Microsoft finally injects end-to-end chat crypto into Skype – ish...

If you sign up to be a tester

By Iain Thomson in San Francisco

Posted in Personal Tech, 11th January 2018 23:06 GMT

Microsoft has bunged end-to-end encrypted communications into beta versions of Skype using the open-source Signal protocol.

Redmond has been a laggard in locking down Skype as a truly end-to-end encrypted comms system – end-to-end meaning only the people talking to each other can decrypt the chatter, leaving Microsoft and whoever may be eavesdropping on the connections in the dark.

To be clear, Skype uses standard encryption for audio and video calls, and texts and file transfers. However, it is possible for Microsoft to decrypt, or be forced to decrypt, this information. End-to-end crypto ensures only each end of the conversation – the people talking to each other – can decipher messages.

Skype's incoming end-to-end protection, dubbed Private Conversations, safeguards audio calls, text messages and shared files. Crucially, it is only, for now, going out in a limited release to Skype Insider testers. And it can only be used for one-on-one chats. The group conversations Redmond is touting as a key business tool won’t be covered by the Signal system.

"With Private Conversations, you can have end-to-end encrypted Skype audio calls and send text messages or files like images, audio, or videos, using the industry standard Signal Protocol by Open Whisper Systems," said Microsoft program manager Ellen Kilbourne on Thursday.

"The content of these conversations will be hidden in the chat list as well as in notifications to keep the information you share private. You can only participate in a private conversation from a single device at a time. You can switch the conversation to any of your devices, but the messages you send and receive will be tied to the device you’re using at the time."

Snowden

Signal is the gold standard of end-to-end encryption. Its development is headed by dreadlocked computer security guru Moxie Marlinspike at Whisper Systems, and the code is endorsed by the likes of Edward Snowden and Bruce Schneier. Google's Allo, Facebook's WhatsApp, and the social network's Messenger client have been using Signal since 2016. One has to wonder why it has taken so long for Microsoft to get onboard.

Once upon a time, Skype's distributed peer-to-peer communications was considered pretty good for privacy. However, in 2012, a year after Microsoft bought Skype, the service moved to using supernodes hosted inside Redmond's data centers for communication, a move that some said was to make it easier for the tech giant to work with law enforcement to intercept calls and other chatter.

Skype denied the claims in a carefully worded memo, saying the changes were all about improving the quality of service and making it easier to roll out new applications. Microsoft does hand over some people's details and chat logs where "legally required and technically feasible," Mark Gillett, the company's chief operating officer said at the time.

PRISM

But then came the Snowden disclosures, and it turned out that things at Skype were not as they seemed. The comms biz was part of the NSA's PRISM surveillance network, which punted emails, chat logs, VoIP traffic, files transfers, and other private stuff at the American intelligence agency – and Microsoft was a founding member of PRISM back in 2007.

To make matters worse there were also reports that Skype had been running an internal team, codenamed Project Chess, that was tasked with making it easier for the Feds to not only collect metadata, but also to listen in on calls and conversations.

Whether Microsoft's latest move to Signal will really help is in question, given the software goliath's past tactics ad cooperation with Uncle Sam. Those who really want secure communications should probably just cut out the middleman, and install Signal's app.

Separately, there was a flap earlier this week about hackers and spies being able to slip into Signal-protected WhatsApp group chats by compromising WhatsApp servers. However, Marlinspike explained that doing so would tip off everyone in a group that someone had been added, and that all end-to-end encrypted conversations up to that point in the group could not be read by the snoop anyway. ®

Sign up to our NewsletterGet IT in your inbox daily

20 Comments

More from The Register

Skype for Biz users: Go watch nature vids. Microsoft wants you to get good at migration

New roadmap for Teams does everything but name Skype's death date

That terrifying 'unfixable' Microsoft Skype security flaw: THE TRUTH

Oh yeah, we patched that in October, Windows giant yawns

Microsoft says Skype outages are over – a few hours too early

Global Skype outages spill over onto a second day

Microsoft beefs up Skype for Business as Amazon Chimes in

Corporate comms face-off

Can't login to Skype? You're not alone. Chat app's been a bit crap for five days now

Something something two-factor authentication – Microsoft

Belgian court says Skype must provide interception facilities

Microsoft classified as a telco, so told to cough up. It may gaufre an appeal

Microsoft officially hangs up on old Skype phones, users fuming

Then again it has been four years coming

Microsoft boasted it had rebuilt Skype 'from the ground up'. Instead, it should have buried it

Users slam attempt to infuse app with social media magic

Cortana, please finish my sentences in Skype texts for me

Redmond's AI assistant can now scan your messages and make your more eloquent

Skype, Slack, other apps inherit Electron vuln

Updated Devs, check your protocol handling, patch if necessary