A security researcher has found it’s possible to reveal a Skype app user’s IP address without the target needing to even click a link. Microsoft said the vulnerability does not need immediate attention.

99 points

People still use Skype?

permalink
report
reply
55 points

You just hurt the feelings of 5 internet users

permalink
report
parent
reply
3 points

And mine.

permalink
report
parent
reply
18 points

You’re number 4.

permalink
report
parent
reply
17 points

People still use Skype?

Relevant parody

permalink
report
parent
reply
4 points

Here is an alternative Piped link(s): https://piped.video/watch?v=ZI0w_pwZY3E

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I’m open-source, check me out at GitHub.

permalink
report
parent
reply
2 points

How have I missed that 🤣

permalink
report
parent
reply
2 points

Look at all of his other Message from the CEO of ____ videos. They are amazing.

permalink
report
parent
reply
1 point

Lol!!

permalink
report
parent
reply
66 points

The attack could pose a serious risk to activists, political dissidents, journalists, those targeted by cybercriminals, and many more people.

Lmao like they’re using Skype when trying to hide

permalink
report
reply
24 points

Hello. I am evil hacker cyber criminal.

If you want to discuss terms, find me on Skype at EvilHackerCyberCriminalGuy69.

Do not be fooled by the 69, as while it can be seen as a joke, it is my birth year as the original name was taken.

Thank you.

permalink
report
parent
reply
5 points

I use 88 in stuff as well. I didn’t realize until way to late that 88 is a nazi thing.

permalink
report
parent
reply
17 points

Have to be honest, I thought Skype was discontinued years ago.

permalink
report
parent
reply
8 points

It was but we forgot to tell our grandparents, and Microsoft

permalink
report
parent
reply
5 points

somehow Emperor Skype returned

no matter how many times you say no it keeps coming back, same with Edge

permalink
report
parent
reply
3 points

i did too. i’m genuinely not sure why it exists. microsoft is making teams into its favorite productivity app, and i can’t think of anything skype has that teams doesn’t. why does skype still exist?

permalink
report
parent
reply
3 points

Because it sucks quite a bit less than Teams. I know I’ll be sad to see it go when companies eventually switch to Teams. They’re already running side by side in most places now while companies are migrating so it’s only a matter of time. Microsoft will probably announce end of life sometime this year.

Skype basically bridged the time it took Microsoft to come up with their own conferencing solution so now that Teams is here to stay they can take Skype out back and shoot it.

permalink
report
parent
reply
13 points
*

On a serious note, most of those people (activists, journalists, etc.) aren’t exactly the computer savvy types, nor have the time or resource to spend learning about matters they seldom know about, and yet they are the ones that desperately need this knowledge. They might have an important message to be sent. What would you use to spread the message in their shoes?

Sure, we the tech guys, especially subscribed to privacy related communities, can talk about Tor browser or threat modeling all day. But have you tried bring that up in social circles, if any?

Non tech minded activists will simply use the tools at their disposal: messaging apps? sure; social media apps, if looking for message amplification, whatever it runs on their cheap android phone. Metadata? IP? Profiling? Browser fingerprinting? Some are aware of it, as they also had to endure internet censorship growing up. It’s a trade they make knowingly or unknowingly between the cause and their physical and mental health.

We can laugh at their ignorance all we want, but this is how we become the Ivory tower that fuels resentment.

permalink
report
parent
reply
53 points

Ohh no, someone on the Internet might have my IP address! The horror! What if they try to ping me?!

permalink
report
reply
11 points
*

People used to use this attack in League of Legends a decade ago. If they’re losing, they guess someone might have Skype open; and moreover, that their Skype is the same as their summoner name. Then they get an ip address and ddos the entire lobby, causing the game to crash (I think it happened in one of my games maybe once, but I didn’t really play ranked other than team ranked).

Also, since all pro & semipro players had each other added, this was possible to do at any time during online tournaments (which was most tournaments - TSM invitational etc). So there were always rules that ddossing was disallowed. But it did happen.

Known ddossers were more hated in the community than known flamers, but a few people who did it “reformed” and went on to be pro players anyway.

permalink
report
parent
reply
6 points

What if they leave an anonymous tip that you’re distributing CSAM?

permalink
report
parent
reply
27 points
*

With just an IP? Then the system is broken. Because an IP is often easy to get, and everything that directly connects to you needs your IP, unless you use a VPN I guess.

Every website knows your IP. Every internet application knows your IP. Everyone in a peer-to-to-peer network knows your IP. It’s not a secret, it’s just your internet address. It is designed to be known.

permalink
report
parent
reply
7 points

Yk I was on the others side of this til this comment, like I was gonna say there’s a difference between corporations and malicious individual actors, but nowadays I’d trust some random individual 1000x before a company.

God I hope veilied becomes popular

permalink
report
parent
reply
48 points

Is this even news? Literally an exploit as old as time.

permalink
report
reply
9 points

I remember my friends and I doing this in 2008. This really is super old

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
parent
reply
35 points

When Skype was still in common use, this was a very known issue. I’m in lots of gaming communities, and you had to be careful about who knew your username because you could have your IP exposed then get DDoS.

Possibly they patched it and this is a new instance of this, but it was like this for years and years before.

permalink
report
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 11K

    Posts

  • 506K

    Comments