The encryption of Skype VoIP phone calls might not be as secure as you think.
It's possible the company keeps keys so law enforcement authorities can decrypt encrypted VoIP phone calls, a report says, but Skype won't say for sure one way or the other.
According to an online report, Austrian officials with legal authority to tap VoIP phone communications have no problem listening in on Skype calls, which are encrypted as a standard part of Skype service.
A Skype spokesman wouldn't say whether Skype keeps keys to decrypt calls. "Sorry, Skype does not comment on media speculation," says Skype vice president Chiam Haas.
It's virtually impossible to figure out for sure from independent research whether Skype keeps encryption keys or not, says David Endler, chairman of Voice Over IP Security Alliance and senior director of security research at Tipping Point.
"No one has shown it publicly," he says. "Skype is a closed software package, essentially a black box." The company has on rare occasions allowed outside researchers to examine and verify the security of its encryption, but not whether the keys that can crack the encryption can be retrieved, he says.
To allay fears that the calls might not be secure from law enforcement, Skype should open its platform to evaluation by trusted, credible industry experts, he says.
Endler says it's equally difficult to know whether commercial VoIP vendors leave open the possibility of turning encryption keys over to law enforcement.
In the United States, the Communications Assistance for Law Enforcement Act (CALEA) forbids requiring that vendors build in back-door decryption, says Jim Dempsey, vice president for public policy at the Center for Democracy & Technology. "CALEA expressly forbids requiring anyone to be able to decrypt anything," he says.
But that doesn't mean they don't build in key-retrieval anyway. Dempsey says there are no active proposals to force vendors to leave encryption back doors in their VoIP gear, but that could change. "Nothing in regulations is permanent," he says.
Endler says that attempts by researchers to learn more about how Skype works have been effectively blocked by measures put in place by Skype. "They've taken extreme measures to prevent reverse engineering of their client software," he says, more so than mainstream VoIP vendors.
Latest on Encryption
- Toshiba feature wipes data when hard drives turned off
- Indonesia presses RIM over its BlackBerry service
- Saudi Arabia to ban BlackBerry service on Friday
- Google moves encrypted search to a new site
- In pictures: 10 free (and legal) ways to bypass Net filtering
- Amazon encrypts CloudFront, but security comes at a price
- Symantec buys encryption specialist PGP for $300M
- UK registry to implement DNS security protocol
- VeriSign rolls out new Web site verification service
- Heartland moves to encrypted payment system
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
- WebSphere Solution Design (S20) - CBD, contract role3/09/2010
Other
I.T. & T
WebSphere Solution Design (S20) - CBD, contract role - Solution Architect - Web Application Architecture Project!3/09/2010
Other
I.T. & T
Solution Architect to provide strategic and operational consulting for the end-to-end Web Application System project! Experienced with J2EE or .NET?! - Principal Consultant - ITIL2/09/2010
Other
I.T. & T
Excellent opportunity for an experienced ITIL Principal Consultant to join an innovative leading IT Service management consultancy. Attractive packag - Mainframe Developer - COBOL - 12 Month Contract2/09/2010
Other
I.T. & T
Mainframe Developer - COBOL - 12 Month Contract - Business Systems Analyst2/09/2010
Other
I.T. & T
Perm CBD based role for an experienced Business Systems Analyst - Senior SAP Project Manager2/09/2010
Other
I.T. & T
Senior SAP Project Manager - SAP FICO Consultant - 6 week contract - West Sydney2/09/2010
Other
I.T. & T
SAP FICO Consultant - 6 week contract - West Sydney
Whitepapers
-
Allocating data center energy costs and carbon to IT users -
PlateSpin Forge: Plug In and Protect Server Workloads -
Novell Holds Down Data Center Costs with PlateSpin Work load Management Solutions -
Virtualisation: Optimised Power and Cooling to Maximise Benefits -
Implementing Energy Efficient Data Centers
TechWorld Blogs
Recent blog posts
- Windows Phone 7: how big can it get?
- NBN gets a turn at political football
- Internet filter gets caught up in politics
- TechWorld Forums goes live
- Selective sourcing the hybrid of cloud services
- Social networks catch more business attention
- RIP Kin
- Telstra’s copper and NBN’s fibre: will the two ends meet?
- RIP Windows 2000, XP lives on
- Does the world need another iPhone? Why not
Recent comments
- java development
11 hours 43 min ago - When mine called they
12 hours 26 min ago - 3D TV cannot fall - no way! Why?
15 hours 40 min ago - Thanks for taking the time to
1 day 3 hours ago - Windows scam
1 day 11 hours ago - My only anti fraud method is
2 days 6 hours ago - Private Cloud Taxonomies
2 days 6 hours ago - ...however...
2 days 15 hours ago - This Guy
2 days 15 hours ago - Glasses Free technology
2 days 16 hours ago - FOSS community
2 days 23 hours ago - i have dv6000 with nvidia
3 days 45 min ago - i have dv6000 and suddenly
3 days 49 min ago - This is an awesome comment.
3 days 4 hours ago - Real Estate
3 days 6 hours ago - Scam - eventvwr scammers
3 days 10 hours ago - Well I never...
5 days 1 hour ago - Too bad Microsoft was mentioned
5 days 3 hours ago - Phone card is a better option to make calls at a lower rate
5 days 7 hours ago - In other words: "Developers,
5 days 13 hours ago










Comments
Post new comment