Last week Skype announced Skype Prime. In a nutshell, Skype prime allows individuals to run their own pay-per-use or pay-per-minute VoIP services. I have not tried this service yet, but I can already realize how this is both a great and potentially bad thing:
What makes it great? It makes it very simple for you to offer premium phone services to the Skype community. You could offer tech support or homework help for $0.50 a minute or you could offer a daily joke for a $1 a call. Or, you can charge certain people more money to call you so that they don't call you every 3 seconds. While not necessarily good, although not necessarily bad, I wouldn't be surprised if this turns into a huge porn venue (heck, you can charge for video calls, I would be surprised if someone didn't start such as service already). But then there are the downsides.
Imagine if you will that you initiate a call legitimately to a 'Prime' provider and you accept their fees, but then feel you didn't get what you were promised? Or you agreed to a high per-minute rate and felt that they were prolonging the call? What is your medium for dispute? How are both buyer and seller protected? (funny, doesn't this sound a lot like eBay issues?)
Worse than that, I am sure that it won't be long before folks find illegitimate ways to profit from this. For example, a malicious user could theoretically force you to download a skype Plug-in that randomly calls a 'prime' service and eats away your credits. They wouldn't even have to rob you blind - they could extract 10 or 20 cents from a few hundred thousand people and still make some serious cash. Or, they could offer prime services in some obscure currency that masks the real rate and makes the service seem cheaper. In the former case, it would cause skype to change the rules and permissions for writing extras, thereby eliminating some of those skype extras that are legitimate.
While I think that this has a lot of potential on the upside, the downside of it is really scary, and I hope the Beta Period Helps Skype figure out how to address some of the security concerns.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Monday, March 12, 2007
Friday, February 16, 2007
Tell me something I didn't already know.
C|Net today reports that Symantec has just published some research performed by scientists at the University of Indiana that exposes a possible vulnerability of consumer routers. As King Solomon wrote in Ecclesiastes, there is nothing new under the sun. Since they came onto the market, home routers have had many a security hole. Something that many people have (myself included) have been warning about for years. However, this research simply shows a practical attack that is very simple to pull off.
In a nutshell, they put together some simple JavaScript/Java code that logs on to your router and changes your DNS settings. In doing so, attackers could say, re-route your requests to say, your banks website so that when you type in https://www.mybank.com - you are really logging in to their phishing site, and you wouldn't know the difference, as even most existing phishing filters would be fooled. (You can get a full PDF here: http://www.cs.indiana.edu/cgi-bin/techreports/TRNNN.cgi?trnum=TR641 ).
Of course, this is just scratching the surface. For example, there are certain brands of routers that use GPL'd code, and make the source code available on their websites. Are truly enterprising Hacker could - download this code, and use a similar method to upload it to replace your router's firmware. The changes could be almost invisible to the end-user, but far more malicious. Why? Think about what those attackers could do.
They could easily modify the router's code to capture and/or intercept all web traffic coming through the router. On the benign side they could, say, re-write Google's ads with their own. On the more malicious side, they could easily capture passwords, credit card numbers and more. Or find other ways of using your web viewing habits against you. They could also forgo the use of computers as 'Zombies' for DDOS attacks, and put them straight on the router. Even worse, they can make the traffic appear as if its coming from any of the PC's on your network.
What's even worse - they don't need to exploit the default password or an uprotected wi-fi network. They can simply publish their code on their website and tout that they have a
'high-performance' version of the firmware.
Granted wi-fi routers are great, and provide tremendous benefit for their owners, I hope that this research will enable manufacturers to take more steps towards securing them.
In a nutshell, they put together some simple JavaScript/Java code that logs on to your router and changes your DNS settings. In doing so, attackers could say, re-route your requests to say, your banks website so that when you type in https://www.mybank.com - you are really logging in to their phishing site, and you wouldn't know the difference, as even most existing phishing filters would be fooled. (You can get a full PDF here: http://www.cs.indiana.edu/cgi-bin/techreports/TRNNN.cgi?trnum=TR641 ).
Of course, this is just scratching the surface. For example, there are certain brands of routers that use GPL'd code, and make the source code available on their websites. Are truly enterprising Hacker could - download this code, and use a similar method to upload it to replace your router's firmware. The changes could be almost invisible to the end-user, but far more malicious. Why? Think about what those attackers could do.
They could easily modify the router's code to capture and/or intercept all web traffic coming through the router. On the benign side they could, say, re-write Google's ads with their own. On the more malicious side, they could easily capture passwords, credit card numbers and more. Or find other ways of using your web viewing habits against you. They could also forgo the use of computers as 'Zombies' for DDOS attacks, and put them straight on the router. Even worse, they can make the traffic appear as if its coming from any of the PC's on your network.
What's even worse - they don't need to exploit the default password or an uprotected wi-fi network. They can simply publish their code on their website and tout that they have a
'high-performance' version of the firmware.
Granted wi-fi routers are great, and provide tremendous benefit for their owners, I hope that this research will enable manufacturers to take more steps towards securing them.
Subscribe to:
Posts (Atom)
