German Government Struggles To Tap Encrypted Skype Calls

from the crypto-works dept

The Wikileaks project is starting to bear fruit, with documents leaked to the site beginning to get a lot of attention. The latest example is correspondence between the German government and a vendor (via Slashdot) that apparently makes software for intercepting Skype calls. Interestingly, the interception technology appears to be pretty primitive and rather expensive. The software has to be installed on the Skype client, and the vendor suggests that this can be accomplished by attaching a trojan to an e-mail or physically entering the premises to install the software on the target machine. And, evidently, only Windows 2000 and XP are supported; Vista support is still in the works. The company charges thousands of euros per target computer. This suggests that Skype's encryption technology is secure against at least the eavesdropping techniques available to the German government. Apparently they haven't found a way to decode encrypted Skype traffic off the wire, so they're forced to resort to these fairly cumbersome attacks on Skype clients -- attacks that are no more convenient for law enforcement than simply bugging the target's office. That suggests that the risk of comprehensive government surveillance of online telephony is still a fair ways off. If you encrypt your online activities, they're probably pretty secure. Of course, it's entirely possible that other government agencies, such as the NSA, have more sophisticated eavesdropping technology that they haven't shared with the Germans. My guess is that any government agencies possessing really sophisticated eavesdropping tools are also less likely to have their private documents show up on Wikileaks.


Reader Comments (rss)

(Flattened / Threaded)

  1.  
    icon
    James (profile), Jan 28th, 2008 @ 12:55pm

    NSA

    If you can imagine it, the NSA can do it. Period.

     

    reply to this | link to this | view in thread ]

  2.  
    identicon
    Anonymous Coward, Jan 28th, 2008 @ 12:59pm

    You seem t be making rather a lot of assumptions without thinking very much ; if you were a security agency and you cracked an encryption but you didn't want anyone to know that you'd cracked it what would you do ?.

     

    reply to this | link to this | view in thread ]

  3.  
    identicon
    More Dread, Jan 28th, 2008 @ 1:34pm

    False sense of security

    IF I were an intelligence agent and I cracked your encryption, I wouldn't tell anyone so that I can continue to data mine all of the encryption to continue to get as much valuable information out of a supposedly secured transmission(s) as possible.

     

    reply to this | link to this | view in thread ]

  4.  
    identicon
    Devil's Advocate, Jan 28th, 2008 @ 2:05pm

    Paranoia

    And if you were an intelligence agent and you *haven't* cracked anyone's encryption would you go around saying you have? What exactly would you have to gain? Pushing the opponent even further in the cryptographic arms-race?

    Now I'm not saying the NSA doesn't do things most of us haven't even imagined - infact I'd be very disappointed if they hadn't - but not stating they've cracked what is considered an extremely effective encryption requiring massive computational resources to maliciously decrypt tells us, in my opinion,

    absolutly nothing.

     

    reply to this | link to this | view in thread ]

  5.  
    identicon
    Anonymous Coward, Jan 28th, 2008 @ 2:37pm

    Decript my ass. You don't think that Phil gave the NSA the keys to Z-Phone? You don't think the NSA is already tapped into Skype? Baaaa, the fact that these guys are still walking around proves this.

    The govt. is tapped into communications providers at the source. You think GWB invented listening into phone calls? Ha. The govt. has servers connected to Microsoft Exchange Server, Hotmail, GMail, Yahoo mail and any other type of mail server. At the source. They don't need to brute force it, they get it from the source. Personally, I think that is a good thing.

     

    reply to this | link to this | view in thread ]

  6.  
    identicon
    Anonymous Coward, Jan 28th, 2008 @ 11:51pm

    Re:

    for one the goverment only has laws where these black box's are forced to be installed on the ISP's systems if they have them in gmail and all the other places you say they have them on then, the companies are willing to do it with out a force of the hand. Since most companies dont really feel like that extra hassle i doubt that gmail and all the other places you listed are not actually tapped in the manner that you say.. but since most email is not encrypted when it comes over your ISP's line and before it hits your computer its been logged and tracked.

     

    reply to this | link to this | view in thread ]

  7.  
    identicon
    Anonymous Coward, Jan 29th, 2008 @ 10:46am

    NSA has lots of money and personal -- true. But the memo claims that Skype is encrypted with RSA and AES which is quite a tough cypher combination. People who laugh about any agency which cannot crack AES have no clue about cryptoanalysis. The presented attack is one of two which don't involve undiscovered mathematical magic. The second on would be to force Skype to surrender used keys or implement key escrow.

     

    reply to this | link to this | view in thread ]

  8.  
    identicon
    Anonymous Coward, Jan 29th, 2008 @ 10:47am

    You are naive if you think that these "black boxes" are not installed in all forms of communication already.

     

    reply to this | link to this | view in thread ]

  9.  
    identicon
    AndThePointIS, Jan 29th, 2008 @ 8:20pm

    We don't have a clue.

     

    reply to this | link to this | view in thread ]

  10.  
    identicon
    Anonymous Coward, Jan 30th, 2008 @ 2:28pm

    "Paranoia is, when everything starts making sense!"
    isn't it Mr Black-Boxes-are-everywhere?

     

    reply to this | link to this | view in thread ]

  11.  
    identicon
    amanda, Mar 11th, 2008 @ 6:03am

    langauage Arts

    I want to just say HI.

     

    reply to this | link to this | view in thread ]

  12.  
    identicon
    live free or die, Aug 5th, 2008 @ 10:06am

    pfff

    hahaha so funny

    they want you to think that it is secure so you drop your guard.

    on wikipedia it says governments have killed 260 m in the last 100 years ( democide )

    the real terrorists are government and those behind government. 911 was an inside job, proof from documentary 911 mysteries for free on google video

     

    reply to this | link to this | view in thread ]


Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Save me a cookie
  • Note: A CRLF will be replaced by a break tag (<br>), all other allowable HTML will remain intact
  • Allowed HTML Tags: <b> <i> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Follow Techdirt
A word from our sponsors...
Essential Reading
Techdirt Reading List
Techdirt Insider Chat
A word from our sponsors...
Recent Stories
A word from our sponsors...

Close

Email This