Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Skype reads /etc/passwd and firefox profiles.
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
halfgaar
l33t
l33t


Joined: 22 Feb 2004
Posts: 781
Location: Netherlands

PostPosted: Mon Aug 27, 2007 10:52 am    Post subject: Skype reads /etc/passwd and firefox profiles. Reply with quote

Hi,

through slashdot, I found this topic on the skype forums. It states that Skype reads /etc/passwd and the current user's firefox profile. I couldn't find anything on the forums about it yet, so I thought I'd post it here in security. As far as I'm concerned, this can go in the weekly news letter...
_________________
Linux backups the right way.
Get surround sound working.
Back to top
View user's profile Send private message
ttuegel
Apprentice
Apprentice


Joined: 18 Jan 2005
Posts: 176
Location: Illinois, USA

PostPosted: Mon Aug 27, 2007 12:01 pm    Post subject: Reply with quote

As the posts on Slashdot explain, this is no big deal for the following reasons:

1) Most programs read /etc/passwd. You have to, in order to get the username of the user you're running as. Also, since there aren't any passwords in this file, it's hardly a security risk.

2) Skype probably also needs to read Firefox profiles because it has a Firefox plugin.
Back to top
View user's profile Send private message
halfgaar
l33t
l33t


Joined: 22 Feb 2004
Posts: 781
Location: Netherlands

PostPosted: Mon Aug 27, 2007 12:13 pm    Post subject: Reply with quote

The first one I can live with indeed, but I'm not sure about the second one. Why would it read ".mozilla/firefox/4h99k4vs.default/bookmarkbackups" or ".mozilla/firefox/4h99k4vs.default/ScrapBook"? And, if I recall correctly, it there have also been news reports about it reading serial numbers from your BIOS or something.
_________________
Linux backups the right way.
Get surround sound working.
Back to top
View user's profile Send private message
nephros
Advocate
Advocate


Joined: 07 Feb 2003
Posts: 2139
Location: Graz, Austria (Europe - no kangaroos.)

PostPosted: Mon Aug 27, 2007 1:22 pm    Post subject: Reply with quote

Hanlons Razor: Never attribute to malice that which can be adequately explained by stupidity.

My guess is, they are not being malicious, but just didn't know how to do it properly.
Or they want to be on the safe side wrt future changes in the firefox home dir structure.

There are many reasons not to trust Skype, but this is IMO not one of them.
_________________
Please put [SOLVED] in your topic if you are a moron.
Back to top
View user's profile Send private message
halfgaar
l33t
l33t


Joined: 22 Feb 2004
Posts: 781
Location: Netherlands

PostPosted: Mon Aug 27, 2007 2:45 pm    Post subject: Reply with quote

Quote:
There are many reasons not to trust Skype, but this is IMO not one of them.


I'd like to know which other reasons you are referring to.
_________________
Linux backups the right way.
Get surround sound working.
Back to top
View user's profile Send private message
nephros
Advocate
Advocate


Joined: 07 Feb 2003
Posts: 2139
Location: Graz, Austria (Europe - no kangaroos.)

PostPosted: Mon Aug 27, 2007 4:04 pm    Post subject: Reply with quote

halfgaar wrote:
Quote:
There are many reasons not to trust Skype, but this is IMO not one of them.


I'd like to know which other reasons you are referring to.


Oh just consult your favorite Internet Conspiracy Site or (better) newsfroup.
A random link would be this:
http://ultraparanoid.wordpress.com/2007/06/19/why-skype-is-evil/

[EDIT:] also this: http://blackhat.com/presentations/bh-europe-06/bh-eu-06-biondi/bh-eu-06-biondi-up.pdf
_________________
Please put [SOLVED] in your topic if you are a moron.
Back to top
View user's profile Send private message
GNUtoo
Veteran
Veteran


Joined: 05 May 2005
Posts: 1919

PostPosted: Mon Aug 27, 2007 8:19 pm    Post subject: Reply with quote

where are we on the decoding of the skype binary?
when will we have a free(as in freedom) skype implementation?
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum