Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy

Researchers Encode Hidden Messages in Skype Calls

University researchers developed a way to encode hidden messages using the silent portions of a Skype call.

University researchers developed a way to encode hidden messages using the silent portions of a Skype call.

Since Skype transmits voice data using 130-byte packets and silences in 70-byte packets, researchers at the Institute of Telecommunications of the Warsaw University of Technology were able to hide a message using structured sequences of silent packets, according to a report in the New Scientist. Wojciech Mazurczyk, Krysztof Szczypiorsk, and Maciej Karaœ built the SkypeHide (also known as SkyDe) application to demonstrate their technique. The application on the sending computer encodes a message in the silent packets in the call’s data stream.

The application on the receiving computer reads the smaller data packets to extract the message. Hidden messages can contain text, audio or video content, so long as the total message does not exceed the maximum transmission rate of 1kbps.

Mazurczyk and Szczypiorski built on their earlier research in steganography using VoIP streams to build SkypeHide. They had previously developed techniques to use empty fields in the RTCP (Real-Time Control Protocol) and RTP (Real-Time Transport Protocol) VoIP protocols to transmit hidden messages. 
The “packet hijack” is hard to detect, as the packets containing the hidden message would be indistinguishable from the normal packets transmitting silence, according to the New Scientist report.

Skype relies on peer-to-peer connections to make calls, making it difficult for malicious parties to intercept or eavesdrop on Skype calls. However, law enforcement has complained this makes it difficult for them to listen in on suspects and other persons of interest using the service to plan or discuss their activities. While Skype has not discussed how its technology works, there have been hints the company could hand over Skype call log data as part of a legal proceeding.

Microsoft, which now owns Skype, has denied rewriting the tool to include a backdoor to allow eavesdropping.

SkypeHide will be presented in June at the First ACM Information Hiding and Multimedia Security Workshop at the University of Montpellier.

Related Reading: Defeating Skype Encryption Without a Key

Advertisement. Scroll to continue reading.
Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.