Category Archives: Podcasts

Blue Box #55: IP phone security vulnerabilities, SIP fuzzing, Phil Zimmermann, ZRTP and IETF, Skype security, listener comments and a brief final commentary about visiting the pyramids in Egypt

Synopsis: IP phone security vulnerabilities, SIP fuzzing, Phil Zimmermann, ZRTP and IETF, Skype security, listener comments and a brief final commentary about visiting the pyramids in Egypt


Welcome to Blue Box: The VoIP Security Podcast #55, a 78-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 36MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box SE #17: Interview with Saverio Niccolini from NEC about efforts to combat SPIT

Synopsis: Interview with Saverio Niccolini from NEC about efforts to combat SPIT.


Welcome to Blue Box: The VoIP Security Podcast Special Edition #17, a 9-minute podcast of an interview by Martyn Davies of Saverio Niccolini from NEC about efforts to combat Spam-for-Internet-Telephony (SPIT). The interview took place at the 3GSM World Congress 2007 held February 12-15, 2007, in Barcelona, Spain.

Download the show here (MP3, 4MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:


Show Content:

At the 3GSM World Congress 2007, Blue Box contributor Martyn Davies had a chance to record an interview with Saverio Niccolini about NEC’s efforts to combat Spam for Internet Telephony (SPIT).  Specifically, they discussed NEC’s new program VOIPSEAL, the prototype of which was unveiled at the 3GSM conference. Saverio is a Senior Research Staff Member in the
Network Laboratories at NEC (www.netlab.nec.de)

Saverio has provided the following links for additional information about the VOIP SEAL solution:

We thank Martyn for contributing this interview and Saverio for his participation.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Security Round Table podcast on OpenID and Security

As I’ve mentioned on recent Blue Box episodes, I recently got together with two other members of the Security Round Table, Michael Santarcangelo and Martin McKeay, to explore the issues around OpenID and security.

We have shared the resulting conversation as a SRT podcast, and have also published as the show notes the large body of links that we accumulated during our preparation for the show.  I’d encourage you to check out the SRT site purely for the links alone, as I think we pulled together one of the more comprehensive lists of links I’ve seen related to OpenID.  If you are not familiar with OpenID, the links in the SRT show notes will help you understand more about it.  I’ve also written more about it over on my DisruptiveTelephony blog.

In the end, the three of us came aware quite impressed with the possibilities of OpenID with regard to the specific piece of the identity puzzle that it is aiming to solve.  We hope this podcast helps people understand both the potential benefits as well as a few potential challenges with regard to security and OpenID.  Comments and feedback are very definitely welcome.

Technorati tags: , , , ,

Blue Box #54: new VoIP security tools list, teleworker FUD, Phil Zimmermann, ETel feedback, SPIT, IETF, listener comments and more…

Synopsis: new VoIP security tools list, teleworker FUD, Phil Zimmermann, ETel conference feedback, SPIT, IETF, listener comments and more…


Welcome to Blue Box: The VoIP Security Podcast #54, a 57-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 27MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content: 

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box SE #16: ETel 2007 – The Black Bag Security Briefing with Dan York, Jonathan Zar and Shawn Merdinger

Synopsis: Emerging Telephony 2007 Workshop by Blue Box co-hosts Dan York and Jonathan Zar and security researcher Shawn Merdinger called the "Black Bag Security Briefing" covering VoIP security threats, tools and best practices.


Welcome to Blue Box: The VoIP Security Podcast Special Edition #16, a 91-minute podcast of a workshop presentation by Blue Box co-hosts Dan York and Jonathan Zar along with security researcher Shawn Merdinger called the "Black Bag Security Briefing" at O’Reilly’s Emerging Telephony Conference on February 27, 2007.

Download the show here (MP3, 43MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:


Show Content:

At O’Reilly’s 2007 Emerging Telephony conference last week in San Francisco, Jonathan, Shawn Merdinger and I presented a 90-minute workshop in which we discussed the threats to VoIP security, the tools out there to test/defend your network and the best practices for securing VoIP systems.  We had a great audience that also included folks like blogger/podcaster Ken Camp and IETF RAI Area Director Cullen Jennings. This is a recording of the full session including the Q&A.

Slides will be available soon.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #53: Skype multiple login issue, OpenID, Cisco IP phone vulnerabilities, net neutrality, drive-by pharming, EU privacy legislation and are smokers really a threat to VoIP security?

Synopsis: Skype multiple login issue, OpenID, Cisco IP phone vulnerabilities, net neutrality, drive-by pharming, EU legislation and are smokers really a threat to VoIP security?


Welcome to Blue Box: The VoIP Security Podcast #53, a 48-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 22MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content: 

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box SE #15: ETel 2007 Black Bag Security Review – Dan York tells a story about VoIP security

Synopsis: Emerging Telephony 2007 General Session by Blue Box co-host Dan York called the "Black Bag Security Review" where Dan tells a story about VoIP security.


Welcome to Blue Box: The VoIP Security Podcast Special Edition #15, a 22-minute podcast of a general session presentation by Blue Box co-host Dan York called the "Black Bag Security Review" at O’Reilly’s Emerging Telephony Conference 2007.

Download the show here (MP3, 10MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:


Show Content:

At O’Reilly’s 2007 Emerging Telephony conference last week in San Francisco, I (Dan) had the opportunity to give a 15-minute presentation to all attendees about VoIP security.  Rather than doing the traditional slideware outlining the threats, tools, best practices, etc., I tried to do something very different and simply tell a story of what could happen if a VoIP system were installed in an insecure manner – and how to go about securing that system.  I tried to make it interesting and humorous (something not often tied to VoIP security) and the feedback at the show was quite positive.  Given that this was the first time I had presented the topic in this manner, I would very definitely appreciate comments (positive or negative) either left here on this blog entry or sent or called in to the email address and numbers below.

Because the presentation was quite different in style from others that were given (and yes, it does come in at 243 slides in just about 15 minutes!), I received a number of questions and wound up writing a bit more about the presentation over on my Disruptive Telephony blog.  I included a bit about Lawrence Lessig and his impact on this presentation style.

I will include here an embedded view of the slides courtesy of SlideShare.net, although without being synced to the audio, they aren’t terribly useful given that I was moving through them fast.  At some point I will also include a PDF version of the slides as well.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #52: Skype spyware? Cisco SIP issue again, secure call recording, Phil Zimmermann on VON Magazine, US Congress and Caller ID, ringjacking, Skype security, VoIP security, listener comments and more

Synopsis: Skype spyware? Cisco SIP issue again, secure call recording, Phil Zimmermann on VON Magazine, US Congress and Caller ID, ringjacking, Skype security, VoIP security, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast #52, a 45-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions. 

NOTE: This show was originally recorded February 14, 2007. 

Download the show here (MP3, 21MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content: 

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #51: Cisco SIP vulnerabilities, VoIP security hype, SPIT, OpenID, other VoIP security news and more…

Synopsis: Cisco SIP security vulnerabilities, VoIP security hype, SPIT, OpenID, other VoIP security news and more… 


Welcome to Blue Box: The VoIP Security Podcast #51, a 35-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions. 

NOTE: This show was originally recorded February 7, 2007. 

Download the show here (MP3, 16MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content: 

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #50: Grand Central anti-SPIT initiative, Cisco and Ironport, Skype and business, VoIP security news and more

 

Synopsis: Grand Central’s anti-SPIT initiative, Cisco buys Ironport, Skype targets business, other VoIP security news, listener comments and more… 


 

Welcome to Blue Box: The VoIP Security Podcast #50, a 26-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions. 

NOTE: This show was originally recorded January 17, 2007. 

Download the show here (MP3, 12MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now: 


 

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.