Skype Won't Say if it Decrypts VoIP Calls for Law Enforcement

Back door to VoIP calls is possible, report says.

CONNECTIONS
Skype
Thu, July 31, 2008Network World The encryption of Skype VoIP phone calls might not be as secure as you think.

It's possible the company keeps keys so law enforcement authorities can decrypt encrypted VoIP phone calls, a report says, but Skype won't say for sure one way or the other. (Compare IP PBXs .)

According to an online report, Austrian officials with legal authority to tap VoIP phone communications have no problem listening in on Skype calls, which are encrypted as a standard part of Skype service.

A Skype spokesman wouldn't say whether Skype keeps keys to decrypt calls. "Sorry, Skype does not comment on media speculation," says Chiam Haas, who works for Skype's PR firm. "Skype to Skype calls are safe and secure. The privacy of our users' communications is very important to us. Skype cooperates with law enforcement agencies where legally appropriate and technically possible." 

Asked for further clarification, he responded by e-mail with, "This statement is all the company has to say on the matter."

It's virtually impossible to figure out for sure from independent research whether Skype keeps encryption keys or not, says David Endler, chairman of Voice Over IP Security Alliance and senior director of security research at Tipping Point.

"No one has shown it publicly," he says. "Skype is a closed software package, essentially a black box." The company has on rare occasions allowed outside researchers to examine and verify the security of its encryption, but not whether the keys that can crack the encryption can be retrieved, he says.

To allay fears that the calls might not be secure from law enforcement, Skype should open its platform to evaluation by trusted, credible industry experts, he says.

Endler says it's equally difficult to know whether commercial VoIP vendors leave open the possibility of turning encryption keys over to law enforcement.

In the United States, the Communications Assistance for Law Enforcement Act (CALEA) forbids requiring that vendors build in back-door decryption, says Jim Dempsey, vice president for public policy at the Center for Democracy & Technology. "CALEA expressly forbids requiring anyone to be able to decrypt anything," he says.

But that doesn't mean they don't build in key-retrieval anyway. Dempsey says there are no active proposals to force vendors to leave encryption back doors in their VoIP gear, but that could change. "Nothing in regulations is permanent," he says.

Endler says that attempts by researchers to learn more about how Skype works have been effectively blocked by measures put in place by Skype. "They've taken extreme measures to prevent reverse engineering of their client software," he says, more so than mainstream VoIP vendors.

Loading...
Network MarketSpace
White Papers
The Challenge of a Demanding Network Infrastructure
Today's data centers are expanding as demand for data and storage continues to grow exponentially. Learn more »
Reduce Infrastructure and Administrative Costs
The Brocade® FastIron® CX Series of switches provides new levels of performance. Learn more »
A New Generation of Application Delivery Controllers (ADCs)
Learn more about Brocade® ServerIron® intelligent application delivery and traffic management solutions. Learn more »
Want to Offer a Superior User Experience?
Control a "boundary-less" enterprise with scalable solutions. Learn more »
Realize Potential Without Increasing Your Risk
Combining Brocade's high-performance infrastructure and McAfee's Web gateway solution ensures trusted environments. Learn more »
Brocade and Imperva: Providing Best-of-Breed Products
Web applications have become the backbone of business in nearly every segment of the economy. Learn more »
 
SPONSORED LINKS
 

Maximizing the Business Value of the PC Infrastructure

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Seven Ways ITIL Can Help You in an Economic Downturn

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Reduce risk, gain agility. See how Progress can help your business.

Improve ROI, lower TCO and reduce energy consumption.

Introducing the new HP ProLiant G6 server family

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

64-page prescriptive guide to security, compliance, and IT operations.

Get Google Enterprise Search for your business information.

Accenture IT Consulting: Enabling high performance. More...

 
 
RESOURCE CENTER