28 April 2008
iSkoot is passing passwords in the clear!
Dameon (PhoneBoy) found and reported a security leak in the S60 iSkoot which is passing passwords in the clear, unencrypted and exposing your SkypeID and password under very stringent conditions.
He put a packet-trace on his WiFi router, and used the Nokia N95 to access iSkoot via WiFi rather than the way it is more usually accessed which is over the air.
This morning he has also provided a dump of the session to prove to the network geeks out there that his assertion is correct.
iSkoot team responded very quickly, issue has been acknowledged and addressed already, they are working on the solution and they’ll fix the issue as soon as possible. iSkoot CEO Mark Jacobstein says the existing S60 build will be pulled. The bug will be fixed and a forced upgrade to a patched version will be pushed.
In meantime, if you one of those that uses iSkoot over WiFi connection better don’t use the WiFi at a public access point or change the password on your Skype account to something that you don’t use anywhere else.
 |