| Author |
Message |
GardRailz
Full Forum Member


Joined: Jan 30, 2005
Posts: 73
Location: WV
|
Is there any reason why Vonage cant switch to the SRTP protocol instead of using the RTP protocol it uses now?
My company was about ready to switch to Vonage, until they found out that any network engineer on the internet backbone (or upstream of them) can fire up a sniffer and listen in on any phonecall placed.
SRTP will fix that. or atleast make it more difficult to decode. |
|
|
|
|
 |
reebok
Vonage Forum MVM


Joined: Oct 24, 2004
Posts: 3198
Location: Lakeland, FL
|
|
|
|
 |
GardRailz
Full Forum Member


Joined: Jan 30, 2005
Posts: 73
Location: WV
|
Indeed. Unfortunatly it doesn't go into great detail about the security vulnerabilities.
Lets paint a picture of the situation. You're plugged into your cable modem on Adelphia's network. A bored network engineer connects to a monitoring port on a switch, or ethernet tap and fires up a free sniffer called ethereal. In ethereal, one simply selects they want to capture everything, then later filter on 'CIP' and 'RTP'. based on the packets obtained, that individual can determine the source and destination phone numbers of the conversation, as well as decode the conversation which took place.
That doesn't sound too bad, I mean, people have been able to do that for years with cordless phones and scanners. The thing with cordless phone security is, you can always pick up a land line and tell a customer service individual your credit card information. With voice over ip, it's sent across the wire in the clear, meaning in a matter of 3 or 4 seconds, someone can decode your entire conversation and have your credit card information.
A savy crook could infact copy a conversation of an individual giving their credit card information over the phone, and keep it saved in .wav format. Then play it back whenever that individual wants to buy something over the phone.... I mean, it would be your voice providing the information... how could it be disputed in court?
Shall I go into identity theft? you're on the phone with your healthcare provider, and you have to give them your phone number, address, name... birth day, and possibly even your SSN.... that's everything someone needs to do ANYTHING as you...
Lets secure the network, especially if you have representatives stating that the Vonage system is secure.... |
|
|
|
|
 |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum |
All times are GMT - 5 Hours | |