Category Archives: Podcasts

Blue Box #35: IMS Security, VoIP security news, listener comments and more

Synopsis: IMS security interview, VoIP security news, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #35, a 71-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show also includes a 25-minute interview with Miguel Garcia about IMS security.

NOTE – Due to production issues, this show is coming out after show 36 and about a month after it was originally recorded.  We do sincerely apologize for the delay!  Please note also that also that the audio comment line number is wrong in the recording.  As noted on the show website, the new number is +1-206-350-2583.

Download the show here (MP3, 65MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.

 Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #36: Black Hat super-sized edition – VoIP security news, interviews with David Endler, Mark Collier, Ofir Arkin and much, much more…

Synopsis: Black Hat 2006 super-sized edition – VoIP security news, interviews with David Endler, Mark Collier, Ofir Arkin and much, much more


Welcome to Blue Box: The VoIP Security Podcast show #36, a 83-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This is a special edition focusing on the 2006 Black Hat Briefing in Las Vegas and the voice security talks that were given at the conference.

NOTE:  As explained in the show, this podcast #36 is being released before show #35, which will be released next week.  You didn’t miss #35… it just hasn’t been released yet.

Download the show here (MP3, 77MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.


NOTE: As I will explain in more detail on our next show (#37), there were a number of issues with the audio in this show both in the recording as well as in the post-production.  One of the issues was some very annoying noise artifacts in the Endler/Collier interview that sound like cell phone interference.  There are also a couple of gaps… and those with finally attuned ears will hear some clipping of the audio.  Suffice it to say that I would not want our podcast to be judged by the audio quality of this episode!  I’ll explain more in our next episode about exactly why this episode didn’t hit our usual quality level.


Show Content:

(NOTE – More detailed show notes with links will be made available next week.  For right now, we just want to get the show posted.)

  • 00:20 – Intro to the show, contact information and how to provide comments.  Welcome to all the new listeners.
  • 08:10 – Interview with Dave Endler and Mark Collier about their Black Hat talk and the VoIP security tools they released this week. (News articles from ZDNet and the Register.)
  • 35:41 – Discussion of Hendrik Sholz’s new smap tool and his zero-day exploit against Cisco PIX firewalls
  • 39:46 – Discussion of Jay Schulman’s session on phishing with Asterisk
  • 45:29 – Discussion of Doug Mohney’s session on using voice analytics to defeat social engineering
  • 46:13 – Discussion of Nicolas Fischbach’s session on carrier VoIP security
  • 48:38 – Interview with Ofir Arkin about his session on NAC, Insightix, his role in VOIPSA, security research, etc.
  • 1:05:42 – Mention of Alan Schimmler and his Still Secure blog and NAC
  • 1:06:35 – Chat with Brenno de Winter about RFID (including this movie), his Dutch IT news podcast, and his podcast about learning Dutch that he started for his American girlfriend
  • 1:11:41 – Mention of session on Network Neutrality and Dan Kaminsky’s tools to help measure the neutrality of carriers
  • 1:12:30 – Dark Reading: Skype’s Fire(wall) Fight (quotes Shawn Merdinger and sent in by Craig Bowser)
  • 1:13:30 – Upcoming shows:
  • 1:15:03 – Comment (email) from Martyn Davies
  • 1:16:30 – Comment (email) from John Haluska
  • 1:17:48 – Comment (email) from David Belle-Isle
  • 1:19:17 – Comment (email) from Bobby Fentress
  • 1:19:48 – Comment (weblog) from Michael Boman
  • 1:20:37 – Comment (email) from Craig Bowser
  • 1:22:11 – Wrap-up of the show
  • 1:22:40 – End of show

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #34: IPv6 security, VoIP security news, more

Synopsis: IPv6 security, VoIP security news and more…


Welcome to Blue Box: The VoIP Security Podcast show #34, a 49-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show covers the usual VoIP security news and then includes a 27-minute interview with Yurie Rich and John Spence from Command Information about IPv6 security.

Download the show here (MP3, 45MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Telecom Junkies podcast on Pena/Moore VoIP fraud case

As we mentioned on recent shows, I (Dan) was a guest on a recent Telecom Junkies Podcast called “VoIP Fraud Sets Off New Alarms” where we discussed the Pena/Moore voip fraud case that we’ve been discussing on recent shows. Target audience was for “telecom managers” at large enterprises and is produced by the folks who create “The Telecom Manager’s Voice Report“.

The other guests on the show with me were Gary Meliefsky from NetClarity and consultant Ken Agress. Definitely a fun show to do and I appreciated the Voice Report folks having me on the show.

Blue Box #33 – VoIP Fraud case and CALEA revisited, VoIP security news, listener comments and more

Synopsis: VoIP fraud case and CALEA revisited, VoIP security news, listener comments and much, much more…


Welcome to Blue Box: The VoIP Security Podcast show #33, a 44-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show covers the usual VoIP security news, but then through some excellent listener comments gets back into a continued discussion of the Pena/Moore VoIP fraud case and also CALEA.

Download the show here (MP3, 40MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #32: ENUM Tutorial, VoIP security news, listener comments and more

Synopsis: ENUM tutorial, VoIP security news, listener comments and much, much more…


Welcome to Blue Box: The VoIP Security Podcast show #32, a 49-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show includes a 14-minute tutorial on ENUM – what it is and what implications it has for security – as well as the usual coverage of VoIP security news and comments from listeners

Download the show here (MP3, 45MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #31: VoIP Fraud case, CALEA tutorial/commentary, VoIP security news, comments and more

Synopsis: VoIP fraud case, CALEA tutorial/commentary, VoIP security news, listener comments and much, much more…


Welcome to Blue Box: The VoIP Security Podcast show #31, a 53-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show includes a 10-minute segment on the recent Pena/Moore VoIP fraud case and about a 15-minute discussion of the recent FCC decision about CALEA and what that means. There is of course the usual coverage of VoIP security news and comments from listeners

Download the show here (MP3, 61MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

NOTE: I would welcome any comments about the audio quality of this MP3 file as compared to our other shows would be appreciated – I am trying out a new audio encoder. Thanks.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #30: Voip security in mainstream media, Martyn Davies report on Third Annual VoIP Security Workshop in Berlin, much more…

Synopsis: VoIP security in the mainstream news, Martyn Davies’ report on the 3rd Annual VoIP Security Workshop in Berlin, listener comments and much, much more…


Welcome to Blue Box: The VoIP Security Podcast show #30, a 57-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show includes a 24-minute report from Martyn Davies on the 3rd Annual VoIP Security Workshop in Berlin.  Martyn’s report also includes interviews with workshop participants.

Download the show here (MP3, 65MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

NOTE: I would welcome any comments about the audio quality of this MP3 file as compared to our other shows would be appreciated – I am trying out a new audio encoder. Thanks.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast #29: VoIP security news, Skype security, VOIPSA blog, comments and more

Synopsis: VoIP security news for the week, Skype security issues, VOIPSA weblog, our listener survey, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #29, a 32-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. 

Download the show here (MP3, 37MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

NOTE: I would welcome any comments about the audio quality of this MP3 file as compared to our other shows would be appreciated – I am trying out a new audio encoder. Thanks.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast #28: David Endler Interview, VoIP security news, comments and more

Synopsis: Interview with VOIPSA Chair David Endler, VoIP security news for the week, our listener survey, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #28, a 62-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security.  This show includes a 14-minute interview with David Endler, Chair of the VoIP Security Alliance (VOIPSA).

Download the show here (MP3, 56MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

In this show we also mentioned the final week of our promotion – anyone submitting audio comments (either by email or calling the comment line) before the next show will be eligible for a drawing for a free copy of "Practical VoIP Security" from Syngress Press. Many thanks to Bruce Stewart and the folks at O’Reilly & Associates (who distribute Syngress books) for providing this book.
Five people have so far submitted audio comments, so your odds of winning are very good if you submit a comment before the end of the month!

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.