Wednesday, January 28, 2009

Skype vs. Eavesdropping

Mike Chapple handles a Skype question...
Q: Can an attacker gain important and private information from my phone through a peer-to-peer network?


A: Peer-to-peer telephone services such as Skype offer a way to save significant money on telephone services. By leveraging peer-to-peer networks to route calls around the world, every call becomes a local one. Peer-to-peer services allow telephone calls to be routed through the privately owned equipment of one or more unknown individuals. This raises a number of confidentiality, integrity and availability concerns, and little information is available about what, if any, security controls these services have put in place to protect your telephone calls.

While this is an interesting technology, I would not recommend that it be used for any private communications. (more)

Additional considerations...
Skype says their communications is encrypted.
Some say Skype encryption can be bypassed.