Skype has released an external security evaluation of its product; you
can find it at
http://www.skype.com/security/files/2005-031%20security%20evaluation.pdf
(Skype was also clueful enough to publish the PGP signature of the
report, an excellent touch -- see
http://www.skype.com/security/files
[I'm posting the whole thing because the New York Times rapidly expires
all their articles, making it impossible to refer to them over the
long term. --Perry]
http://www.nytimes.com/2005/10/23/technology/23college.html
October 23, 2005
Colleges Protest Call to Upgrade Online Systems
By SAM DILLO
- Original Message -
Subject: [Tom Berson Skype Security Evaluation]
Tom Berson's conclusion is incorrect. One needs only to take a look at the
publicly available information. I couldn't find an immediate reference
directly from the Skype website, but it uses 1024-bit RSA keys, the cover