Eavesdropping On Google Voice and Skype
Simmons writes with news of research that demonstrated vulnerabilities in Skype and Google Voice that would have allowed attackers to eavesdrop on calls or place unauthorized calls of their own. “The attacks on Google Voice and Skype use different techniques, but essentially they both work because neither service requires a password to access its voicemail system. For the Skype attack to work, the victim would have to be tricked into visiting a malicious Web site within 30 minutes of being logged into Skype. In the Google Voice attack (PDF), the hacker would first need to know the victim’s phone number, but Secure Science has devised a way to figure this out using Google Voice’s Short Message Service (SMS). Google patched the bugs that enabled Secure Science’s attack last week and has now added a password requirement to its voicemail system, the company said in a statement. … The Skype flaws have not yet been patched, according to James.” Reader EricTheGreen contributes related news that eBay may sell Skype back to its original founders.
Read more of this story at Slashdot.