.

Although an actual call connection is required to enable the attack, the researchers say hackers will be able to sidestep not being on a user’s contact list by initiating a call, blocking information packets, tracking the victim’s IP address, and ending the call without it even ringing through on the targeted computer.

Skype has apparently been informed of the security loophole (a year ago!), but is yet to act. The researchers say the VoIP service should be able to close the hole quickly and easily by simply tweaking the existing Skype protocol so that it withholds a user’s IP address unless an incoming call is physically accepted.

Skype, which was recently acquired by Microsoft, has not offered an official comment regarding the matter.

Around the Web

Comment on this Story

comments powered by Disqus

From Autosaur.com

World’s first flat-pack truck the OX could help Africa

A flat-pack truck which can be put together by anyone in just half a day has been invented to help people living in remote places in Africa and other parts of the developing world. The OX is shipped in pieces but can be assembled with just three people in 11.5hours — and they need no [...]

The post World’s first flat-pack truck the OX could help Africa appeared first on Autosaur.

Nissan 370Z Nismo to rock the Gumball 3000 rally

The Nissan 370Z Nismo will be one of the cars in the 2013 Gumball 3000 rally where  â€” as the guys from TV show Jackass put it — “filthy stinking rich” people drive super-expensive cars 3,000 miles through 13 countries across Europe. The car, above, will be driven by a team from publishing and production [...]

The post Nissan 370Z Nismo to rock the Gumball 3000 rally appeared first on Autosaur.

#MyTurnToJag and Playboy: How Jaguar targets men

Jaguar has launched a new Twitter campaign called #MyTurnToJag to advertise its new F-Type â€” as well as teaming up with men’s magazine PLAYBOY. The #MyTurnToJag competition gives members of the public the chance to drive one of their new sports cars. And it comes after the firm helped announce Raquel Pomplun, left, as Playboy’s Playmate of [...]

The post #MyTurnToJag and Playboy: How Jaguar targets men appeared first on Autosaur.