All the latest UK technology news, reviews and analysis

Hacker claims to have found Skype hole

by Lawrence Latif

09 Jul 2010

Be the first to comment

  • Tweet this
Skype
Skype has single handedly popularised VoIP calling

Skype's security credentials have been called into question by a developer who claims to have released a software library that emulates an encryption algorithm used by the popular VoIP service.

Sean O'Neill, best known for designing the EnRUPT hash algorithm, has released program code which emulates the RC4 algorithm used by Skype to encrypt communications over its network.

Skype is widely used in home and business environments, and the company guards its source code fiercely.

This has led to numerous attempts to crack the encryption algorithm which would result in conversations being deciphered to 'plaintext'.

An initial analysis of the code appears to show that O'Neill's solution is a partial exposure of Skype's privacy measures.

However, given the resourceful nature of hackers, a small crack could expand into a gaping fissure in a relatively short space of time.

The developer has decided not to reveal further details of his exploits until his presentation at the respected Chaos Communication Congress in December.

Until then, O'Neill has uploaded his code allowing other hackers to test and potentially carry on his hard work.

The wait until O'Neill reveals the extent of his breach of Skype's encryption could result in firms thinking twice before they use the application.

However, Skype hit back at O'Neill in a strongly worded statement. The firm said it was proud of its software's security and that the hacker's efforts "in no way" compromises this.

"We believe that the work being done by Sean O'Neil, who we understand was formerly known as Yaroslav Charnovsky, is directly facilitating spamming attacks against Skype and we are considering our legal remedies," the statement continued.

"Whilst we understand the desire for people to reverse engineer our pro tocols with the intent of improving security, the work done by this individual clearly demonstrates the opposite.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

29%

1%

12%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

PHP Software Developers/Programmers- Automated Trading - London

PHP Software Developers/Programmers- Automated Trading...

1st Level Application Support - Southampton, Hampshire - £20K

1st Level Application Support required to join a leading...

Helpdesk Adviser; Service desk Analyst; Northeast’s; £Neg on Experienc

Helpdesk adviser required for a major organisation in...

.NET Developer

.NET Developer is needed for a financial services...

To send to more than one email address, simply separate each address with a comma.