<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Are your Skype username and password completely exposed if you use iSkoot?</title>
	<atom:link href="http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/feed/" rel="self" type="application/rss+xml" />
	<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/</link>
	<description>Collective thoughts and musings on the state of VoIP security today.</description>
	<pubDate>Fri, 16 May 2008 02:27:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: iSkoot SSL Problem, Disclosure Of Skype User Names And Passwords, Has Been Fixed. &#124; VoIP MoVoIP Blog</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-188707</link>
		<dc:creator>iSkoot SSL Problem, Disclosure Of Skype User Names And Passwords, Has Been Fixed. &#124; VoIP MoVoIP Blog</dc:creator>
		<pubDate>Wed, 07 May 2008 15:07:38 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-188707</guid>
		<description>[...] have been following Dameon Welch-Abernathy, a.k.a. PhoneBoy&#8217;s discovery of the iSkoot program disclosing Skype user names and passwords, the problem has been taken care [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] have been following Dameon Welch-Abernathy, a.k.a. PhoneBoy&#8217;s discovery of the iSkoot program disclosing Skype user names and passwords, the problem has been taken care [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Voice of VOIPSA &#187; Blog Archive &#187; iSkoot disclosure of Skype credentials resolved - new version by Wednesday</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-183885</link>
		<dc:creator>Voice of VOIPSA &#187; Blog Archive &#187; iSkoot disclosure of Skype credentials resolved - new version by Wednesday</dc:creator>
		<pubDate>Mon, 28 Apr 2008 17:07:16 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-183885</guid>
		<description>[...] you have been following this weekend&#8217;s discovery by Dameon Welch-Abernathy, a.k.a. PhoneBoy, of the iSkoot program dis... (see also the chronology), you will know that the problem has been fixed and a formal statement [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] you have been following this weekend&#8217;s discovery by Dameon Welch-Abernathy, a.k.a. PhoneBoy, of the iSkoot program dis&#8230; (see also the chronology), you will know that the problem has been fixed and a formal statement [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Voice of VOIPSA &#187; Blog Archive &#187; Chronology of the blogosphere and iSkoot weekend response to the iSkoot security issue</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-183844</link>
		<dc:creator>Voice of VOIPSA &#187; Blog Archive &#187; Chronology of the blogosphere and iSkoot weekend response to the iSkoot security issue</dc:creator>
		<pubDate>Mon, 28 Apr 2008 13:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-183844</guid>
		<description>[...] Voice of VOIPSA Collective thoughts and musings on the state of VoIP security today.      &#171; Are your Skype username and password completely exposed if you use iSkoot? [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Voice of VOIPSA Collective thoughts and musings on the state of VoIP security today.      &laquo; Are your Skype username and password completely exposed if you use iSkoot? [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security flaw on iSkoot: discovered and solved over the weekend &#124; LucaFiligheddu.com</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-183787</link>
		<dc:creator>Security flaw on iSkoot: discovered and solved over the weekend &#124; LucaFiligheddu.com</dc:creator>
		<pubDate>Mon, 28 Apr 2008 07:49:46 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-183787</guid>
		<description>[...] perspectives to the story here, here, here and [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] perspectives to the story here, here, here and [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Courtney</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-183651</link>
		<dc:creator>Jim Courtney</dc:creator>
		<pubDate>Sun, 27 Apr 2008 21:19:57 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-183651</guid>
		<description>Dan,

As a result of an email exchange I have had with Mark Jacobstein, he set his developers to work today (Sunday) and came back with the following statement:

"Unfortunately, it turns out that Dameon was right. We’re not sure how, but a non-production Symbian build ended up on the site, and it had this bug. We’re pulling the build and fixing the bug and will be doing a forced upgrade to every Symbian user as soon as possible. We also checked all the other builds, and they’re all fine (Windows Mobile, Blackberry, J2ME, etc.)"

Dameon's and your diligence are appreciated by all; also kudos to iSkoot for addressing the issue so promptly such that we can all be assured of the security integrity of iSkoot going forward (even if one had to do handstands combined with backflips to find the security bug).

</description>
		<content:encoded><![CDATA[<p>Dan,</p>
<p>As a result of an email exchange I have had with Mark Jacobstein, he set his developers to work today (Sunday) and came back with the following statement:</p>
<p>&#8220;Unfortunately, it turns out that Dameon was right. We’re not sure how, but a non-production Symbian build ended up on the site, and it had this bug. We’re pulling the build and fixing the bug and will be doing a forced upgrade to every Symbian user as soon as possible. We also checked all the other builds, and they’re all fine (Windows Mobile, Blackberry, J2ME, etc.)&#8221;</p>
<p>Dameon&#8217;s and your diligence are appreciated by all; also kudos to iSkoot for addressing the issue so promptly such that we can all be assured of the security integrity of iSkoot going forward (even if one had to do handstands combined with backflips to find the security bug).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan York</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-183212</link>
		<dc:creator>Dan York</dc:creator>
		<pubDate>Sun, 27 Apr 2008 00:58:53 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-183212</guid>
		<description>Mark,

Thank you for commenting here and providing a response from iSkoot. Your statement is consistent with what is on your website, what is in past interviews and, quite frankly, what I would expect for you to do.

However, Dameon has now posted a tcpdump packet capture showing a Skype username and password ( http://www.phoneboy.com/2244/proof-of-iskoot-passing-credentials-in-the-clear ). If it were SSL-encrypted there is no way he should be seeing this.

Something is not right here - and probably the best step for all involved would be for you and Dameon to be directly in contact and sort this out.  I will send you contact information via email.

Thanks again for your comment,
Dan

P.S. Regarding the use of WiFi, as far as I understand Dameon is running your *regular* program on his dual-mode Nokia phone. Your program uses his phone's *data connection*, which would normally be the carrier network unless he is in range of a WiFi hotspot in which case his phone flips to use WiFi for the data connection. This should be transparent to you and as far as I know an SSL connection would work identically across either data connection.</description>
		<content:encoded><![CDATA[<p>Mark,</p>
<p>Thank you for commenting here and providing a response from iSkoot. Your statement is consistent with what is on your website, what is in past interviews and, quite frankly, what I would expect for you to do.</p>
<p>However, Dameon has now posted a tcpdump packet capture showing a Skype username and password ( <a href="http://www.phoneboy.com/2244/proof-of-iskoot-passing-credentials-in-the-clear" rel="nofollow">http://www.phoneboy.com/2244/proof-of-iskoot-passing-credentials-in-the-clear</a> ). If it were SSL-encrypted there is no way he should be seeing this.</p>
<p>Something is not right here - and probably the best step for all involved would be for you and Dameon to be directly in contact and sort this out.  I will send you contact information via email.</p>
<p>Thanks again for your comment,<br />
Dan</p>
<p>P.S. Regarding the use of WiFi, as far as I understand Dameon is running your *regular* program on his dual-mode Nokia phone. Your program uses his phone&#8217;s *data connection*, which would normally be the carrier network unless he is in range of a WiFi hotspot in which case his phone flips to use WiFi for the data connection. This should be transparent to you and as far as I know an SSL connection would work identically across either data connection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Jacobstein</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-183095</link>
		<dc:creator>Mark Jacobstein</dc:creator>
		<pubDate>Sat, 26 Apr 2008 20:34:55 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-183095</guid>
		<description>Hi Dan -

I'd like to reassure you and our users that our clients absolutely utilize SSL encryption and that nothing with respect to our security measures--which iSkoot regards with utmost importance--has changed in our recent client releases. As indicated on our website, the user's password is stored on the handset only, and any time this information is sent to the server it is 100% SSL encrypted. We never store passwords to the server.

Additionally, please note that iSkoot does not have a WiFi client available on the market. Our clients utilize the mobile voice and data channels only, and users cannot utilize iSkoot over WiFi. If users are running a mobile Skype client via WiFi, they are not using publicly available iSkoot product. I can also assure if we did release a WiFi client to market, our security measures would be no less stringent - we always employ SSL encryption.

Best regards,

Mark Jacobstein, CEO
iSkoot Inc.</description>
		<content:encoded><![CDATA[<p>Hi Dan -</p>
<p>I&#8217;d like to reassure you and our users that our clients absolutely utilize SSL encryption and that nothing with respect to our security measures&#8211;which iSkoot regards with utmost importance&#8211;has changed in our recent client releases. As indicated on our website, the user&#8217;s password is stored on the handset only, and any time this information is sent to the server it is 100% SSL encrypted. We never store passwords to the server.</p>
<p>Additionally, please note that iSkoot does not have a WiFi client available on the market. Our clients utilize the mobile voice and data channels only, and users cannot utilize iSkoot over WiFi. If users are running a mobile Skype client via WiFi, they are not using publicly available iSkoot product. I can also assure if we did release a WiFi client to market, our security measures would be no less stringent - we always employ SSL encryption.</p>
<p>Best regards,</p>
<p>Mark Jacobstein, CEO<br />
iSkoot Inc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PhoneBoy</title>
		<link>http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/#comment-182928</link>
		<dc:creator>PhoneBoy</dc:creator>
		<pubDate>Sat, 26 Apr 2008 15:53:20 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/?p=372#comment-182928</guid>
		<description>I did not do extensive testing, but I saw it at least once per session. In my mind, once is enough to create an exposure risk.</description>
		<content:encoded><![CDATA[<p>I did not do extensive testing, but I saw it at least once per session. In my mind, once is enough to create an exposure risk.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
