|
|
|
|
|
by BadCRC
4781 days ago
|
|
couldn't they be using this to prevent/detect spam? edit: the article claims this can't be so because the page only does a HEAD request, though a HEAD request could be useful if you wanted to detect an HTTPS domain with ephemeral pages (which perhaps, could be a good feature in detecting spam domains) |
|
Furthermore they used test URLs containing hypothetical login credentials and showed how skype would get access to these.
The last troubling bit the author points out is that there seemed to be anomalous traffic to URLs shared in a skype conversation, where a microsoft IP seemed to attempt what they call a "replay attack".