Skype Logo Take a deep breath™.
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
Peeter P. Mõtsküla

Changes in the API access authorization logic

By My status Peeter P. Mõtsküla on October 19, 2007 in Developer Blog.

Updated on 2007-10-31: This change will be rolled back from Skype for Windows 3.6 gold. A different solution involving centrally managed whitelist and blacklist will be implemented as soon as possible. Read more about this new solution.

Following the outbreak of a worm that affected some users of Skype for Windows, we have decided to change the way applications get access to the public API the Skype client provides.

Presently, when a new application attempts to gain access to the public client API, Skype client presents the user a dialog box, allowing the user to choose whether to deny access, allow this time only, or allow this application to use the API from now on. The worm used the APIs provided by the Windows operating environment to send mouse clicks into appropriate places on this dialog, choosing "allow from now on" and closing the dialog before most users would even notice.

In order to avoid this, we've decided to start handling code-signed applications differently from these that are not. For applications that come with a valid code signature (e.g. Authenticode), the handling logic remains unchanged. For non-signed applications, Skype will not pop up a dialog box, but will raise a "missed event" notification instead. The user can then click on the event notification, open the access dialog, and decide what to do next.

This new logic is already implemented in internal test builds and will become available to the larger developer and user community when we release the next public beta version of Skype for Windows 3.6.

Additional changes are expected down the road. Please note that neither the timeline nor the exact nature of these further changes are not yet finally decided.

We are planning to make it possible for "trusted" applications to gain access to the public client API without ever requiring the user to explicitly allow them to do so (the users will still have an opportunity to deny such applications via the Options dialog if they so choose). "Trusted" will in this context likely include applications that we have evaluated and found to be reasonably safe.

The "reverse side" of this second change is that we'll be able to centrally blacklist applications that we have found to be harmful. Such applications will be denied access to the public client API, and the users will be notified via the events panel, so that they would be able to promptly react to potential malware infection.

We're also discussing the possibility that in future, a valid code signature will become a mandatory prerequisite for any public API access.


We believe that these changes benefit the end users and "good" developers alike. For the end users, this will definitely mean lower risk of becoming a target, or unwilling distributor, of malicious software. For the developers, it would probably mean increased willingness of the end users to try out various software that works with Skype.

View blog reactions

Comment on this post

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Back to index

Subscribe to this blog
What? Tell me more…

using RSS Subscribe
via Bloglines Subscribe in Bloglines
using Newsgator Subscribe in NewsGator Online
with MyYahoo
with Google Add to Google
with My AOL Add to My AOL
with Anothr.com Subscribe by Anothr
with netvibes Add to Netvibes
with email Get email updates
Skype Developer Newsletter

Sign up now for all the latest news, tips and tricks on using Skype Public API.

Developer Zone

  • Home
  • Docs
  • Tutorials
  • Download
  • Support
  • Certification
  • Blog
  • Community
  • Help
  • Find...
Skype Blogs
  • Share Skype Blog
  • About Skype
  • Heartbeat
  • Developer Zone
  • Business
  • Jobs
  • Skype Prime
  • Skype Gear
  • Security
  • Garage
  • Mac
  • Linux
  • Eesti keeles
  • Töökuulutuste leht
  • 日本語
  • Česky
  • Deutsch
  • Français
  • Italiano
  • Brasil
  • United Kingdom
  • Svenska
  • Polski
  • United States

Recent posts

  • New Skype Certified product in June -- Trend Micro WTP for Skype
  • Developer Zone version 3 is out there
  • Developer Zone down for maintenance
  • Skype for Business Showcase in Stockholm, Sweden
  • Skype sponsors Python Developer Conference (sold out)
  • Support updates and fixes in EM 2.0
  • New Skype Certified products in April
  • Update from Eion Robb and Brandon Holland
  • Long time partners... SDP, what's going on?
  • Time to Join Skype at the eBay DevCon

Archives

  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
About us · Partners · Jobs · Prices · Security
Privacy policy · Legal · © 2008 Skype Limited