Phil Wolff

Your SkypeOut call records sometimes exposed

May 15, 2006 10:38 AM

Topics: Business | News | Security | SkypeOut | Skype杂志 | ebay | privacy | regulation | skype | skypejournal | voip | wishlist

Ever had Skype ask for your feedback on a SkypeOut call? Screenshot of SkypeOut call feedback formThat's more than AT&T ever did for me. Would be nice if it used a secure browser page (SSL, https) instead of posting my skypedout phone number in the clear. The url leading to the form:

http://www.skype.com/feedback/survey/calls/? service=skypeout & version=2.0.0.103
& username=YOURSKYPENAMEHERE
& call_date=1147565396
& cpu=0
& bandwidth=0
& a_number=+DIALEDPHONENUMBERHERE
& call_type=outgoing
& provider=
& status=
& result=FINISHED
& log_ringing=0
& log_answer=12
& log_finished=145
& pstn_feedback_info=

Lots of unencrypted personal info floating from users to Skype over the Internet daily, where anyone with a packet sniffer can assemble and read the data.

This data is exposed before you even see the form.

Fortunately the fix is easy to recode, a small change. But it's an indicator of how hard it is to keep complex information systems in full compliance with all regulations and company policies.

As of post time:

  • SkypeOut data is still being posted in the clear.
  • Skype is working on a client hot fix.
  • The number of calls and callers exposed is still unknown.
  • This doesn't compromise call security, just the metadata describing the caller (skype name, IP address) and call (phone number, start time, duration).

One last note. The timing of this report is an accident. I noticed this privacy problem around 3am Pacific Sunday morning.




Trackback Pings

TrackBack URL for this entry:
http://www.skypejournal.com/cgi-bin/mt/mt-tb.cgi/2265

Comments

Posted by: Hans A. Koch at May 16, 2006 11:53 AM

It seems that when I press Red Cancel Button several times after a call I always get that feedback page.

Posted by: BarkerJr at May 17, 2006 3:19 PM

Hmm, would be nice if they at least hashed it or something.

Post a comment




Remember Me?

(you may use HTML tags for style)





Other Recent Posts

Skype 3.0 Folder Pollution in Life | Products | Skype杂志 | complaints | design | ebay | skype | skypejournal | voip | wishlist on 11/22/06

Skype 3.0 Beta for Windows; bugfix build 137 in General Notices | News | Products | Skype News | Skype杂志 | ebay | skype | skypejournal | voip on 11/22/06

Skype PR Wake Up Call III: The Commentary in Business | Every Post | Ideas & Views | Marketing | Skype News | Skype杂志 | Strategy | ebay | observations | skype | skypejournal | voip on 11/22/06

Wednesday morning scan in Business | Life | Marketing | News | Products | Skype Partner Watch | Skype杂志 | Strategy | Technology | Tips & Tricks | Yahoo | counterpoints | design | ebay | freedom | observations | regulation | skype | skypejournal | voip on 11/22/06

Yes, TalkPlus reverse engineered Skype. in Developers | North America | Skype Partner Watch | Skype杂志 | Strategy | Technology | ebay | skype | skypejournal | voip on 11/21/06

Email to a friend