The End of the "Skype as Bandit" Era

SkypebanditAnd so it ends... Skype was always always a fun company to write about because they were always a bit of a rogue.

The scrappy little startup that took on the megacorps of the telecom industry... and won in so many ways... look at their leading % of international calls... or the fact that per-minute call costs are now very clearly being commoditized down to zero...

... the product that came from the grey areas of P2P file sharing and created some truly revolutionary network technology and created a software client that "just worked" like magic from behind any firewall...

... a company from Estonia of all places, which pre-Skype most of us could only vaguely put on a map but now many of us know more about, including that fact that many Estonians have multiple vowels together in their names in ways we don't in English (ex. "Jaanus" and "Liive")...

... a product that was given away for free across multiple operating systems (even if some of us whined about the lack of attention to our chosen platform)...

... a service that just went ahead and implemented SRTP and encrypted call control when all the major telcos were whining about why they couldn't secure calls over IP because of the demands, latency, blah, blah, blah...

... a product that gave most all of us the first experience we ever had with wideband audio - where it felt like you were right there with the other person... and in fact, many of us found we could record podcasts over Skype (even using video)...

... a product that offers the best implementation of persistent group chats I've yet to see... and that allows globally distributed companies and organizations to work so well together across all timezones and regions...

... a product that truly offered a multi-modal/multi-channel user experience... and raised the bar for all the enterprise products that were trying to deliver "Unified Communications" ... Skype was offering the "UC" experience before "UC was even coined as a term...

... a product that became a verb... "just skype me"...

... and a product that had enough of a sense of humor - and roguishness - to implement emoticons like these:

(banghead)
(bandit)
(moon)
(finger)

(Tip: Don't type the last two in a chat window where people might be offended... and methinks the first one might come in VERY handy with meetings between Skypers and their new masters. :-) )

I started using Skype back in 2004 or so when it was still very early days. In 2005 I started using it to record the Blue Box podcast and to contribute to the For Immediate Release podcast. I was at Mitel in those days in the product management team and I remember back then talking to my peers about how Skype "just worked" through firewalls and how the wideband audio was outstanding.

Since that time, Skype has become part of the DNA of my personal IT infrastructure... I use it extensively for my own communication... and I use it very extensively within Voxeo where it is our Unified Communications tool of choice right now (for reasons I wrote about before). If there's one tool that's always open on my computers, it is Skype.

And Skype is probably the one company/product/service I've written about the MOST on this Disruptive Telephony blog since I launched this blog back at the beginning of 2006. Largely because Skype has been one of the single most disruptive influences on our industry. Sure, many of my posts have been critical, particularly of the new Skype 5.0 for Mac, but they have been critical out of my passion for the product - and of wanting it to be so much better.

And now we who have been raging Skype fanboys confront a new reality...

Microsoft acquiring Skype!

Goodbye, bandits...

... you are no longer fighting "against THE MAN"... you now are "THE MAN"! It's hard to get much bigger of a megacorp than Microsoft!

I do actually think the acquisition is good for Skype in a number of ways:

  • Financial stability - Being part of as large an organization as Microsoft will finally give Skype a bit of room to really figure out their monetization play beyond what they've done so far.

  • Enterprise credibility - Skype has struggled for years to get any kind of real credibility within enterprises. Many have completely blocked Skype and many have no understanding of what it can do. Microsoft completely gets the enterprise... in some ways they own the enterprise... so this can only help Skype grow in business usage... and that's a GOOD thing for those of us who already use it that way.

  • Security - Whatever you want to say about Microsoft, they do understand how to communicate about security, something Skype is lacking. I can only hope that MS will now bring a higher level of communication to this aspect of Skype.

  • Synergy - I'm not a fan of that word... but it makes sense here. Think of the other products Microsoft makes... what if you could get Skype integration into Microsoft Office? what if Skype and Lync could play nice together to connect the whole Skype world to the enterprise UC offering of Lync? what about making Kinect work with Skype? There are a lot of cool things that could be done. (And, of course, we'll undoubtedly see Skype on Windows Phone 7, etc.)

  • Customer Support - And hey, maybe Microsoft can help Skype get a proper customer support organization so that I am no longer their corporate receptionist!

I worry, of course, about the acquisition and what it will do to the tool I use so much. Those of us on NON-Microsoft platforms have complained for years about Skype's lack of attention to our Skype clients. The Mac OS X client has at least received more attention and near-parity with the Windows client (even though many may not be fans of the new UI)... while the Linux client has languished. In the new world of Microsoft, will those other platforms really receive much attention? (despite the requisite platitudes mouthed in the news conferences and stated in the news releases)

And how about the iPad client for Skype that has been rumored? Will that ever see the light of day?

Will Skype truly be able to function independently as a "disruptor of telecom" now that it is part of such a large corporation?

The answers remain to be seen over the next months as the deal moves toward closing. I have many friends who work at Skype and I do wish them all the best through this whole transition... I wish them well seeing how long they can hang on to their Mac laptops and iPhones ;-) ...

... and I wish them much ":-D" and hope they don't experience too much "(banghead)".

Welcome to the new era of Skype!


If you found this post interesting or useful, please consider either:



Skype Issues 2nd Mac 5.1 Hotfix for "Security Issues" - But What Are Those Issues?

skypelogo-shadow.pngToday, Skype issued a new Skype 5.1 for Mac "hotfix" for more "security issues". The problem?
We don't know what those "security issues" are?

We don't know, for instance:

  • Are they related to the remote exploit that was publicly disclosed on Friday? Or to related attacks on the same theme? (as discussed on SecNiche today)

  • What is the severity of these "security issues"? Remote compromise? Denial of service? What?

  • What is the priority that we should place on getting this update in place? Is it a "UPDATE NOW!" kind of priority? or a "Update when you can"?

  • What kind of mitigating circumstances are there for these security fixes?

  • Are there any workarounds that could be put in place at a network layer (or any other layer) to prevent attacks on individual systems? (i.e. as a safety measure until the individual clients are all updated?)

We need to know this kind of information.

Particularly as Skype looks to try to move more into the "business" or "enterprise" market space, this level of NON-disclosure is unacceptable.

In comparison, take a look at any of the recent Microsoft security bulletins, like, oh, this one, and you can see the kind of information that a security professional is looking for. Now, sure, Skype doesn't necessarily need to go to the level of detail that Microsoft has... but something more than just "Security issues" is necessary.

Letting Us Know?

Additionally, why again is Skype issuing a "hotfix for security issues" without telling anyone about it? Just like they did back in April?

Once again the hotfix is mentioned only on Skype's Garage blog. Nothing on Twitter on either @skype or @skypesecurity. Nothing on the Mac blog (although they finally updated that blog about the issue on Friday). Nothing on the Security blog.

And once again, the "Check for Updates..." feature in Skype 5.1 does not show a new update available:

Skype

So apparently the only way we can get this hotfix for unknown "security issues" is to go to Skype's main download site and download it!

C'mon Skype! You can do better than this!

Recommendations for Skype

So rather than just rant, let me offer these suggestions to Skype for what they should do when they have a "security hotfix":

1. Provide More Info - Saying it is simply "security issues" doesn't cut it. We need to know things like:

  • what is the severity of the security issue? if an attacker could compromise the Skype client, what could he or she do?
  • how easy is it for an attacker to execute an attack? can the attacker be remote? do they have to be a contact?
  • are there mitigating circumstances that would make an attack less likely?
  • are there workarounds that could be put in place at a larger level than just the client?
  • what is the potential exposure of NOT upgrading?

Skype should look seriously at tools like the Common Vulnerability Scoring System (CVSS) used by many software/hardware providers (see also the CVSS FAQ). And while perhaps the full CVSS process may be too heavy for a smaller organization like Skype, the document at least gives insight into the type of questions security professionals want.

Similarly, the Cisco Security Vulnerability Policy and associated links is worth a read. Again, it may be too heavy a system for a smaller company like Skype... but then again perhaps in all of the new hires Skype is looking to do they could hire some folks specifically to work on this process.

2. Let People Know About The Security Hotfix - Skype has a "security" blog and specific @skypesecurity Twitter account. They should be used to communicate the availability of security hotfixes. Security professionals associated with companies using Skype could then know that they need to subscribe/follow those sites to know when there are new issues needing attention.

3. Make The Security Hotfix EASY To Obtain - Make the "Check for Updates..." process work from the beginning. The blog post or other update should be able to state that Skype users can simply go up to "Check for Update..." to download/install the new version. Perhaps this means that the blog post has to be delayed until the new version is uploaded to whatever update servers Skype has... but so what? Wait a bit - or improve the internal process so that these uploads happen faster. The end result will be that MORE people will update sooner, which, I would think, should be the goal.

Those three steps would help people feel a whole lot better about Skype's concern for security - and would also make sure that Skype users are better protected. It would also help Skype's reputation, brand, etc.

And it would stop people like me from writing blog posts like this. ;-)

Seriously, Skype... security matters... and even more, communication about security matters. We all know that with any system there are security issues... no system is perfect and attackers will always try to compromise systems. We get that. It is how you react and communicate about those security issues that is so incredibly critical.


Fascinating to Watch AT&T and Sprint Duke It Out Over T-Mobile Acquisition

Interesting piece on the "This Is My Next" site last night about Sprint and AT&T taking to print ads to ratchet up their fight over AT&T's proposed acquisition of T-Mobile:

Sprint and AT&T take merger battle to print: ‘Competition is American, Competition plays fair’

The issue is, of course, that there is a U.S. Congressional hearing on the proposed acquisition this coming Wednesday in D.C. Sprint obviously is opposed to the merger and is pulling no punches in saying exactly what it feels about the proposed merger. I do admit to enjoying one line in their ad:

Competition keeps us all from returning to a Ma Bell-like, sorry-but-you-have-no-choice past.

This definitely IS a concern for all of us as the companies in the mobile space continue to consolidate.

AT&T of course counters with how this will be the best for the country, how it will foster innovation, bring about a stronger network, etc.

It will be interesting to see how this all plays out. For me personally, the proposed merger offers very little. AT&T has poor coverage where I live (Keene, NH) and T-Mobile has even worse coverage of the area... so I don't expect that we'd see any improved coverage here.

On a macro level, the consolidation is concerning... it will be interesting to see what happens in DC this week.


If you found this post interesting or useful, please consider either:



Skype's Security Communication FAIL - Why Issue a HotFix If You Don't Tell Anyone?

skypelogo-shadow.pngWhat is the point in issuing a hotfix that addresses a security vulnerability... if you don't tell anyone that the hotfix is available?

Tonight Skype published a blog post saying that back on April 14th they released a "hotfix" for this problem in Skype for Mac version 5.1.0.922. That's great... it's good that the fix is out there, but...

how were we Mac users supposed to know about it?

Hmmm... let's see... Could we find out about the Skype for Mac hotfix...

  • ... using the "Check for Updates" feature? Nope, doesn't work for me. Maybe it works for others out there, but not for me.

  • ... from the Skype for Mac Release Notes page? Nope, that page STILL hasn't been updated, three weeks later, to indicate that a new version is out. Nothing on there at all about 5.1.0.922.

  • ... from Skype's Twitter account? Nope, no mention of a hotfix back on April 15th, although they did talk about the fact that Skype was mentioned twice on 30 Rock and that there was Skype call on the Rachael Ray show.

  • ... from Skype's skypesecurity Twitter account? Nope, no mention.

  • ... on Skype's Mac blog? Nope. Last post there was April 14th, the day before this hotfix came out.

No mention of a "hotfix" for Skype 5.1 for Mac OS X on any of those communication vehicles.

In The Garage?

Ah, but wait... Skype did mention the hotfix, over on the Skype Garage blog, which is all about "Experiments and pre-releases". Here's a screen capture of the notice:

Skypegarage

So they posted news of this important "hotfix" on a blog for "experiments and pre-releases", didn't tweet it out, and didn't update release notes or put it anywhere regular Mac users would find it.

And a curious thing...

THERE IS NO MENTION OF A SECURITY ISSUE!

Nothing whatsoever.

I am guessing that "Minor bug fixes" must include this security issue. And maybe the fix was simply a "minor bug fix". Maybe someone forgot to do bounds checking on some part of the chat system and as a result a buffer overflow occurred. Maybe it was some simple little fix.

But labeling it in this way gives absolutely no incentive for anyone to upgrade. Even had I seen this notice, I probably wouldn't have bothered to upgrade (unless the Check for Updates had worked). There is no urgency on this.

And... call me crazy, perhaps, but I guess I don't consider a security issue where someone could send me a chat message and gain complete control of my Mac to be a "minor bug"!

Did Skype not think that at some point the security researcher would publish his findings?

And why in the world didn't Skype communicate with this security researcher to tell him that they had fixed the bug he found and would be issuing (in fact had issued a fix)? Now maybe they thought they did... but whatever the situation was, he didn't know and out of frustration published his post today.

It Didn't Have To Be This Way

In other words...

... everything that happened today was COMPLETELY PREVENTABLE had Skype only communicated more.

Skype would not have had the negative coverage in ZDNet, CNet, ComputerWorld, Mashable, TheNextWeb, my own blog ... and many other sites, let alone all the tweeting and retweeting.

Instead of having all this negative activity, they could have jointly come out with a statement with the security researcher or at least crediting the researcher. It would have shown that Skype was serious about security and protecting us - and also serious about working with the security community.

And even after the story broke early today, Skype could have tweeted out a response... or posted the blog post earlier... they could have cut off all the discussions and concerns simply by being more transparent and providing some information - or even just communicating that they were in the process of getting an answer.

Instead, there is only one word to summarize Skype's communications:

FAIL!

The thing that kills me is that Skype employs a ton of truly brilliant engineers. They have on their payroll a couple of the leading SIP/VoIP security researchers that are out there. And these guys know how the security community works.

Knowing some of those folks personally, I have to think that the process broke down somewhere in the external communications side of the house. Because of the IPO and the "silent period", I know that people at Skype are ultra-cautious about saying anything. And maybe that's part of it, but in this case, it truly failed them.

Too bad... because none of all this communication today had to happen.


If you found this post interesting or useful, please consider either:



Sorry, Skype, But Your Auto-Update Feature Is A Fail!

According to Skype's Security Blog post right now, I'm supposed to just do an "auto-update" that will give me the latest version 5.1.0.922 of the Skype for Mac client. When I check what version I have, it is 5.1.0.914:

Skype 1

So I go up to the Skype menu and choose "Check for Updates..."

Checkforupdates

And this is what I get...

Skype

So if, as Skype indicates, this security issue was fixed a month ago, how was I supposed to get it?

Sure... it now seems that I can go to the main page and download the software directly, but why would I ever think of doing that?

C'mon, Skype... if you are going to send out security updates as optional updates, please make sure your "Check for Updates" feature works!

P.S. When I first heard of the security issue, after checking the Skype blogs and Twitter streams, the first thing I did was to go into my Skype 5.1 client and do this "Check For Updates". The next thing I did was check the Skype for Mac Release Notes, which still do not list this update that was apparently fixed in April. After that I did some more poking around and then wrote the blog post...


If you found this post interesting or useful, please consider either:



UPDATED: Skype for Mac Has Dangerous Security Vulnerability... and There's No Public Word From Skype

UPDATE: Skype has now published a blog post indicating that a Skype 5.1 update is available for download. As I noted separately, the auto-update process is NOT working for me. It appears that I will need to download the new version directly from Skype's website.

Separately, Skype PR indicated to me that version 2.8 is not vulnerable - although I note that this information is not in Skype's security blog post. (Skype has now confirmed in a tweet that Skype 2.x is not vulnerable.)

It's great that Skype claims they fixed this in mid-April... but if they didn't tell anyone - including, apparently, the security researcher who reported the issue - what value is it that they fixed the issue?

I have a longer piece that I need to write on this... but I'll leave that for another post.

Meanwhile, we finally do have some information and a fix - many hours after it would have been helpful to have had it.

The original post remains below...


skypelogo-shadow.pngFrom the Can-We-Please-Communicate-Better Department... there is apparently an open vulnerability in the Skype for Mac client that lets an attacker send a message to a Skype user and gain remote access. As reported today by Gordon Maddern on the PureHacking blog:
The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victims Mac. It is extremely wormable and dangerous.

Given that I basically live inside of Skype for Mac and use it extensively every day, this is obviously extremely concerning. Particularly because I do let anyone on Skype send me messages... and my Skype ID is easily found on my websites and many other locations (and since is rather obvious - "danyork"). I also tend to leave Skype running on a Mac in my home office that is online all the time. Mostly this provides a way to quickly catch up on chats as I have all the messages already there on that system (rather than waiting for Skype to sync up after it is launched).

Maddern indicates that he contacted Skype over a month ago about this and no fix has come out yet. In his post, he says:

Pure Hacking wont give specifics on how to perform this attack untill a patch from skype is released. However we will give a full disclosure after skype takes action or a resonable responsible disclosure time.

Which is great... except that now attackers will be out there trying to figure out what kind of "payload" he sent that created this condition. There is always the chance that someone may discover the attack.

Where is Skype's Statement?

ZDNet UK covered the story today and received this update from Skype:

Skype has just sent ZDNet UK a statement promising a fix next week. The statement reads: "We are aware of this and will release a fix early next week to resolve the issue. We take our users privacy very seriously and are working quickly to protect Skype users from this vulnerability."

What is concerning, though, is that there is no other public comment on this from Skype...

It's Friday afternoon here in the US... people are about to leave their offices and some % of those who use Macs may in fact leave their computers on and leave Skype running. Are those machines vulnerable? Can someone really just send someone a message and gain control of their Mac?

Which version of Skype for Mac is vulnerable? Is this only in the newer 5.x client? Or does this impact the older 2.8 client?

We need answers, Skype! I can understand that a fix may take some time, but in the meantime we need to understand what the risk is. Are there mitigating circumstances? Or actions we can take in the meantime?

How To (Maybe) Protect Yourself

So what are we to do until there is either a fix or a helpful statement?

1. QUIT OUT OF SKYPE - Obviously this is one option (and one I might pursue on that computer in my office). But that may not be practical for folks... and isn't for me in my work context.

2. CHANGE PRIVACY SETTINGS - It seems to be the biggest change we can make is to only allow chat messages from people in our contact list. This would mean that a random attacker out on the Internet couldn't just send you a message and take over your Mac. You will only get chat messages from your contacts, not random people.

In Skype 5.x for the Mac, you go to the Skype menu and then Preferences and then make sure that the settings are that only Contacts can contact you:

Skypeprivacy 1

On the Skype 2.8 for Mac client, the layout is a bit different but the choices are similar:

Privacy 1

Now, in these images I'm only suggesting you restrict chat messages. In the blog post about the attack, it is very clear that the attack vector is a chat message, so in theory you should only need to change the one privacy option for chat messages. Whether or not you also want to restrict calls to be from your contacts is up to you. Absent a clear statement about the vulnerability from Skype, we have very limited information to go on... but again the blog post was very clear that the attack was through a chat message with a particular payload.

Will that protect your system? I don't know... I'm guessing along with you all.

Now, depending upon how paranoid your mind operates, there is, of course, the case that an attacker could take over a Mac operated by one of your contacts, and then potentially use the Skype client on that machine to then contact you. Maybe that's possible, maybe that's not.

3. RUN AN OLDER SKYPE VERSION - Does this only affect the newer Skype 5.x for MacOS X? Could we be protected by reverting to the older 2.8 client? (which I'm still running on one of my systems)

I don't know... and I wouldn't use this as my only protection mechanism.

Give us a clue, Skype!

We don't know... and that's not a good space to be in.

What can you tell us who are Mac users, Skype?


UPDATE #1 - The Register also covered the story and pointed out that perhaps the attacking chat message could cause other chat messages to be sent out. Again... possible... but we just don't know.

Also, someone pointed out that Skype did have a "public statement", so my title is not accurate. Sure... they gave a statement to ZDNet UK and perhaps other media outlets... but where is that on Skype's public presence? Why not on one of their blogs or on Twitter?


If you found this post interesting or useful, please consider either:



Skype No Longer Doing The Samba - Drops Inbound Numbers In Brazil

skypelogo-shadow.pngInteresting development in the land of Skype... they are no longer offering inbound phone numbers in Brazil. Per a post on Skype's Portuguese blog, translated into English via Google Translate, the company providing phone numbers in Brazil, Transit Telecom, has notified Skype that it will no longer be supplying these phone numbers.

Skype's inbound numbers are now referred to as "Online Numbers" but were originally called "SkypeIn" numbers. For an annual fee of somewhere between $30 - 60 USD per year (depending upon discounts with subscriptions), you can have multiple inbound numbers attached to your Skype account from a range of countries:

Skypeonlinenumbers

In full disclosure, I've had a SkypeIn/OnlineNumber for years and it works extremely well.

The challenge for Skype, of course, is that they typically have to work with local carriers in the individual countries to obtain those inbound numbers (also referred to as "DIDs" in telecom)... and obviously is at the mercy of the local carrier to keep providing those numbers. Now who knows what happened in this case... perhaps Transit Telecom wanted to charge more than Skype wanted to pay... perhaps they had some other business challenge between the two companies.

Whatever the case, Brazil is no longer an option for an inbound number into your Skype account. Per Skype's note, existing Brazilian numbers will continue to work for the duration of your subscription but will not be able to be renewed. Unless, of course, Skype can find another service provider to provide them with Brazilian DIDs...


If you found this post interesting or useful, please consider either:



Making SIP Phone Calls Over IPv6 Using Linphone on MacOS X, Windows, Linux

Want a softphone that can make calls on IPv6 using the SIP protocol? I was... and kept striking out until I discovered that Linphone: a) ran on more than just Linux (it also supports MacOS X and Windows); and b) worked beautifully with IPv6. I wrote up my findings in this post and included some screenshots:
How To Make SIP Calls Over IPv6 Using Linphone (on Mac, Windows, Linux)

It's quite simple to use (assuming you have IPv6 connectivity) and worked very well in my testing. A big benefit to me was that Linphone lets you do direct computer-to-computer SIP calls, without requiring you to register with a SIP server or other IP-PBX. This gets around the need to have an IP-PBX that is IPv6-connected, which could be a different challenge.

Linphone

As I noted in the blog post, I am definitely interested in any info people have about other softphones that support IPv6. Jitsi (the renamed "SIP Communicator") indicates that it has IPv6 support, but it requires registration with a SIP server, and I don't have one of those running on IPv6. If you have info about other softphones (or other VoIP endpoints), please do leave comments either here or on the other blog post. Thanks!

P.S. And yes, I'll be talking about and demo'ing Linphone in my IPv6 and SIP webinar on Thursday, May 5th.

P.P.S. If you want to set up IPv6 on your home network, I've posted instructions with an Apple WiFi device (Time Capsule, Airport Express) and more generic instructions using Tunnelbroker.net.


If you found this post interesting or useful, please consider either:



Reminder: Free Training on IPv6 and Communications Apps (including SIP) on Thursday, May 5, 2011

voxeologohoriz.pngAs I mentioned last week, I'm speaking in a "Developer Jam Session" on this Thursday, May 5, 2011 on the topic of:
IPv6 and How It Impacts Communication Applications

I'll briefly cover IPv6 basics, talk about how it impacts building communication applications and the SIP protocol and then have some demonstrations of SIP-over-IPv6. You can learn more about the session and register on the Jam Session web page.

It's free to attend the session - and it will be archived for later viewing if you can't get there live during the session.

It should be an educational session and I expect I'll be writing a good bit more about IPv6 in the weeks and months ahead. (You can see some of my writing over on Voxeo's blog at http://blogs.voxeo.com/speakingofstandards/tag/IPv6/ and here on this blog at http://www.disruptivetelephony.com/ipv6/)


If you found this post interesting or useful, please consider either:



Mitel Reorganizes - President Leaves, Business Units Simplified, More Changes

mitellogo.jpgMitel today announced a series of organizational changes, including the departure of Paul Butcher, Mitel's President and Chief Operating Officer. The news release indicates they are merging together various sales organizations and simplifying the business units into three:
  • Mitel Communications Solutions: responsible for delivering unified communications and collaboration products and services to businesses.
  • Mitel NetSolutions: responsible for network and hosted services, mobile services, and broadband connectivity.
  • Mitel DataNet: responsible for the distribution of third-party products to partners and customers.

It also briefly mentions the departure of Paul Butcher as of Saturday. From a product point-of-view, there were two statements I found interesting:

  • "a re-direction of our R&D investment to products serving the high-growth market of 100 to 2,500 user organizations." Which makes sense, given that this area is one in which Mitel has traditionally done well.

  • "we intend to exploit our significant market leadership in voice virtualization." i.e. continuing their partnership with VMware. Again this also makes sense given that people are looking for solutions to deploy more applications with less hardware... and looking at virtualization as one of the potential solutions.

To me, all of this is naturally to be expected after Mitel appointed Richard McBee the new CEO back in January 2011. A new CEO comes in and he'll listen for a few months... and then start making changes. Obviously this is his reshaping the organization in the way he thinks it should go.

In that vein, the departure of Paul Butcher is not surprising. Paul had been in the CxO part of Mitel since 2001, coming in at the time when Terry Matthews bought the company back and launched it on its current course. Over that time he was quite involved in many aspects of the company and worked quite a bit with the now-retired CEO Don Smith. With a re-org of this magnitude and with a new CEO wanting to reshape the organization, it's not surprising that some of the previous leadership would leave. I wish Paul well with whatever comes next.

I wish Mitel well, too. I haven't been writing about Mitel all that much lately, but that's more because my own interests are no longer as much with the IP-PBX space that Mitel plays in. If you look at my recent writing, it's mostly been about SIP, Skype, mobile devices... with a handful of IPv6, Voxeo and other topics thrown in. I haven't been really writing about any of the IP-PBX and Unified Communications vendors for a while.

Regardless, I wish them well... though I only recognized a couple of the names in the news release and much has changed since I left Mitel back in 2007, I still have good friends working there and Mitel still has outstanding technology. Their challenge has always been around getting that story out to the larger world. Perhaps these changes will help. We'll see.


If you found this post interesting or useful, please consider either: