March-hare / Operator-Distribution

A portable distribution for managing a communications team deployment
http://www.march-hare.org/project/OD
6 stars 2 forks source link

Integrate skype #9

Open evoltech opened 12 years ago

evoltech commented 12 years ago

The research for this has already been done, but it still needs to be implemented. Refer to the issue on march-hare

isislovecruft commented 12 years ago

I take issue with this, due to Skype's accessing of the /etc/password file on linux host systems [1], its use of bandwidth while not being actively utilized (it's basically a voluntary botnet) [2], that it inherently and by default trusts any other application which speaks the same protocol, it creates a file in your /tmp directory called 1.com which reads your BIOS settings and version and also your motherboard serial number [3]. Also, it has been readily established that Skype's cryptosystems are reversible by Skype and parent companies of Skype, including Ebay, who divulged the information of several German users to the US governement [4] [5]. (Sorry that those two references are in German, but I promise that they say what I say they say.)

[1] http://yro.slashdot.org/story/07/08/26/1312256/Skype-Linux-Reads-Password-and-Firefox-Profile [2] http://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-biondi/bh-eu-06-biondi-up.pdf [3] http://www.pagetable.com/?p=27 [4] http://www.heise.de/newsticker/meldung/25199/ [5] http://www.intern.de/news/neue--meldungen/--200711232857.html

evoltech commented 12 years ago

All of these are good points, and it is bad that the application is closed source. I suggest however that this be used where it makes sense and it has often made sense with deployments in the past to provide a PSTN to voip gateway that is easy to setup and allows for rollover functionality. Granted this functionality can be replaced as soon as we fully integrate in ekiga with the asterisk setup, but the process for getting a sip provider and an account is still more involved. With skyp you can provision a call in number that everyone can use without any additional infrastructure. I wouldnt suggest skype for secure communications but I would suggest skype as an easy way to stand up a roll over style call center such as the one that is used by operators during a comms deployment.

Also any binary that uses the getpw function access /etc/passwd, which includes ssh and sshd.