Microsoft sees all your HTTPS links in Skype, and you didn't know

4.5
While the Internet gets a reputation for being an anonymous playground, nothing is completely anonymous. Microsoft seems to be proving that point today, with the discovery they're accessing any secured links sent via Skype. Any HTTPS URL transmitted via Skype is picked up by the software giant, and then visited by an IP address from Redmond.

This was first picked up by an anonymous tipster, who informed Heise Security since it bore similarity to a replay attack. Somewhat ironically, Microsoft themselves explain what a replay attack is. In a nutshell, it's repeated legitimate traffic, which is then treated as such.

Heise was able to confirm the tipster's suspicions, using two test URLs to do so. They sent a URL containing login information, and one pointing to a cloud-based service. Both URLs were later revisited by a Redmond IP address, so it was no isolated incident.

You may wonder how this can be justified. It's in Skype's data protection policy, and is for 'preventing spam, fraud or phishing links'.


This bit in the policy has Microsoft covered.

You may remember the open letter which was published after Microsoft's Skype takeover. It queried how the giant would act with US government requests, and whether they would invade user privacy.

Whether you consider this revelation with secured web links an invasion or not, it'll doubtless have some effect.

Posted:
Related Forum: PC General Forum

Source: http://www.neowin.net/news/microsoft-sees-all-your-https-links-in-skype-and-you-didnt-know

Comments

"Microsoft sees all your HTTPS links in Skype, and you didn't know" :: Login/Create an Account :: 49 comments

If you would like to post a comment please signin to your account or register for an account.

slapshot101Posted:

Cougar Like this wasn't known already, they have everything on you.

All these companies have all the information on you, don't you think that Safari, Firefox and Chrome save everything on you too?

OGPurgePosted:

Yea, I thought they saw everything its on their servers.

CougarPosted:

Like this wasn't known already, they have everything on you.

UK_cHaDd3rZPosted:

Vlif
-me0w
Requirement This is neat, but also kinda creepy.


More creepy than neat though.


yeah like, you can't send a nude to your GF without some 45 year old man running Skype seeing it anymore xD


hes not exactly going to skype you and say,

hello vlif,
saw your GF's ****, they look fantastic, you should send her a pic of your ****.


i'm not sure whether any of you realize this but anything you do over the internet can be seen or heard there could be somebody watching your computer right now that is in an organisation such as the FBI, CIA etc. they have most likely been watching for years.

RojoPosted:

Imagine a Microsoft employee looking through the URLs and sees a weird nude pic, I think Microsoft will stop doing this because of the surprises they will be getting be people. :)

HenderPosted:

Well its not that bad if it only logs HTTPS urls, most aren't secure.

PoonPosted:

-me0w
Requirement This is neat, but also kinda creepy.


More creepy than neat though.


yeah like, you can't send a nude to your GF without some 45 year old man running Skype seeing it anymore xD

ii_Bacon_xPosted:

imgur
Requirement This is neat, but also kinda creepy.


How is that neat? That's invasion of privacy, you share something with someone, not someone and a Microsoft employee.


You're using their service. Therefore nothing is between you and someone else. If you don't like it don't use it.

-TamPosted:

scammers are getting caught lol

GossipPosted:

I like when somebody knows my business!!!