5 ms·
calling this a backdoor is pretty disingenous
by y_u_no_rust 10y ago
calling this a backdoor is pretty disingenous
- ht85 10y agoAn access that bypasses regular security / auth, isn't that the definition of a backdoor?
- shuntress 10y ago'backdoor' comes with the implication that it was included intentionally to allow for future (secret) access. Where it could instead be a bug or mistake that was not intentionally included.
- ht85 10y agoMaybe I misunderstood the current situation? Of course other services exploiting it isn't intentional, but giving a free pass to one of their own services was definitely intentional?
- shuntress 10y agoThe article mentions: "the actual Skype Dashboard widget does not seem to utilize the backdoor into the Skype Desktop API despite the name" which, to me, lends more credence to the assumption that this was perhaps a test or a prototype and only included in the shipped version accidentally.
- brianbarker 10y agoNo. A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. If every system flaw or coding bug is a backdoor, then defects like OpenSSL's Heartbleed would be deemed backdoors, and they're not. Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought.
- ht85 10y ago> Unless you're wearing a heavy tin foil hat and think the coding mistake for Heartbleed was intentional. I guess I can't dissuade you from that train of thought. Are you addressing me personally? What does that have to do with what I said? > A backdoor is considered to be deliberate and obfuscated from easy discovery, with the intent to be secret access. Isn't that the case here?
- brianbarker 10y ago- Not you personally. I have experience with HN comments. Just covering my bases. - No, it's not the case here. Unless you can prove it. There's no evidence it was done intentionally.
- ht85 10y agoWhen I say it was done intentionally, I mean opening an authentication-less was intentional. It could be disguised as an access for their own service and the real purpose be mass surveillance, or it could be a simple mistake in a big codebase, but the "door" is definitely not a bug. Even though nowadays we keep hearing about nefarious backdoors, they used to simply refer to hidden service entrances for software creators, a completely legitimate use.
- linkregister 10y agoIndeed, this is a valid definition of backdoor.
- 0x0 10y agoWhy is it that everything either has to be a blatant backdoor or an innocent mistake or tinfoil hat territory? I find it hard to believe that nobody ever wrote a backdoor and took the time to conceal it as an innocent, plausible mistake.
- Kalium 10y ago