Unencrypted Skype Data Represents Security Risk

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
Full name, birthday, phone numbers, email addresses and complete chat transcripts? Yeah, I think Microsoft might want to look into this. :eek:

Skype keeps personally identifiable information (PII) and chat transcripts in an unencrypted file, on the local system. That statement in and of itself is the risk. Let’s look a little further into the file of concern: main.db. Could they have chosen a more obvious name for this database?
 
lol.
Experience counts for nothing with some companies.
 
This is old as shit and is carried on from the Skype days before Microsoft.
 
If someone has physical access to your computer, they own it. If they're running code on it, they own it.
 
Why is this surprising? It's a database. So you store the data using a standard database format. Just use a SQL database reader to open it and read the contents. Trivial.

To be fair to the Skype devs, this is supposed to be a VIDEO chat program so storage of text chats is of secondary concern to them. It won't be anything to do with the NSA.

What is funnier is that when you tell Skype to delete your chat logs it doesn't bother zeroing the database. As part of my job I did some forensic work on a Skype database for a client. Client's husband thought he had been deleting his chat logs. Didn't take too long with a Hex editor to rebuild many of his "deleted" chats. Which meant his "secret" affair was not secret anymore.... He is now an ex-husband.

Pretty comical at the amount of data left scattered around a PC. Trails that lead to be able to piece together all kinds of details about you. If you are paranoid, encrypt the hard disk, and physically keep that computer under lock and key.

Or just plain don't have an affair whilst still allowing your wife access to the same laptop!!
 
Back
Top