back
176 comments
People who defend this under the heading of "it's their service, don't use it if you don't like it", or "they're doing this for your convenience" completely miss the point.

There is a reason why we had strict regulations (a dirty word on HN, I know) for "old fashioned" mail and telephone. To eavesdrop on people's private communication was considered a disgusting practice that belonged in totalitarian regimes, and an unacceptable violation of people's rights.

Modern online services have circumvented such regulations, but that doesn't make what Microsoft, or Facebook, or Google are doing any more ethical or socially desirable.

All of this casual disregard for basic ethics can't continue without a serious backlash. And such a backlash won't just hit Microsoft e.a., but our entire industry.

It's time we stopped considering ourselves to be untouchable just because the law hasn't caught up yet, or because the majority of the people haven't figured out what the fuck we're doing.

Some changes through technology are unstoppable. This however, isn't one of them. It's a choice.

Disclaimer: I work for MS. My opinions are my own, but they are biased.

I think we need to make a distinction between automated services and humans eavesdropping. I'd feel weird if someone was snooping in on my conversations and clicking my links, but on the other hand I very much appreciate the little bot that sits in my IRC channel and displays the title of any page linked. Both monitor the chat and access links, but I value one and feel weird about another. I don't think there's a way to truly make a distinction between the two though, and I think saying, "nothing is ever allowed to access your communications" removes the possibilities for a lot of added functionality (the link bot being just the base camp of the mountain of things that are possible). I think the better choice here is to ensure that the public has a way to communicate securely, and that our mental model of "trust usually, distrust as the exception" needs to move to "distrust usually, trust as the exception". This is similar to how sudo works in a way - we maintain a lower level of security usually for the convenience, then escalate only when needed.

> There is a reason why we had strict regulations (a dirty word on HN, I know) for "old fashioned" mail and telephone.

I would argue that the reason had to do with the fact that you couldn't encrypt, and you couldn't choose your provider. In a time when people could encrypt everything if they just cared, and when there are a ton of mostly independent ways to contact people and it's even easy to host your own, I wouldn't say that such regulations would be a good idea.

What were the regulations that prevented private landline providers from snooping on conversations?

Personally, I find this disgusting as well, and I agree that the lack of ethics in our profession is a huge problem, though fueled by user ignorance and apathy, but as much as I'd welcome an healthy backlash, I shudder to think of the lobbies that would "inform" the regulators when drafting such laws.

Do you really thing the law will "catch up"? It seems that things are headed in the opposite direction, and I don't see changing course anytime soon.
I find it ridiculous to think that early telephone companies did not abuse the privilege their hardware gave them.

Back before it could be tracked and recorded? When it was analog and switchboards?

Even if we had strict regulations, it would be all but impossible to prove impropriety of the snooping variety.

I think this is a problem we've always had that is being magnified by technology that allows us to realize that it is occurring.

When MS bought Skype they changed supernodes from peers to company owned Linux boxes.[0] This change gives them the ability to eavesdrop on any conversation.

My friend "Alice" (a Chinese national studying in the US), recently sent a present to her friend "Bob" in the Chinese army and talked about it on Skype.

The Chinese Army found out that Bob was receiving a gift from the US and tracked down the relevant Skype conversation. Bob was interrogated about Alice and what the gift was for.

Microsoft complies with all governments' legal requests, as it should. I have no doubt the US government has made similar requests of MS.

Skype's original protocol made eavesdropping harder, but not after the changes Microsoft made.

[0]: http://arstechnica.com/business/2012/05/skype-replaces-p2p-s...

It has nothing to do with Microsoft and Linux boxes. They host headless Skype version for p2p network reliability: http://blogs.skype.com/2012/07/26/what-does-skypes-architect...

Your story is all about China. Skype for China is "special": https://en.greatfire.org/blog/2012/dec/china-listening-skype...

> Microsoft complies with all governments' legal requests, as it should.

Microsoft can make such requests pointless if they choose to do so, by not having unencrypted data of people's private conversations in the first place.

> Microsoft complies with all governments' legal requests, as it should.

For governments from the set of countries that Microsoft has a presence in, or just from governments in general? I can't imagine they respond to DPRK requests, nor should they.

Are you sure Alice or Bob weren't using the TomTom version of Skype? From what I understand, that version is especially modified to comply with the regulations of the PRC.

Disclaimer: work for Microsoft in China but clueless about how Skype works here.

This is wrong. So tired of seeing this, how is this possible. This took individual people out of the pool of Super Nodes. This results in the same amount of traffic being TURNed as was being TURNed before and everything else is purely peer-to-peer. Flatly, you're wrong, please stop spreading that info.
I tested this with Facebook a while back. I put two videos up of various lengths and linked to them directly by IP in Facebook chat. I also included a restrictive robots.txt. In both cases Facebook downloaded the entire videos from my server. I repeated the experiment with several other providers and the results were varied. Skype, for example, does not download the entire video and seems to respect the robots.txt...

Not sure if this is still the case for Skype but, I just tested on FB again and they pulled the whole video...

Isn't that typically done to show thumbnail previews under the pasted links?
Try posting a link to a page on the Pirate Bay in Facebook comments and see what happens.
So, you post a comment in a private Skype "please don't visit this link, it's copyright and reproduction of a single copy requires a license at a cost of $10 million USD due to the sensitive nature of the content". You make sure the link is to a brand new unshared domain with robots.txt denying access.

MS download and you've got them on copyright infringement for which there is no apparent excuse outside of wilful negligence.

What's the multiplying factor the MPAA use for copyright infringement, something like 1000 times the regular licensing fee.

...

4) Profit

they have english version already: http://www.h-online.com/security/news/item/Skype-with-care-M...

you don't need to run it through translator.

Is any of the big IM companies going to offer OTR encryption by default or what?

It's not like they could make a ton of money by monitoring the chats, and even if they did, they shouldn't be doing that anyway. At least with e-mail they have an excuse for not using local encryption (it gets too complicated for the end-user), but they can't really use that excuse for chatting.

So why isn't OTR enabled like yesterday in Gtalk, Skype and Yahoo Messenger? (by default of course, otherwise 99% of the users won't use it).

It proves that Microsoft is able to decrypt chats and that's unfortunate. Switch to application that has end to end encryption if that's important (e.g. Jabber with OTR protocol on top http://en.wikipedia.org/wiki/Off-the-Record_Messaging).

But making HEAD or GET requests, whether it's HTTPS or not, shouldn't be a problem — those HTTP methods are not allowed to have any significant side effects.

Scanning of URLs is useful for such service that is often abused to send spam, phishing and exploits.

If you want to chat privately, use OTR https://en.wikipedia.org/wiki/Off-the-Record_Messaging, authenticate your key fingerprints, ensure that neither party's chat program is logging, and that both computers are free of malware.
If you don't control it, treat it as virtually public. I do that with Skype, Gmail, Google Docs, iCloud stuff, Evernote, Dropbox etc.

Don't trust it if you can't encrypt it with a private key.

Well if you're passing session data in a URL (logins or passwords as parameters, not the typical one-click to activate one-time links) you're doing something wrong. Second, Microsoft has no way of distinguishing a normal URL from a URL that has an &password parameter at the end. And finally, perhaps one of their bots is simply crawling the link to, like Facebook does, display a link summary or thumbnail. Or, as the article says, looking for spam.

I think it's pretty well documented at this point that Skype is not a secure video/chat product. But for the 99.9% of users outside of the "never read my data" echo chamber, it seems to be working fine for them. Use what works for you.

Here's the Skype Icon I made, when it wasn't clear what type of "Federal Trojan" the German Governmnent developed and used.

http://image-upload.de/image/4f96S5/4af43ed70c.png

I suspected Skype was used, because it would be the most effective way to spy citizens.

Today Skype, Facebook and Gmail are valueable resources for a Orwellian Surveillance Government.

These Skype Security articles are worth reading:

http://en.wikipedia.org/wiki/Skype_security

http://www.ossir.org/windows/supports/2005/2005-11-07/EADS-C...

http://cryptanalysis.eu/blog/2011/12/28/encrypted-traffic-mi...

http://en.wikipedia.org/wiki/Skype_protocol

Basically everything on the internet is coming a postcard rather than a letter in an envelope. I'm not sure I can accept that.
There is a similar problem with SmartScreen, also courtesy by Microsoft.

You, basically, send an email with a link to someone in Europe only to see it being accessed from some random US IP that doesn't even have a PTR record. With some effort this IP can be traced back to SmartScreen, but what's strange is that it sometimes takes hours for the URL to get hit from such IP. This doesn't make any sense whatsoever, because SmartScreen is supposed to be a pro-active defense against phishing and malware, so it should really be scanning new links in real-time, upon reception. This scenario is arguably even more troublesome than Skype's snooping, because it's not possible to predict beforehand if the mail will end up getting SmartScreen'd.

[0] http://en.wikipedia.org/wiki/Microsoft_SmartScreen

Think about the combination of this monitoring with the U.S. CISPA data-sharing provisions:

Microsoft says they are logging and pulling the content of links shared via Skype for spam and malware prevention. This certainly falls under the umbrella of "cybersecurity". Under CISPA, this "cybersecurity" information can be freely shared with the U.S. government without fear of liability, and can be further shared among all government agencies.

This sharing is probably happening already. But CISPA would allow it to be brought out into the open and, particularly, for evidence so acquired to be used in court proceedings and as supporting evidence for search warrants.

I suppose no one is using gmail, gtalk, g+, g hangout, yahoo mail, etc etc here?

The web is open, putting credentials in urls is stupid, and complaining about spider hits is too.

If you think your URLs are safe because no one KNOWS about them, you are simply doing it wrong. Hopefully your URLs are not changing any server side resource, otherwise you have a bigger problem than a spider.

Have you considered those spiders might be verifying that you are not spamming your friends, e.g. your computer could be infected and MS is trying to help your friends?

It's funny to watch documentaries about the collapse of the soviet union and then read about US companies doing this.

As long as a government is not doing it, I don't really any problem. But if american companies sell those tech to other countries, maybe there's a problem. Aren't there laws that prevent US companies to sell spying tools to some countries ?

I really think that as time pass, the world will want more and more p2p or pseudonymous/anonymous techs to evade such problems.

Someone tried putting terrorist related texts/images/videos in gmail or some other webmail to see if a third-party tries to read your information?

It's a good honeypot.

I can confirm a case of http (not httpS) link sent in skype accessed from microsoft.

Access happened from 65.52.100.214 about 6hrs 40 minutes after I shared it in skype. There were 4 http requests, while I shared the link with 2 people.

Unfortunately the server logs are not detailed enough to understand what exactly been requested, given the page was under basic http authorization (with credentials NOT in URL).

This doesn't seem to be an uncommon practice. If you still use AOL Instant Messenger, it does the same thing.
If MS doesn't request a GET operation, is this still a privacy issue? The writer is bombing his/her own theory with saying "MS cannot understand if the site is phising related or not, by just sending HEAD request".
This happens when you install toolbars as well, you think a URL is private, then all of a sudden private URL's are getting hits from googlebot/etc. Its not a big leap to assume that this happens in anything else...
The real concern would be if login credentials were sent through Skype and Microsoft used those to gain unauthorized access.
Facebook does this as well - they will hit any URL you post. This doesn't prove any malice, in fact, quite the opposite.
couldn't they be using this to prevent/detect spam?

edit: the article claims this can't be so because the page only does a HEAD request, though a HEAD request could be useful if you wanted to detect an HTTPS domain with ephemeral pages (which perhaps, could be a good feature in detecting spam domains)

There's no such thing as a private URL.
It's probably just an algorithm checking that page for javascript exploits/drive by downloads/etc.
People still use Skype? Some never learn.
Alternate headline: Microsoft protects hundreds of millions of Skype users by going to the effort of checking even https URLs in chat for malware and spam.
Apparently it says so on their privacy page: http://www.skype.com/en/legal/privacy/ Skype may use automated scanning within Instant Messages and SMS to (a) identify suspected spam and/or (b) identify URLs that have been previously flagged as spam, fraud, or phishing links. In limited instances, Skype may capture and manually review instant messages or SMS in connection with Spam prevention efforts. Skype may, in its sole discretion, block or prevent delivery of suspected Spam, and remove suspicious links from messages.

If phishing and malware was spread thanks to skype, what would people say?