Telecom Security

Telecom and security are main focus of this blog, where I hope to share my experience, findings and ideas with you. Welcome.

Tuesday, October 18, 2005

Top Ten Concerns to Skype Security

As a security professional, I adopt Skype as my primary IM due to its encryption and firewall bypass. Although firewall bypass is the direct experience, encryption is just claimed by Skype. Nothing more about the encryption mechanism, such as the key generation, management and etc. The following is the Top Ten Questions I want to know about Skype security issues:

0 does Skype company de-encrypt/record my talk/chat?
1 besides the parties of the talk/chat, any body else can read/hear the content?
2 how to process the talk/chat traffic along the internet route?
3 is the talk/chat content stored at somewhere else at the internet?
4 how to negotiate the session-key used to encrypt the traffic?
5 how to encrypt the talk/chat traffic?
6 how to store the public/private key pairs of skype client?
7 is there any means to identify the traffic at network layer? (though Verso has succeeded in it)
8 is there any existing mechanism to account/audit the activities of the skype client, or recommendation from Skype?
9 is there any country agents involved at the key management?

What's yours most of concern questions? want to know from Skype?
Most update version, please click to http://blog.zhaol.cn

0 Comments:

Post a Comment

<< Home