The Red Brick Times

  Sunday, July 26, 2009

A general "security warning" about Skype (an internet "telephone" software) was sent out at work. While warning everyone that it was "Not Approved" and "Disciplinary Measures Will Be Taken" for those using it, it did reveal a bit about how Skype , distributed network programs (i.e.: BitTorrent) and other Peer-to-Peer (P2P) programs work. Note that this is from the doom-and-gloom people who stand at the virtual doors waving their arms, invoking spells and weilding +3 hit statistical weaponry. Your results may vary. Contents may have settled during shipment. If you let unknown data streams into your computer, you may see bad things happen.

"Information Security has been made aware of the presence of a number of Skype users in the Company network for both business and personal use. Because of the nature of Skype, this activity poses a significant risk to the exposure of intellectual property and the security of the network in general. We have reviewed Skype and have identified the following risks associated with Skype:

1. Skype’s privacy policy states that they collect video and sound recordings and may share that and other information with third parties.

o This could lead to the disclosure of sensitive and confidential information to unauthorized people.

o Skype creates exposure for the Company with the potential of communications to fall out of Company control. Corporate Legal supports this evaluation.

2. Skype uses peer-to-peer connection to establish communication, which allows it to bypass Company security controls.

o Peer-to-peer allows Skype to be a source of data leakage, and external attacks to the Company network.

3. Skype creates a file in the temp directory which is capable of reading all BIOS data from a PC.

o Once this file is compromised, an attacker could leverage Skype to have access to all BIOS data which could be used to bypass or adjust BIOS level security controls.

4. There are bandwidth issues of the way Skype routes packets on the Company network. Attempt to get the fastest path to the other caller the Skype client leverages other machines on the Network or Internet. Skype will send the packets through other computers running Skype.

o This setup may allow users to intercept other user’s communications.

o This would also result in machines in the Company running slow not realizing that they
are acting as a Skype gateway.
"

Look up Skype and P2P in Wikipedia for an overall view of the protocols involved. Since Wikipedia is the result of peer-to-peer input, the bad things that may happen are not delineated, since some of the peers WANT to be able to get into your virtual drawers.
by Andy (0) comments

       Comments:

Home