A security researcher has found it’s possible to reveal a Skype app user’s IP address without the target needing to even click a link. Microsoft said the vulnerability does not need immediate attention.

  • RedditWanderer@lemmy.world
    link
    fedilink
    English
    arrow-up
    60
    arrow-down
    1
    ·
    1 year ago

    The attack could pose a serious risk to activists, political dissidents, journalists, those targeted by cybercriminals, and many more people.

    Lmao like they’re using Skype when trying to hide

    • rar@discuss.online
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      edit-2
      1 year ago

      On a serious note, most of those people (activists, journalists, etc.) aren’t exactly the computer savvy types, nor have the time or resource to spend learning about matters they seldom know about, and yet they are the ones that desperately need this knowledge. They might have an important message to be sent. What would you use to spread the message in their shoes?

      Sure, we the tech guys, especially subscribed to privacy related communities, can talk about Tor browser or threat modeling all day. But have you tried bring that up in social circles, if any?

      Non tech minded activists will simply use the tools at their disposal: messaging apps? sure; social media apps, if looking for message amplification, whatever it runs on their cheap android phone. Metadata? IP? Profiling? Browser fingerprinting? Some are aware of it, as they also had to endure internet censorship growing up. It’s a trade they make knowingly or unknowingly between the cause and their physical and mental health.

      We can laugh at their ignorance all we want, but this is how we become the Ivory tower that fuels resentment.

  • jrest18n@lemm.ee
    link
    fedilink
    English
    arrow-up
    31
    ·
    1 year ago

    When Skype was still in common use, this was a very known issue. I’m in lots of gaming communities, and you had to be careful about who knew your username because you could have your IP exposed then get DDoS.

    Possibly they patched it and this is a new instance of this, but it was like this for years and years before.

  • Filipdaflippa@lemmy.ml
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    2
    ·
    1 year ago

    Wait you can still do this? I was booting people off games when they would use the same user as their Skype over 10 years as a script kiddie, how is it not patched by now

  • howrar@lemmy.ca
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    4
    ·
    1 year ago

    If you connect to anything on the internet, you’re giving out your IP address. Why would this be any more of a concern?

    • TORFdot0@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      1 year ago

      Users may consent to giving Microsoft their IP address but not to everyone who sends them a link

    • Redditiscancer789@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      edit-2
      1 year ago

      Lol I love how behind the times academics can be. This literally was a big thing used to ddos streamers back in the day like 2010s-2015s. All that needed to happen was they accepted a call and since Skypes peer to peer the hacker instantly got their IP. I remember Destiny being targeted for a while by it.

  • Franzia@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    2
    ·
    1 year ago

    What the fuck. What percentage of people uses skype? I’d really rather see coverage of the exploits found in discord, zoom, slack, etc.

    • marmo7ade@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 year ago

      I’d really rather see coverage of the exploits found in discord, zoom, slack, etc.

      You intentionally clicked on this link.

  • Swim@lemmy.ca
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    1 year ago

    This is soo old that’s how they would ddos clan leaders and shot callers back in the acheage days

    • LinusSexTips@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 year ago

      Was common practice in procurement for me and my team, still have contacts at ASRock / Keychron / Logitech / SteelSeries / Beacn / HYTE / Maxsun and many more.

      Was a platform that was used early on and has carried through. Factories in China will commonly use WeChat but many of the more mainstream western brands will default to Skype.