Tuesday, October 28, 2008

Perspectives

The Breaching Trust report that investigated the filtering and surveillance of Tom-Skype continues to generate interest. Today both the Globe and Mail and the New York Times mention the report.

The Globe focused on innovation in research coming our of Canadian Universities, which is a very interesting perspective. One of things that make research at the Citizen Lab so exciting is the ability to use unconventional methods.

The NYT article is about the "global code of conduct" that technology companies and human rights groups have been working on for some time now. It provides guides, for companies like Skype, that aim to "avoid or minimize the impact of government restrictions on freedom of expression." It also sets up "accountability mechanisms" so that compliance can be evaluated.

In effect this is what I have been doing (see Search Monitor and Breaching Trust) independently. While rightfully labeled as a "first step" the significance of this initiative should not be minimized. I'll have to wait and see the official documents scheduled to be released tomorrow, but I believe that these principles will help my research by providing benchmark -- to which these companies have voluntarily agreed -- with which I can evaluate their actual behavior. Hopefully, it will also encourage companies to be more transparent about their practices which definitely helps me interrogate their practices with increased accuracy.

Snips from the articles:

In shadowy Web world, schools are on the case - The Globe and Mail

Through its monitoring, the Citizen Lab discovered swaths of text that failed to make it to intended recipients. The messages had been stored in databases run by the Chinese partner of Skype, Tom Online Inc. Citizen Lab found this thanks to Tom's apparent lax security, which allowed the Lab to find both encrypted information and the key that would allow them to decrypt it on a publicly accessible Web page.


Big Tech Companies Back Global Plan to Shield Online Speech - The New York Times

Currently Google, Microsoft’s MSN division and Yahoo’s Chinese affiliate are all cooperating with the Chinese government’s demands that search results be filtered. This month, Canadian researchers revealed that the Chinese version of the Skype Internet chat and telephony client had been modified to permit the logging of chat sessions and storage of the information on server computers belonging to Skype’s Chinese partner, Tom, a wireless and Internet company.

Wednesday, October 8, 2008

TOM-Skype Trojan.Addclicker

One of the links on skype.tom.com points to http://www.skycn.com/skype1/index.html where another version of TOM-Skype is available for download. When I install this version, I receive a Trojan warning from Norton. The file promote.dll (http://skypetools3.tom.com/download/promote/promote.dll) is installed by TOM-Skype and is flagged by Norton as Trojan.Addclicker:

Trojan.Adclicker is a generic class of Trojan Horses that are designed to artificially generate traffic to certain Web sites. These Trojans send HTTP requests to simulate clicks on banner advertisements, or to inflate Web counter statistics.




According to VirusTotal two other Anti-Virus products identify this file as a trojan (Ikarus: Trojan-Spy.Win32.Mslagent & TrendMicro: TROJ_ADCLICKE.IX).

While this is nothing like the report I recently released, it is another indicator that Skype needs to do something about their relationship with TOM.

Sunday, October 5, 2008

Notable Quotes on TOM-Skype Story

Josh Silverman, President of Skype


What have you learned from TOM about the uploading and storing of certain chats, and what are you doing about it?

What we have discovered in our conversations with TOM is that they in fact were required to do this by the Chinese government.


Josh Silverman, President of Skype


In April 2006, Skype publicly disclosed that TOM operated a text filter that blocked certain words in chat messages, and it also said that if the message is found unsuitable for displaying, it is simply discarded and not displayed or transmitted anywhere. It was our understanding that it was not TOM's protocol to upload and store chat messages with certain keywords, and we are now inquiring with TOM to find out why the protocol changed.


Skype


In 2006, Skype publicly disclosed that Tom operated a text filter that blocked certain words on chat messages but that it did not compromise Tom customers’ privacy. Last night, we learned that this practice was changed without our knowledge or consent and we are extremely concerned. We deeply apologize for the breach of privacy on Tom’s servers in China and we are urgently addressing this situation with Tom.



TOM Online


"As a Chinese company, we adhere to rules and regulations in China where we operate our businesses. We have no other comment,"


Ronald J. Deibert, an associate professor of political science at the University of Toronto.


“This is the worst nightmares of the conspiracy theorists around surveillance coming true. It’s ‘X-Files’ without the aliens.”



Rebecca MacKinnon, Hong Kong University


"We may never know whether some of those people whose conversations were logged have gone to jail or have had their lives ruined in various ways as a result of this," said Rebecca MacKinnon, an Internet expert at Hong Kong University.


Isaac Mao


"The problem with Skype is that they did more than what people expected. They over-satisfied the government," said Isaac Mao, one of China's earliest and best known bloggers.


Danny O'Brien, EFF


While it might disclaim responsibility, arguing that this political spyware was not directly written by its own coders, the company is directly implicated by its close relationship with TOM. When Chinese visitors go to the Skype homepage, they are redirected to a page offering a download of TOM's compromised client version.



Leslie Harris, president of the Center for Democracy & Technology


"Companies have to start looking at their human rights risks as part of their bottom line when they go into difficult markets -- and plainly they are not doing it,... It's not enough to say that we have to comply with local laws. It's not clear to me that any of this complies with China's law. It's just the perfect example of what not to do at every level."


Marc Rotenberg, executive director of the Electronic Privacy Information Center


"For users of Skype, this is not good news," Marc Rotenberg, executive director of the Electronic Privacy Information Center, told the E-Commerce Times. "Skype was supposed to enable more secure communications. It's largely prevented this kind of interception from occurring."


Bruce Schneier, the chief security technology officer of BT Group PLC


"For a couple of years, maybe more, people have had the suspicion ... that Skype pretends to be secure but actually isn't," said Bruce Schneier, the chief security technology officer of BT Group PLC, the British telecom carrier. "The Chinese eavesdropping on Skype text messages only adds to the PR problems, the image problems, that Skype has among those who care about security," Schneier added.


Vincent Brossel, Reporters Without Borders


According to Vincent Brossel, in charge of Asian affairs for the news organisation Reporters Without Borders, these revelations are not surprising. “We knew this for months, but this is the first time that a report provides concrete proof”, Brossel told FRANCE 24. “Chinese dissidents have been telling us for a while now that their communications (on the Chinese version of Skype) do not get through, or are subject to interference.”


ImageThief


It's your brand at stake, regardless of whether you're a minority shareholder, you simply licensed the core technology, or you simply had no idea what was going on. This was true for Yahoo, who surrendered all control of what happened with their brand in China when they sold their China operations to Alibaba.com. It's true for Skype's JV with Tom.com in China. A visit to the home page of the Skype-Tom home page reveals tons of Skype branding, while TOM appears only in text links at the top and bottom of the page.

Your Chinese JV partner doesn't care what your stakeholders back home think. This is especially true if you've surrendered control of the technology or hold only a minority stake. It's concerns first and foremost will be 1) the Chinese authorities, 2) profitability or potential thereof and 3) winning Chinese customers. The concerns of your overseas stakeholders will be somewhere way down the list of priorities.

The Chinese government will be involved somehow. They will set censorship guidelines, listen in, demand personal information on users who cross the line or all of the above. Now refer back to the first point in the previous paragraph.


Derek Bambauer

eBay (which has thus far eluded the scrutiny that Microsoft, Google, and others have faced over operations in China) has responded by saying they’ll have TOM-Skype fix the “security breach.” No, not the one that stores all these messages - the one that let Nart access them. This is like spotting a sewage leak like by the flies above it, and vowing to do something about those flies.


Rebecca MacKinnon


Skype is now learning the lesson Yahoo! already learned the hard way: that if you leave your users' privacy and security to your local partner to sort out without paying too much attention to details or thinking through how things might play out, you could burn your users badly and badly damage the credibility of your global brand.


Ross Anderson, University of Cambridge, U.K


"The real issue here is that if you're an American company and you value your public image, you should be very careful about who your partners are in foreign countries," says Ross Anderson, a professor of security engineering at the University of Cambridge, U.K. "It used to be the case that surveillance was done more or less on a per-country basis," he adds. "But more and more, the censorship may be on a per-company basis."

Surveillance was a Chinese Gov't Requirement -- Skype

I raised questions in the "Breaching Trust" report regarding why TOM-Skype started to log their users' messages and who had access to the data? Skype now says that the monitoring was a Chinese government requirement. Now we know why it was done and who had access to the captured messages.

Skype President Josh Silverman writes:


What have you learned from TOM about the uploading and storing of certain chats, and what are you doing about it?

What we have discovered in our conversations with TOM is that they in fact were required to do this by the Chinese government.

Thursday, October 2, 2008

"Extremely Concerned" -- Skype

UPDATE: Skype President Addresses Chinese Privacy Breach -- Josh Silverman's statement on the Skype blog.

The AFP reports:

Skype said it learned just Wednesday that a previously disclosed text filter operated by TOM-Skype, a joint venture between Chinese mobile firm TOM Online and Skype, had been altered.

"Last night, we learned that this practice was changed without our knowledge or consent and we are extremely concerned," Skype, which is owned by US online auction house eBay, said.

"We deeply apologise for the breach of privacy relating to chat messages on TOM's servers in China and we are urgently addressing this situation with TOM," the company said.


AFP

Skype president Josh Silverman said in a statement that TOM Online "just like any other communications company in China, has established procedures to meet local laws and regulations.

"These regulations include the requirement to monitor and block instant messages containing certain words deemed 'offensive' by the Chinese authorities," Silverman said.

"It is common knowledge that censorship does exist in China and that the Chinese government has been monitoring communications in and out of the country for many years," he said.

He recalled that in April 2006, Skype admitted that TOM Online "operated a text filter that blocked certain words in chat messages" and unsuitable messages were to be "discarded and not displayed or transmitted anywhere."

"It was our understanding that it was not TOM's protocol to upload and store chat messages with certain keywords, and we are now inquiring with TOM to find out why the protocol changed," he said.

"We are currently addressing the wider issue of the uploading and storage of certain messages with TOM," Silverman said, stressing that the millions of people around the world using standard Skype software were unaffected.

TOM-Skype Q & A

I have been getting a lot of questions and feedback on the "Breaching Trust" report. I'll try to post more details and answer questions. Here are some of the common questions people have been asking.

How were you able to determine that messages containing keywords were being uploaded to a web server? How did you find and decrypt the messages?

Wireshark. Every time I typed the word "fuck" an HTTP connection was made to a TOM Skype server. I visited the URL directly in Firefox, cut off the file name and was able to view the contents of the directory. With a little poking around I found the encryption key. A few lines of Python and voila. I did not "crack" anything nor was there any "elite" hackery -- just plain, simple stuff.

Is "normal" Skype affected?

No. The Skype software downloaded from skype.com is not affected by the behavior. The only time "normal" Skype users are affected is when they communicate with TOM-Skype users.

What is TOM-Skype and what is the difference between it and Skype?

If you go to www.skype.com from China, you are redirected to skype.tom.com -- so that's version most Chinese people will use.

In 2004 Skype developed a relationship with TOM Online, a leading wireless provider in China, and announced a joint venture in 2005. Skype and TOM Online produced a special version of the Skype software, known as TOM-Skype, for use in China.

What is Skype saying, have they said anything to you?

I contacted Skype to have the security issue fixed before the report was released. So, they have configured the servers so that one can no longer view the logs and they have deleted sensitive files, such as the one containing the encryption key. Other than that contact, I've only seen the
statements they've made to reporters.

The NYT:

Jennifer Caukin, an eBay spokeswoman, said, “The security and privacy of our users is very important to Skype.” But the company spoke to the accessibility of the messages, not their monitoring. “The security breach does not affect Skype’s core technology or functionality,” she said. “It exists within an administrative layer on Tom Online servers. We have expressed our concern to Tom Online about the security issue and they have informed us that a fix to the problem will be completed within 24 hours.” EBay had no comment on the monitoring.


To the WSJ

Jennifer Caukin, a spokeswoman for Skype, said in an emailed statement that the security problem had been remedied as a result of the new report. The idea that China's government "might be monitoring communications in and out of the country shouldn't surprise anyone," Ms. Caukin said. "Nevertheless, we were very concerned to hear about the apparent security issue" that enabled people to view user information, and "we are pleased that, once we informed TOM about it, that they were able to fix the flaw."

In a separate statement, TOM Group said that "as a Chinese company, we adhere to rules and regulations in China where we operate our businesses."


The WSJ blog, has the statement in full.

In the past Skype stated:

The text filter operates on the chat message content before it is encrypted for transmission, or after it has been decrypted on the receiver side. If the message is found unsuitable for displaying, it is simply discarded and not displayed or transmitted anywhere.


What I found directly contradicts this.

How does this relate to Corporate Social Responsibility (and the voluntary Principles of Free Expression and Privacy process)?

This case demonstrates the critical importance of the issues of transparency and accountability by providers of communications technologies. It highlights the risks of storing personally identifying and sensitive private information in jurisdictions where human rights and privacy are under threat. It also illustrates the need to assess the security, privacy and human rights impact of such a decision.

Some companies, such as Google, has stated that while the censor some search results they "will not maintain on Chinese soil any services, like email, that involve personal or confidential data."

In this case Skype appears to have delegated all of the censorship and surveillance responsibilities to TOM - I don't think they read Rebecca's paper; they should. While examining the Yahoo! China - Shi Tao case she warned:

Companies that choose to ignore the broader human rights implications of their business practices are gambling with their long-term global reputations as trustworthy conduits or repositories of people’s personal communications and information.


Are the "key words" censored? Or are the messages just logged?

The only key word that I could use to trigger the content filter (the messages is not displayed to the user) and have logged in the content filter logs (uploaded to the tom-skype server) was "fuck" (and variations like f*ck). If a message contains the word "fuck" it is not displayed to the user (the entire message is not displayed) and the entire message is uploaded and logged.

In the same content filter logs I found that the majority of the logged messages did not contain obscenities, like fuck. However, many of the messages contained words like "Communist Party", I counted the number of logged messages that contained these words, from that I identified what I think are key words. It is unclear if these messages are just logged, or are censored and logged.



Post questions in the comments and I'll try to answer them :)

Wednesday, October 1, 2008

Breaching Trust: An analysis of surveillance and security practices on China’s TOM-Skype platform

[UPDATE: New York Times coverage of the report here.]

Our investigation reveals troubling security and privacy breaches affecting TOM-Skype—the Chinese version of the popular voice and text chat software Skype. It also raises troubling questions regarding how these practices are related to the Government of China’s censorship and surveillance policies.

The questionable security practices of TOM-Online led to the disclosure of millions of records containing personal information regarding mobile phone accounts, SMS messages, and the usage of TOM-Skype. However, this disclosure also confirms that TOM-Skype is censoring and logging text chat messages that contain specific, sensitive keywords and may be engaged in more targeted surveillance.

These findings raise key questions. To what extent do TOM Online and Skype cooperate with the Chinese government in monitoring the communications of activists and dissidents as well as ordinary citizens? On what legal basis is TOM-Skype capturing and logging this volume and detail of personal user data and communication, and who has access to it?

Full Report (mirror)