PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Microsoft Won’t Patch a Severe Skype Vulnerability Anytime Soon

Posted on February 14, 2018 by pogowasright.org

Normally, something about a Skype vulnerability might be posted over on DataBreaches.net instead of this site, but because therapists may use Skype for online therapy or to communicate with patients, I thought maybe I’d post this one here. Swati Khandelwal writes:

A serious vulnerability has been discovered in Microsoft-owned most popular free web messaging and voice calling service Skype that could potentially allow attackers to gain full control of the host machine by granting system-level privileges to a local, unprivileged user.

The worst part is that this vulnerability will not be patched by Microsoft anytime soon.

Read more on The Hacker News.

Whether Skype is HIPAA-compliant is something that continues to be debated, and I don’t feel qualified to offer any technical or legal opinion on that question, although as I mentioned on Twitter recently, if your choice is whether to absorb some risk or the patient doesn’t get any therapy and has no options, well, it’s worth considering. And as attorney Matt Fisher commented, some of the issue can be addressed by informing the patient of possible risks, and then allowing the patient to make an informed decision.

 

 

Category: BreachesBusinessHealthcare

Post navigation

← In Congressional Testimony, EPIC to Call For Comprehensive Privacy Law, New Privacy Agency
Why I won’t be reading Salon anymore →

2 thoughts on “Microsoft Won’t Patch a Severe Skype Vulnerability Anytime Soon”

  1. anonymous says:
    February 14, 2018 at 12:13 pm

    I actually think it is a great idea. I think this is a great example in how modern technology devices can work in a positive direction in medical/HIPAA related areas. If the kinks of some vulnerabilities can be flushed out, it can be considered an excellent idea.
    It is always best to speak with or see people directly. At least with Skype, you are not exactly in the same room, but at least the parties are seeing each other where they can also observe and pick up on body mannerisms and facial expressions.

    Also is everything ok? The other blog site has “comments off at this time” for the most recent blog posts you are putting up. Is everything ok? One site has comments off and the other site doesn’t

    1. Dissent says:
      February 14, 2018 at 5:15 pm

      I’ve been experimenting with blocking comments due to a harasser/stalker situation.

Comments are closed.

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe
  • AI tools collect and store data about you from all your devices – here’s how to be aware of what you’re revealing

RSS Recent Posts on DataBreaches.net

  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
©2025 PogoWasRight.org. All rights reserved.