Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Skype is at its core a p2p idea, so this is expectable. That's sort of the same thing that was done for bittorent users, except with a single centralized authority.

The interesting thing is that they do this without making a call. They only request contact information. This could be avoided.

Skype can mitigate this, but in the end, there is little more to be done. If you want a p2p network where anyone can be reached, at some point, you will need ips.



What they could do is have contact requests go through Skype master servers, not p2p, that way you could only look up the IPs of people you are connected to. But is it a big enough issue that they will make such a big change? I doubt it - and I'm not sure they ought to have to do it, either.


Yes there would have to be master servers to close this hole, but I can't imagine how it can be done without everybody upgrading to the new client, so we can assume that every Skype user's ip is known or will soon be known. The current state will last for a while.

You don't have to be even logged in for this to work(!) according to some already published research.


Note that you are not always forced to be in someone's contact list to contact him. It's a user configurable setting. I wonder if call-blocking for incoming calls from persons not in contact list is done at server level or client level.


Skype sometimes routes calls through a third party. Even when calling you shouldn't be sure that the IP is that of the recipient or the third party.

(The site doesn't work so I haven't read the article.)




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: