silicon-valley-sleuth

a blog from

Skype stumbles into the security big leagues

  • Tweet this

Skype today was forced to publish a clarification to its justification for last week's service outage.

Skypebuglg1 The company implicitly blamed Microsoft for crashing the service, because it's monthly update forced users to reboot and sign into Skype.

The message was clear to the press and bloggers: Skype was trying to shift blame for the embarrassing crash to a company that has served as the world's whipping boy for over a decade.

22 Aug 2007

Today's clarification finally provided a (somewhat) detailed report about what happened. It's wasn't so much a denial of service attack. Instead Skype was unable to recover from the loss of a large amount of so-called "supernodes", regular users who essentially act as a central server in the Skype's peer-to-peer model.

Skype called these problems onto itself with its poor management of the whole incident. Information was released piecemeal, and there didn't appear to be a clear policy regulating what should be released. Skype furthermore appears to be the only company that issues security bulletins on its blog.

Microsoft by contrast has some experience with plugging security holes, and has the whole system down to an art. That's one reason why, when it looked like Skype was blaming Microsoft, few people believed it.

Skypecrash

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.
To send to more than one email address, simply separate each address with a comma.