Simson Garfinkel analyses Skype - Open Society Institute

Florian Weimer fw at deneb.enyo.de
Fri Jan 28 15:01:11 EST 2005


* David Wagner:

> I don't buy it.  How do you know that Skype is "more secure", let alone
> "vastly more private"?  Maybe Skype is just as insecure as those other
> systems.  For all we know, maybe Skype is doing the moral equivalent
> of encrypting with the all-zeros key, or using a repeating xor with a
> many-time pad, or somesuch.  Without more information, we just don't know.

Skype is unregulated.  PSTN operators (and other VoIP services by
large telcos) are subject to at least some scrutiny.

There's another not readily observable property of Skype's network:
reliability.  Would anyone claim that Skype's network is more reliable
than PSTN?  I don't think so, even though we know as little about its
reliability as about its security.

And please don't forget that privacy of call records is much more
important than encryption of the actual voice traffic.  Doing
interesting things with call record data is much, much cheaper than
voice recognition, entire call archival and so on.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list