Skypodon II has been launched... Here come the probers. Part of the Skype-database exposed.

I blogged aobut this earlier. Now I putting a bit more online. I find it the right thing to do. If Skype want to become a business-tool well them it must fix certain issues. On the other hand the current user-population must be aware of certain risks. Use it wisely. If you are a company you will defenitely have to device a proper implementation strategy, IT-policy and contingency-plan. Skype in essence is quite safe,but hey there are some problems. Let’s not hide behind «some Public Relations firewall» or «marketing hype» ignoring public secrets but address them straight-on. Here goes. It seems to me that the «exposure» of one problem leads to an escalation of something else that floats to the surface. For example See the Blog of Bucken Fush.
. Look at the screendumps of this program that will probe the public skype / p2p-supernodes (I call it supernode hopping) for available logged on names. It is called Skypeprobe and will attach itself to the Skype Client and start digging. Note that I am not the maker of exploiter of this program. I just was informed of it’s existence. I think there are quite some issues here that need to be addressed. See the Screendumps.
I am convinced that if one program exist and floats to the surface that there are others too, doing the same thing.
Some issues come to mind :
- should this part of the database of skype not be protected against such software
- there are thousands types of abuses that can and will occur.
- how can business have faith in Skype as a potential business application if this is possible
- what if some marketing agencies will start doing data-mining on these data. the phone-numbers and email are present
- should Skype not protect it’s users from these kind of exploits ?
- is this fixable or patchable ?
- maybe it is not such a big problem after all. (those who says that have not been thinking, sorry).
- what concept and blue-print lays behind the presence of such phenomena, this can hardly be called a bug anymore…
- does the nature of P2P-system allow control ?
Whatever, you make about it. I consider this a serious breach in the security of Skype. It better be addressed and acknowlegded and properly fixed.
Related : Net phone services falling short






























I like it.
I don't like it.









Recent Comments