<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Skype&#039;s IP-leaking security bug creates denial-of-service cottage&#160;industry</title>
	<atom:link href="http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Thu, 23 May 2013 16:13:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686816</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Sun, 24 Mar 2013 04:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686816</guid>
		<description>It&#039;s got bugger-all to do with &#039;means&#039;, I was talking about impact.

Is this really debatable?</description>
		<content:encoded><![CDATA[<p>It&#8217;s got bugger-all to do with &#8216;means&#8217;, I was talking about impact.</p>
<p>Is this really debatable?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SomeDude</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686804</link>
		<dc:creator>SomeDude</dc:creator>
		<pubDate>Sun, 24 Mar 2013 03:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686804</guid>
		<description>So if I understand, &quot;individuals and executives&quot; is code for &quot;people of little means and people of plentiful means&quot;.  Got it.</description>
		<content:encoded><![CDATA[<p>So if I understand, &#8220;individuals and executives&#8221; is code for &#8220;people of little means and people of plentiful means&#8221;.  Got it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dragonfrog</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686682</link>
		<dc:creator>dragonfrog</dc:creator>
		<pubDate>Sat, 23 Mar 2013 23:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686682</guid>
		<description>Yeah - if you DDOS the president of Verizon, they&#039;ll get some serious resources behind DDOS resistance.  If you DDOS someone&#039;s mum, she&#039;s quite likely to be dropped as a customer by her ISP, because it&#039;s much easier for them than protecting her.</description>
		<content:encoded><![CDATA[<p>Yeah &#8211; if you DDOS the president of Verizon, they&#8217;ll get some serious resources behind DDOS resistance.  If you DDOS someone&#8217;s mum, she&#8217;s quite likely to be dropped as a customer by her ISP, because it&#8217;s much easier for them than protecting her.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dragonfrog</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686679</link>
		<dc:creator>dragonfrog</dc:creator>
		<pubDate>Sat, 23 Mar 2013 23:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686679</guid>
		<description>The bug is not that your IP is leaked when a call is established.  The bug is that even if you don&#039;t answer, or even if you have blocked a particular Skype account from being able to call you, the IP address is still revealed.

This is entirely unnecessary - Skype could be engineered so that your IP address is only revealed to the caller when you accept the call.</description>
		<content:encoded><![CDATA[<p>The bug is not that your IP is leaked when a call is established.  The bug is that even if you don&#8217;t answer, or even if you have blocked a particular Skype account from being able to call you, the IP address is still revealed.</p>
<p>This is entirely unnecessary &#8211; Skype could be engineered so that your IP address is only revealed to the caller when you accept the call.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gilbert Wham</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686492</link>
		<dc:creator>Gilbert Wham</dc:creator>
		<pubDate>Sat, 23 Mar 2013 16:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686492</guid>
		<description> It&#039;s just distinguishing two different subjects referred to earlier in the sentence, and the respective threats to both. Stalkers tend to stalk individuals, not corporations.</description>
		<content:encoded><![CDATA[<p> It&#8217;s just distinguishing two different subjects referred to earlier in the sentence, and the respective threats to both. Stalkers tend to stalk individuals, not corporations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: invictus</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686460</link>
		<dc:creator>invictus</dc:creator>
		<pubDate>Sat, 23 Mar 2013 15:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686460</guid>
		<description>Not to mention the latter being able to apply far greater pressure on M$.

I note Skype &lt;a href=&quot;http://www.skype.com/en/business/&quot; rel=&quot;nofollow&quot;&gt;does promote its services specifically for business settings&lt;/a&gt;. There must be a corporation or two out there who&#039;ll sit up and take notice of this glaring security hole, right? Right?</description>
		<content:encoded><![CDATA[<p>Not to mention the latter being able to apply far greater pressure on M$.</p>
<p>I note Skype <a href="http://www.skype.com/en/business/" rel="nofollow">does promote its services specifically for business settings</a>. There must be a corporation or two out there who&#8217;ll sit up and take notice of this glaring security hole, right? Right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686428</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686428</guid>
		<description>Yep, not to mention an Achilles’ heel for security over the years as well.</description>
		<content:encoded><![CDATA[<p>Yep, not to mention an Achilles’ heel for security over the years as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686427</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686427</guid>
		<description>Hopefully, it&#039;s been an unreliable POS for years.</description>
		<content:encoded><![CDATA[<p>Hopefully, it&#8217;s been an unreliable POS for years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686425</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686425</guid>
		<description>Guess we can say bye to Skype! ;D</description>
		<content:encoded><![CDATA[<p>Guess we can say bye to Skype! ;D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686423</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686423</guid>
		<description>Strange, it shows compatibility with Safari in Windows, but not Safari on Mac.  Never seen that before.  Guess for now have to use Chrome, Firefox Nightly on Mac?</description>
		<content:encoded><![CDATA[<p>Strange, it shows compatibility with Safari in Windows, but not Safari on Mac.  Never seen that before.  Guess for now have to use Chrome, Firefox Nightly on Mac?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686424</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686424</guid>
		<description>It really is super cool.

Our primary involvement is design (we&#039;re an agency) but I&#039;ll pass it on!</description>
		<content:encoded><![CDATA[<p>It really is super cool.</p>
<p>Our primary involvement is design (we&#8217;re an agency) but I&#8217;ll pass it on!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686422</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686422</guid>
		<description>Very cool!  Good luck!</description>
		<content:encoded><![CDATA[<p>Very cool!  Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686421</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686421</guid>
		<description>Just spotted a reference to WebRTC - that&#039;s the ticket.</description>
		<content:encoded><![CDATA[<p>Just spotted a reference to WebRTC &#8211; that&#8217;s the ticket.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686420</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686420</guid>
		<description>I believe so yes!

(I&#039;m working on a product in a &#039;non-technical&#039; capacity that&#039;s launching next month)</description>
		<content:encoded><![CDATA[<p>I believe so yes!</p>
<p>(I&#8217;m working on a product in a &#8216;non-technical&#8217; capacity that&#8217;s launching next month)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686419</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Sat, 23 Mar 2013 13:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686419</guid>
		<description>This?

http://code.google.com/p/sipml5/</description>
		<content:encoded><![CDATA[<p>This?</p>
<p><a href="http://code.google.com/p/sipml5/" rel="nofollow">http://code.google.com/p/sipml5/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686418</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Sat, 23 Mar 2013 12:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686418</guid>
		<description>&quot;Is their privacy somehow more important than other peoples&#039;?&quot;

I wouldn&#039;t say it&#039;s more &#039;important&#039;, but it&#039;s potentially a lot more destructive.

DDOSing your mum is likely to have a different affect to DDOSing the president of Verizon.

Kind of a given isn&#039;t it?</description>
		<content:encoded><![CDATA[<p>&#8220;Is their privacy somehow more important than other peoples&#8217;?&#8221;</p>
<p>I wouldn&#8217;t say it&#8217;s more &#8216;important&#8217;, but it&#8217;s potentially a lot more destructive.</p>
<p>DDOSing your mum is likely to have a different affect to DDOSing the president of Verizon.</p>
<p>Kind of a given isn&#8217;t it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686417</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Sat, 23 Mar 2013 12:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686417</guid>
		<description>Some new in-browser SIP options coming soon thanks to new browser technology. Stay tuned.</description>
		<content:encoded><![CDATA[<p>Some new in-browser SIP options coming soon thanks to new browser technology. Stay tuned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SomeDude</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686414</link>
		<dc:creator>SomeDude</dc:creator>
		<pubDate>Sat, 23 Mar 2013 12:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686414</guid>
		<description>&lt;BLOCKQUOTE&gt;this vulnerability could allow stalkers or corporate rivals to track the movement of individuals and executives as they travel between cities and states.&lt;/BLOCKQUOTE&gt;I can&#039;t figure out what the intent was when mentioning &quot;executives&quot;... are they not individuals, and therefor already covered by the earlier phrasing?  Is their privacy somehow more important than other peoples&#039;?</description>
		<content:encoded><![CDATA[<blockquote><p>this vulnerability could allow stalkers or corporate rivals to track the movement of individuals and executives as they travel between cities and states.</p></blockquote>
<p>I can&#8217;t figure out what the intent was when mentioning &#8220;executives&#8221;&#8230; are they not individuals, and therefor already covered by the earlier phrasing?  Is their privacy somehow more important than other peoples&#8217;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686387</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Sat, 23 Mar 2013 09:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686387</guid>
		<description>It&#039;s a shame for people that purchase a static IP address.  Seems like if you use Skype, you should change to a dynamic IP address while you&#039;re doing it.  Or, better yet, don&#039;t use Skype at all until they get around to fixing this security bug.

If they never fix it, find a different service; Let them go out of business, they deserve it for this kind of gross ineptitude.</description>
		<content:encoded><![CDATA[<p>It&#8217;s a shame for people that purchase a static IP address.  Seems like if you use Skype, you should change to a dynamic IP address while you&#8217;re doing it.  Or, better yet, don&#8217;t use Skype at all until they get around to fixing this security bug.</p>
<p>If they never fix it, find a different service; Let them go out of business, they deserve it for this kind of gross ineptitude.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alexk</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686329</link>
		<dc:creator>alexk</dc:creator>
		<pubDate>Sat, 23 Mar 2013 03:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686329</guid>
		<description>If you had bothered to read the article, you would have seen that it doesn&#039;t talk about getting the ip from a direct connection. That required that you have added someone and initiated a direct connection with him.
These sites use a modified client that creates a debug log from where you can extract the last known IP the client has connected from.</description>
		<content:encoded><![CDATA[<p>If you had bothered to read the article, you would have seen that it doesn&#8217;t talk about getting the ip from a direct connection. That required that you have added someone and initiated a direct connection with him.<br />
These sites use a modified client that creates a debug log from where you can extract the last known IP the client has connected from.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleknevicus</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686328</link>
		<dc:creator>Aleknevicus</dc:creator>
		<pubDate>Sat, 23 Mar 2013 03:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686328</guid>
		<description>Using your phonebook analogy...

Even though you give your phone number to selected people, you still might want an unlisted number.

There are many reasons why you don&#039;t want *everyone* to have access to the information you give to certain parties.  </description>
		<content:encoded><![CDATA[<p>Using your phonebook analogy&#8230;</p>
<p>Even though you give your phone number to selected people, you still might want an unlisted number.</p>
<p>There are many reasons why you don&#8217;t want *everyone* to have access to the information you give to certain parties.  </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: merreborn</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686290</link>
		<dc:creator>merreborn</dc:creator>
		<pubDate>Sat, 23 Mar 2013 01:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686290</guid>
		<description>Isn&#039;t this inherent in skype&#039;s P2P nature?  How exactly do you propose you hide your IP in a P2P network?

Bittorrent is essentially prone to the same problem: you expose your IP to your peers.  The only difference is bittorrent doesn&#039;t happen to tie a username to your activities.

But you could just as easily open a service like this to DDOS everyone downloading a specific piratebay torrent, for example.

Bitcoin and spotify might be similarly exploitable.

Initiating a direct file transfer via most IM clients similarly exposes IP addresses.

&quot;Leaking your IP&quot; seems like a bit of a trumped-up threat.  The phonebook also &quot;leaks your telephone number&quot;, but that&#039;s the cost you pay for direct connections...</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t this inherent in skype&#8217;s P2P nature?  How exactly do you propose you hide your IP in a P2P network?</p>
<p>Bittorrent is essentially prone to the same problem: you expose your IP to your peers.  The only difference is bittorrent doesn&#8217;t happen to tie a username to your activities.</p>
<p>But you could just as easily open a service like this to DDOS everyone downloading a specific piratebay torrent, for example.</p>
<p>Bitcoin and spotify might be similarly exploitable.</p>
<p>Initiating a direct file transfer via most IM clients similarly exposes IP addresses.</p>
<p>&#8220;Leaking your IP&#8221; seems like a bit of a trumped-up threat.  The phonebook also &#8220;leaks your telephone number&#8221;, but that&#8217;s the cost you pay for direct connections&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EH</title>
		<link>http://boingboing.net/2013/03/22/skypes-ip-leaking-security-b.html#comment-1686276</link>
		<dc:creator>EH</dc:creator>
		<pubDate>Sat, 23 Mar 2013 01:14:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=220291#comment-1686276</guid>
		<description>The &quot;someone&#039;s home&quot; is a weird construction, are these tools used amongst and against finance workers?</description>
		<content:encoded><![CDATA[<p>The &#8220;someone&#8217;s home&#8221; is a weird construction, are these tools used amongst and against finance workers?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
