German Government Struggles To Tap Encrypted Skype Calls

from the crypto-works dept

The Wikileaks project is starting to bear fruit, with documents leaked to the site beginning to get a lot of attention. The latest example is correspondence between the German government and a vendor (via Slashdot) that apparently makes software for intercepting Skype calls. Interestingly, the interception technology appears to be pretty primitive and rather expensive. The software has to be installed on the Skype client, and the vendor suggests that this can be accomplished by attaching a trojan to an e-mail or physically entering the premises to install the software on the target machine. And, evidently, only Windows 2000 and XP are supported; Vista support is still in the works. The company charges thousands of euros per target computer. This suggests that Skype's encryption technology is secure against at least the eavesdropping techniques available to the German government. Apparently they haven't found a way to decode encrypted Skype traffic off the wire, so they're forced to resort to these fairly cumbersome attacks on Skype clients -- attacks that are no more convenient for law enforcement than simply bugging the target's office. That suggests that the risk of comprehensive government surveillance of online telephony is still a fair ways off. If you encrypt your online activities, they're probably pretty secure. Of course, it's entirely possible that other government agencies, such as the NSA, have more sophisticated eavesdropping technology that they haven't shared with the Germans. My guess is that any government agencies possessing really sophisticated eavesdropping tools are also less likely to have their private documents show up on Wikileaks.
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team

Filed Under: encryption, germany, skype, trojans, voip, wiretapping
Companies: skype


Reader Comments

Subscribe: RSS

View by: Time | Thread


  • icon
    James (profile), 28 Jan 2008 @ 12:55pm

    NSA

    If you can imagine it, the NSA can do it. Period.

    link to this | view in chronology ]

  • identicon
    Anonymous Coward, 28 Jan 2008 @ 12:59pm

    You seem t be making rather a lot of assumptions without thinking very much ; if you were a security agency and you cracked an encryption but you didn't want anyone to know that you'd cracked it what would you do ?.

    link to this | view in chronology ]

  • identicon
    More Dread, 28 Jan 2008 @ 1:34pm

    False sense of security

    IF I were an intelligence agent and I cracked your encryption, I wouldn't tell anyone so that I can continue to data mine all of the encryption to continue to get as much valuable information out of a supposedly secured transmission(s) as possible.

    link to this | view in chronology ]

  • identicon
    Devil's Advocate, 28 Jan 2008 @ 2:05pm

    Paranoia

    And if you were an intelligence agent and you *haven't* cracked anyone's encryption would you go around saying you have? What exactly would you have to gain? Pushing the opponent even further in the cryptographic arms-race?

    Now I'm not saying the NSA doesn't do things most of us haven't even imagined - infact I'd be very disappointed if they hadn't - but not stating they've cracked what is considered an extremely effective encryption requiring massive computational resources to maliciously decrypt tells us, in my opinion,

    absolutly nothing.

    link to this | view in chronology ]

  • identicon
    Anonymous Coward, 28 Jan 2008 @ 2:37pm

    Decript my ass. You don't think that Phil gave the NSA the keys to Z-Phone? You don't think the NSA is already tapped into Skype? Baaaa, the fact that these guys are still walking around proves this.

    The govt. is tapped into communications providers at the source. You think GWB invented listening into phone calls? Ha. The govt. has servers connected to Microsoft Exchange Server, Hotmail, GMail, Yahoo mail and any other type of mail server. At the source. They don't need to brute force it, they get it from the source. Personally, I think that is a good thing.

    link to this | view in chronology ]

    • identicon
      Anonymous Coward, 28 Jan 2008 @ 11:51pm

      Re:

      for one the goverment only has laws where these black box's are forced to be installed on the ISP's systems if they have them in gmail and all the other places you say they have them on then, the companies are willing to do it with out a force of the hand. Since most companies dont really feel like that extra hassle i doubt that gmail and all the other places you listed are not actually tapped in the manner that you say.. but since most email is not encrypted when it comes over your ISP's line and before it hits your computer its been logged and tracked.

      link to this | view in chronology ]

  • identicon
    Anonymous Coward, 29 Jan 2008 @ 10:46am

    NSA has lots of money and personal -- true. But the memo claims that Skype is encrypted with RSA and AES which is quite a tough cypher combination. People who laugh about any agency which cannot crack AES have no clue about cryptoanalysis. The presented attack is one of two which don't involve undiscovered mathematical magic. The second on would be to force Skype to surrender used keys or implement key escrow.

    link to this | view in chronology ]

  • identicon
    Anonymous Coward, 29 Jan 2008 @ 10:47am

    You are naive if you think that these "black boxes" are not installed in all forms of communication already.

    link to this | view in chronology ]

  • identicon
    AndThePointIS, 29 Jan 2008 @ 8:20pm

    We don't have a clue.

    link to this | view in chronology ]

  • identicon
    Anonymous Coward, 30 Jan 2008 @ 2:28pm

    "Paranoia is, when everything starts making sense!"
    isn't it Mr Black-Boxes-are-everywhere?

    link to this | view in chronology ]

  • identicon
    amanda, 11 Mar 2008 @ 6:03am

    langauage Arts

    I want to just say HI.

    link to this | view in chronology ]

  • identicon
    live free or die, 5 Aug 2008 @ 10:06am

    pfff

    hahaha so funny

    they want you to think that it is secure so you drop your guard.

    on wikipedia it says governments have killed 260 m in the last 100 years ( democide )

    the real terrorists are government and those behind government. 911 was an inside job, proof from documentary 911 mysteries for free on google video

    link to this | view in chronology ]


Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.