Security



July 8, 2005 10:46 PM | Phil Wolff

by Jan GeirnaertJan drinking SkypeIn, an IT/Internet Business Consultant in Malaysia.

I have worked here in Kuala Lumpur, Malaysia, as the IT manager and network administrator for a small non-IT business. One of the many things I did is cutting the cost of the phone bill by implementing Skype as a VoIP solution. These thoughts are not purely IT/technical. My wage was paid by the cost-savings on the telecom-bill.

Here are some issues to be taken into account before implementing Skype. What you read below is how I did it, these are my personal experiences. The standard setup-recommendations can be found on the Skype web site.

Make your case gently and with numbers

Explain properly to all involved management levels and teams (especially Finance and higher management-levels) what the solutions consist off. Don’t go too much into IT-technical issues. Focus on the advantages and the low cost (only your time and skill are important here). Take into account that VoIP (Skype included) is something new and a low-level entry is better than no entry at all. If you make things sound complicated, it just won’t work.

continue reading.....
June 17, 2005 01:37 PM | Phil Wolff

Living the Skype Life

Roxy in headphonesDoes anyone know Roxy's Skype name?

engadget: Use DittyBotdittybotlogothumb.gif and Skype to access your iTunes collection from any cellphone (Mac). It works, but Om says you can buy an iPod for the same price as the added mobile minutes. DittyBot (cute name, cuter character) is another example of the willingness of customers to make their own features.

Russell Shaw explains 15 common Skype error messages.

For your inner Quant

The latest Skype stats:
  • Total Skype Downloads: 122,320,159
  • Users Online Now: 3,014,635
  • Total Minutes Served: 9,947,864,820 (should roll over)
For contrast: 64 million Firefox users
Researcher Sandvine says Skype users rule North America.
  • Skype users account for 35.8 percent of individual callers on North American networks.
  • Skype calls account for 46.2 percent of minutes used.
also...

vSkype multiuser video chat free Beta release shipping now. See Bill Campbell's product review and exclusive interviews.

IPdrum promises a bridge between net and mobile phones later this summer. "Patent-pending technology to connect traditional mobile systems with Skype." Wholesale service or retail? via Engadget.

Skype voicemail came out of beta. New feature: Voicemail customers can leave voicemail for any Skypers.

Security? Om Malik re-voices concern about Skype crossing firewalls.

Skypes To The Editor: Online publication MSmobiles.com uses Skype for reader feedback. Leave a voicemail with your comments.

What's Your Skype Strategy? Blast from three months ago.

Coming this week:

May 30, 2005 02:58 AM | Phil Wolff

Their statement: Restrictions on running Skype P2P software at CERN. Because Skype clients help each other find others on the net (acting as supernodes), basically behaving too much like KaZaA. via physics professor Jacques Distler's thoughtful blog post.

The stated reason seems a little shaky to me. Aside from the unsavoury nature of its cousins, the P2P filesharing programs, I don’t see why skype supernodes would pose an undue burden on the CERN network. It seems to be more of an “It’s the principle of the thing!” issue, than an actual concern about bandwidth or network performance.
Does your IT organization have a Skype policy? What makes an informed, useful, and effective policy? What concerns should it address?

May 27, 2005 10:20 AM | Phil Wolff

First off, let's look at writing. The American Management Association wants writing interns to write a book on making deals online. Has Skype helped you make a deal? If not, the you may want to swing by the World Association of Newspapers conference in Seoul. 29 May - 1 June. If blogging is journalism, what is skyping? The next day another conference, TrendTag (Trend Day) in Hamburg looks like a great time for quants and futurists. 2 June. For more events I find interesting, see my list on evdb.com, including The 8th Asia Pacific IP Telephony, Singapore, the Wireless Community Conference, Monterey, California, INBOX, San Jose, California (where I want to learn more about spam over IP telephony), and SUPERCOMM Chicago.

We all want more from Skype. A million Apple fiends are all goosepimply with excitement that Spymac is adding Skype, maybe to become SkypeMac? This popular Macintosh portal adds SkypeMe to its user profiles, forums, to push realtime conversation on news and user posts. I wonder what Skype video will do to portals and online communities? Or to libraries: 26 steps for effective web presence in libraries includes Skype.

Martin Geddes is craving a long list of Skype client features. He ain't alone. Jan's Tech Blog says Skype's SkypeOut Dialing Wizard helps you sort out international numbers before you spend those SkypeOut minutes. Build it into the next release, please.

I'm fascinated by Consumer Casting Conversations (fr) who are using Skypecasting for market research. via Franck Dumesnil. Reminds me of Sparkcasts' beercasting. Gregory Narain, are you listening?

Skype's shaking people up.
  Some band together: the Internet Telephony Services Providers’ Association is trying to make the world safe for Skype and Skypers and others of our ilk.
  Others resort to force, as Hello Estonia sees it: Next call for Net phoning : Regulation. The idea of using Skype for emergency calls is beyond belief, per Richard Cobbett. "What wonderful, idyllic, crime-free world does he see in the morning, where technology is reliable and the internet doesn’t die on a daily basis?" Read Richard's "He’s got a gnu!" for a serious chuckle. All the fear mongering could lead to an Online Dating Patriot Act sponsored by True.

If you take comfort in your toolkit, Make your own Skype phone. Not for the faint of screwdriver.

May 23, 2005 08:12 PM | Stuart Henshall

Mixed messages? Two clips from the same day from Skype's website. Are recent E911 rulings scaring Skype? I find real mixed messages here for consumers too. As a Skyper, Skype has replaced the telephone for me. So it is a "replacement." Yet it isn't apparently a "replacement" service.

If VoIP providers want to win / and work with users to get the "right" regulation in play then better language is required. Users don't care about quibbles. Portray it as a "nomadic service", define it as a "socialnet", or augmented communications. It is both very much more and very much less. It is certainly different. Users know this.

What feedback is Skype getting from country regulators? How are the current experiments in the US, UK, Denmark, Poland, Finland, Sweden, France, and Hong Kong going? (Note Norway is no longer available.)How many numbers have now been issued?

Skypetelephony.jpg

Skypenottelephony.jpg While I'm happy with the service having spent another 55 Euro today on Skype for an English number and more minutes others may want to read the terms and conditions There are not a lot of guarantees there. We understand the emergency dialing, and then most phone companies would refuse to guarantee your number too.

April 25, 2005 03:21 AM | Phil Wolff

Andrew Ferguson is a disturbed young man. Brilliant, but disturbed. Funny and innovative. But disturbed.

You know the email spam you get that says, please call this bloke in Africa to send him money to (fill in the appeal here) in the wake of (insert natural or national disaster)? Well Andrew decided to call. Using SkypeOut. Interminably. At odd hours. Tying up the con-man's phone line.

Aside from the dark pleasure of petty revenge, what's going on here?

Skype's design favors offensive tactics

First, there's an imbalance in our cost of calling. As a Westerner, he can afford 10 Euros for 10 hours of calls. If he buys more, the rate falls even further. As a percent of disposable income, this is small potatoes to Andrew.

Second, there's an asymmetry in the opportunity cost of tying up the spammer's phone line. Others aren't getting through to the spammer, so every hour the line is tied up is a sucker missed and money foregone.

Third, Skype calls can be automated. So you can program a thorough barrage of short calls scattered throughout the day. And night. This optimizes your use of your SkypeOut minutes since there is not per-call charge, just a charge for the time. It also exploits the spammer's need to answer each time the phone rings or never talk to another sucker. So every call both increases the effort needed to capture a sucker, since for each sucker there are dozens or hundreds or thousands of fake calls. With little effort (one programmer coded this in 20 minutes) you can make it pointless for a spammer to keep a given number.

Take this a step further: decentralize. Create a spam filter that looks for, say, new Nigerian phone numbers in your email spam bin. Automatically grab them, and post to a listserve, sharing targets. Then have your Skype run the attacks against multiple targets, randomly selected by you and others. This decentralizes the work, aggregates your SkypeOut minutes, buying power, and exposure (if someone tries to find out who you are) among many Skypers. Putting the Power of Many to use.

This is a hoot.

Until the number being attacked is a fire department, or a hospital, or your home. Or air traffic control, or a credit card processing center. Or your mobile phone, where you have to pay high rates for every call, even one lasting just a few seconds.

What can you do about a telephonic denial of service attack?

Other than changing your number?

Maybe we can adapt defenses against flooding attacks in other media, like email and DNS. Maybe not; much of the information used on the Internet isn't available with POTS.

Can you detect an attack building up?

How about a distributed DOS attack?

Who would you call for help?

After the fact, which laws would apply? When would Skype cooperate with law enforcement or civil litigators to provide SkypeOut logs connecting calls to SkypeOut user accounts? Would Skype provide billing data?

And could we blame it on Andrew? Or his Doctor from Nigeria?

April 24, 2005 11:54 AM | Phil Wolff

Skype Journal confirmed that Skype users in the United Arab Emirates are blocked from the Skype.com web site. United Arab Emirates mapThis prevents users of the Skype internet telephone system from buying minutes to call at highly discounted rates, of special importance to the many expatriates who work in Dubai. We don't know where the actual blocking is taking place (presumably at Etisalat's Emirates Internet and Multimedia, the only ISP in the UAE), at whose direction, or for what purpose.

Motives may be economic. About 2.5 million people live in the UAE, 1.6 million are non-nationals. There are more phones than people: 1.1 million land lines (operated by Etisalat) and 2.9 million mobile. Etisalat has a monopoly on telephony.

The motive may be one of political control. Skype automatically encrypts conversations, making it costly and difficult to tap conversations or determine calling patterns.