Security Hole In Skype Allows Users To Surreptitiously Connect To Other Users

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
Reddit user Ponkers posted an interesting find to /r/Android today, pointing out a significant privacy hole in Skype that essentially allows users to force an Android device to answer a call, making eavesdropping nearly effortless.

Ponkers drew a diagram below, which I feel compelled to include based on its artistic merits, but here's the gist of how the process works.
Assume you have three devices, device 1, device 2, and device 3. There are also two Skype accounts involved: account A and account B. Device 1 and device 3 are attached to account A. Device 2 is attached to account B.

If a user uses device 1 to call device 2, then shuts off any network connection to device 1, device 2 will then automatically call and connect to device 3, giving the holder of account A a connection to device 2 without the owner of the device necessarily knowing.


Security Hole In Skype Allows Users To Surreptitiously Connect To Other Users
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top