V
V
Vlek2013-06-16 06:12:47
Information Security
Vlek, 2013-06-16 06:12:47

How to protect yourself from unauthorized Skype actions?

Several times I noticed that Skype (usually like a thief in the dead of night) rummages through the disks on my computer and even downloads something vigorously (up to 5-10 Mbps) on the Internet. Kaspersky does not interfere. It is possible to stop only by exiting Skype.
How to understand what exactly he downloads?
How to defend yourself from an adversary?

Answer the question

In order to leave comments, you need to log in

6 answer(s)
E
Eugene, 2013-06-16
@r4tz52

First, try running Process Monitor and see what it writes/reads.

T
turboNOMAD, 2013-06-16
@turboNOMAD

Don't use skype.

V
Vlek, 2013-06-16
@Vlek

Thanks a lot!
I downloaded Process Monitor, I'll figure it out, I'll use it.

A
alex_bel, 2013-06-16
@alex_bel

I can't say anything about Windows. I do not work with this OS, but for Linux users I can advise this reading about Skype.
In a nutshell: no one knows what Skype does in the system, because it was specially compiled with decompilation protection.
Just like the nvidia drivers, for example, skype is loaded into the kernel as a binary blob. Roughly speaking, what he is doing there is very difficult to find out.
The best solution, as turboNOMAD rightly said, is not to use Skype.
But if you really have to, then you can reduce the negative impact - run from a user who has a minimum of privileges. Groups "skype, audio, video" will be enough for full-fledged work. That's exactly how it works for me. A virtual machine is not needed.

D
Dmitry Shvalyov, 2013-06-17
@dshster

Most likely, Skype switches to super-node mode (or whatever it is called) and passes through itself the traffic of other people with a weak channel. Somewhere on Habré there was information about this and how to disable the mode through the registry. In general, Skype is still a black box.

G
gjf, 2013-06-17
@gjf

1. A restrictive network policy will not work - Skype either uses the network with might and main, or does not start at all (in the sense that it does not log in).
2. You can try fine-tuning access to disk resources from under HIPS - restrict access to all folders except %userprofile%\AppData\Roaming\Skype Theoretically, it will work. I practically don't know.
3. Run Skype from any sandbox, access to external resources from which is closed (my way).
4. (as I understand it, not your way) Switch to something else, less spying.
PS The supernode mode was already kind of canceled a couple of years ago, so it's irrelevant.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question