Skype flaw reveals users' identities
security experts have exposed a loophole in voice over Internet protocol (VOIP) service, Skype, that allows hackers to identify individuals, track their location, and view their file-sharing habits, IT Pro Portal notes.
In a report, researchers identified potential vulnerabilities present in Skype, which is one of the most popular VOIP platforms and was acquired by Microsoft earlier this year.
According to Help Net Security, real-time communication in the Internet is naturally done via peer-to-peer networks. However, this exposes the IP addresses of all the participants in a conversation to each other.
According to the researchers, other IM applications such as MSN Live and Google Talk can also be used instead of Skype to harvest the user's IP address.
The research paper, titled “I Know Where You are and What You are Sharing”, made several recommendations for improving Skype's ability to conceal the identity of its users, The Register reveals.
The report explains that one way would be to design a VOIP system so that IP addresses are not revealed.
Adrian Asher, chief information security officer in Microsoft's Skype division, says: “We value the privacy of our users, and are committed to making our products as secure as possible.
“Just as with typical Internet communications software, Skype users who are connected may be able to determine each other's IP addresses. Through research and development, we will continue to make advances in this area, and improvements to our software.”

