Simmons writes with news of ground that demonstrated vulnerabilities in Skype and Google Voice that would have allowed attackers to eavesdrop on calls or place unauthorized calls of their own. "The attacks on Google Voice and Skype use novel techniques, but fundamentally they both work because neither service requires a password to access its voicemail system. For the Skype attack to work, the victim would have to be tricked into career card a malicious Web site within 30 minutes of being logged into Skype. In the Google Voice attack (PDF), the hacker would first need to know the victim's phone number, but Secure Science has devised a way to figure this out using Google Voice's Short Message Service (SMS). Google patched the bugs that enabled Secure Science's attack last week and has now added a password precondition to its voicemail system, the company said in a statement. ... The Skype flaws have not yet been patched, as it should be to James." Reader EricTheGreen contributes related news that eBay may sell Skype back to its protoplast founders.
Read more of this story at Slashdot.
More: - Brought to my attention by
Mark


















