[16700] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Simson Garfinkel analyses Skype - Open Society Institute

daemon@ATHENA.MIT.EDU (Peter Gutmann)
Wed Jan 26 19:05:20 2005

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: daw-usenet@taverner.CS.Berkeley.EDU
Cc: cryptography@metzdowd.com
In-Reply-To: <200501110433.j0B4Xf4I014871@taverner.CS.Berkeley.EDU>
Date: Wed, 12 Jan 2005 05:00:29 +1300

David Wagner <daw@cs.berkeley.edu> writes:

>>Is Skype secure?
>
>The answer appears to be, "no one knows".  

There have been other posts about this in the past, even though they use known
algorithms the way they use them is completely homebrew and horribly insecure:
Raw, unpadded RSA, no message authentication, no key verification, no replay
protection, etc etc etc.  It's pretty much a textbook example of the problems
covered in the writeup I did on security issues in homebrew VPNs last year.

(Having said that, the P2P portion of Skype is quite nice, it's just the
 security area that's lacking.  Since the developers are P2P people, that's
 somewhat understandable).

Peter.


---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post