Category Archives: VoIP Security

Blue Box Podcast #19 – VoIP security news, interview about VoIP over cable and much more

Synopsis: Interview with Geoff Devine from Cedar Point Communications about the security of VoIP over cable networks, VoIP security news and much more


Welcome to Blue Box: The VoIP Security Podcast show #19, a 63-minute podcast  from Dan York and Jonathan Zar around news and commentary in the world of VoIP security.  This show features a 36-minute interview with Geoff Devine from Cedar Point Communications about security of VoIP over cable networks.  As usual, the show also features news and comments from listeners.

Download the show here (MP3, 33MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast #18 – SPIT Tutorial, NAC vs NAP, VoIP security news, more

Synopsis: Tutorial on SPam over Internet Telephony (SPIT), discussion around Microsoft and Cisco’s competing network security proposals (NAC vs NAP), VoIP security news and much more


Welcome to Blue Box: The VoIP Security Podcast show #18, a 36-minute podcast  from Dan York and Jonathan Zar around news and commentary in the world of VoIP security.  This show features a mini-tutorial on SPam over Internet Telephony (SPIT) and includes a guest commentary from Rick Robinson. The show also includes a brief discussion of the different competing architectures put forward by Microsoft and Cisco for controlling access to the network.  The show also features the usual news and comments from listeners.

Download the show here (MP3, 33MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

  • 00:20 – Intro to the show, contact information and how to provide comments.  Welcome to all the new listeners.  Mention of Frappr map for the showPlease join the map!
  • 03:20 – A note about the dates we put at the beginning of shows
  • 04:10 – Burton Group/Cisco webinar  – recording available  (but you seem to have to have been already set up with Interwise’s software)
  • 05:07 – TMC.Net: Patton Electronics: New SmartNode VoIP More Secure
  • 05:31 –SANS/Nortel webcast on Wednesday about VoIP security  (someone from TippingPoint in there as well)
  • 06:08 – If you like this podcast, you may also like Steve Gibson’s "SecurityNow" podcasts, and in particular these:
  • 08:39 – Upcoming conferences – anyone interested in reporting from Berlin?  (Who will already be there)
  • 09:32 – Introduction into our tutorial on SPam for Internet Telephony, aka "SPIT".
  • 10:33 – Commentary on SPIT by Rick Robinson
  • 14:07 – Further discussion and examples of SPIT
  • 21:19 – Discussion on different competing architectures from Microsoft and Cisco related to network access, primarily building on this Network World article: Microsoft, Cisco, not in sync on security
  • 27:04 – Comments – Vash-media: security podcasts
  • 28:54 – Review of the last week’s traffic on the VOIPSEC public mailing list. Large amount of interesting traffic on topics including:
    • Using VoIP over SSL VPNs
    • tunnelling all traffic over IPSEC versus separately encrypting signalling and media
    • which vendors are really using SRTP in their phones
    • using softphones with TLS and OpenSER
  • 31:07 – Note that all Emerging Telephony shows have now been posted
  • 31:24 – Question for the audience: we have been approached about more formally tying the show to the VoIP Security Alliance (VOIPSA)? Is this a good thing?  bad thing? does anyone care?
  • 33:11 – Looking for some folks interested in coming on the show to debate whether or not you should firewall off IP-PBXs from the internal network – interested in joining the PRO or CON side of the debate?  Email us and let us know.
  • 34:45 – Wrap-up, info about how to leave comments, upcoming shows, etc.
  • 35:57 – End of show

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast #17 – Per Cederqvist ‘sdescriptions’ tutorial, VoIP security news, more

Synopsis: Interview/tutorial with Per Cederqvist about sdescriptions, VoIP security news and much more


Welcome to Blue Box: The VoIP Security Podcast show #17, a 41-minute podcast  from Dan York and Jonathan Zar around news and commentary in the world of VoIP security.  This show features an interview/tutorial with Per Cederqvist about the ‘sdescriptions’ method of SRTP key exchange. The show also includes a brief segment with folks from NetIQ as well as the usual news and comments from listeners.

Download the show here (MP3, 38MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

  • 00:20 – Intro to the show, contact information and how to provide comments.  Welcome to all the new listeners.  Mention of Frappr map for the showPlease join the map!
  • 01:59 – Unstrung: WiFi Voice: How safe? and Five WiFi VOIP Security Issues
  • 03:50 – Network World: Network security is the key to keeping VoIP secure  and again on 2/20?
  • 06:52 – IT Business Edge: A Multi-Layered Approach to VoIP Security  (Q&A with former guest Steve Mank of Qovia)
  • 07:09 – Discussion about the RSA Conference that Jonathan attended
  • 11:32 – Feature interview with Per Cederqvist of Ingate systems about the "sdescriptions" method of SRTP key exchange. He provided a great introduction to the protocol and explained both the positive and negative sides of using it.  The interview included:
    • Background on Ingate, his role, etc.
    • sdescriptions background, rationale
    • standards status, industry support
    • differences from MIKEY
    • importance of SSL/TLS
    • encryption used
    • reference implementations?
    • interoperability – contact Per at "ceder@ingate.com" if you are interested in interop testing
    • 21:40 end of interview
  • 22:00 – Comment section – Shawn Merdinger
  • 22:49 – audio comment from Martyn Davies
  • 25:49 – inquiry from a radio station about comment line software
  • 26:53 – Brief interview with Jeff Hicks and Randy Rosenbaum about their news release – NetIQ Unveils First Integrated Systems and Security Management Solution for VoIP (See also this Network World article)
  • 38:53 – Review of the last week’s traffic on the VOIPSEC public mailing list…. there was none!  Quiet week on the mailing list, but that is sure to change.
  • 39:27 – Final comments, wrap-up of show, upcoming conferences, how to give comments, etc.
  • 41:00 – End of show

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box ETel2006 Podcast #5 – Interview with Alec Saunders of Iotum

Synopsis: Interview with Alec Saunders, CEO and "Relevance Revolutionary" of Iotum about security and privacy as they relate to Iotum’s new relevance engine. The interview was recorded at O’Reilly’s Emerging Telephony Conference in January 2006.


Welcome a special edition of Blue Box: The VoIP Security Podcast from the floor of the Emerging Telephony Conference in San Francisco, CA. Every now and then startups emerge that are just doing things that I personally find interesting.  Iotum is one of those companies.  The main thing they are focused on is making communication more relevant to you… as they say on their home page:

iotum is the world’s first smart platform that lets you control who reaches you and how. Get the calls you want, where you want, and avoid those you don’t.

As I came to know more about the company, I was curious to know about how they handled securely gathering all the context information about you and how they preserved the privacy. So out at ETel 2006 I sat down with Iotum CEO Alec Saunders to talk about what Iotum is doing and issues around security and privacy.  In this interview, we covered those points and also ranged into a wide variety of other privacy-related issues such as GPS and cellphones in Japan, social issues around privacy and other points.  While it is a bit outside the realm of topics we normally cover, I hope you find it as interesting as I did.

If you would like to learn more about Iotum, Alec Saunders also maintains his own weblog where he writes on Iotum, VoIP and other topics. I’ll also note that Alec’s "mug shot" photo is not from any recent trip to jail but rather from a bit of fun the company had creating images for all the company members.  (Ahh, the things you can do as a startup…)

Download the show here (MP3, 18MB) or subscribe to the RSS feed to download the show automatically.  The interview runs about 20 minutes.

You may also listen to this podcast right now:

NOTE: This is the last of the interviews and shows coming out of ETel 2006.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.
Audio comments sent as attached MP3 files are definitely welcome and
will be played in future shows.  You may also call the listener comment
line at +1-206-338-6654 to leave a comment there.

Blue Box Podcast #16 – VoIP security news, interview with Information Security Forum, other news and comments

Synopsis: Interview with Nick Frost from the Information Security Forum about his recent VoIP security report, news of upcoming shows, VoIP security news and much more


Welcome to Blue Box: The VoIP Security Podcast show #16, a 69-minute podcast  from Dan York and Jonathan Zar around news and commentary in the world of VoIP security.  This show features a 23-minute interview with Nick Frost from the Information Security Forum about his recent VoIP report. The show also includes brief segments from Irwin Lazar on an upcoming webcast, Carl Ford about VON and the usual news and comments from listeners.

Download the show here (MP3, 65MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box ETel2006 Podcast #4 – Pingtel Interview

Synopsis: Interview with Scott Lawrence of Pingtel who is the project coordinator for the open source  sipX PBX and lead engineer for Pingtel’s commercial SIPxchange version of the open source PBX.  The interview was recorded at O’Reilly’s Emerging Telephony Conference in January 2006.


Welcome a special edition of Blue Box: The VoIP Security Podcast from the floor of the Emerging Telephony Conference in San Francisco, CA. In this interview with Scott Lawrence of Pingtel, the project coordinator for the open source  sipX PBX and lead engineer for Pingtel’s commercial SIPxchange version, we spoke a bit about Pingtel’s products, but mostly talked about SIP security mechanisms and the challenges around securing SIP along with his dire predictions about SPIT. We also discussed a couple of the other projects hosted at SIPFoundry.org.  It was an enjoyable and fascinating interview and we thank Scott for taking the time to speak with us.

Download the show here (MP3, 32MB) or subscribe to the RSS feed to download the show automatically.  The show runs about 35 minutes.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.
Audio comments sent as attached MP3 files are definitely welcome and
will be played in future shows.  You may also call the listener comment
line at +1-206-338-6654 to leave a comment there.

Blue Box ETel2006 Podcast #3 – Ranch Networks and Asterisk/Digium Interview

Synopsis: Interview with Alex Pavlovsky, President of RanchNetworks, and Mark Spencer, President of Digium and creator of Asterisk, at O’Reilly’s Emerging Telephony Conference on January 26, 2006


Welcome a special edition of Blue Box: The VoIP Security Podcast from the floor of the Emerging Telephony Conference in San Francisco, CA. In this interview with Alex Pavlovsky, President of RanchNetworks, and Mark Spencer, President of Digium and creator of Asterisk, we spoke about the RanchNetworks / Digium news release announcing a partnership between the two companies where code now included in Asterisk allows control of Ranch Networks’ firewall devices.  More links:

After discussing the announcement, the conversation continued into a discussion of the IAX protocol, the differences between it and SIP, advantages of IAX, firewall traversal, security issues and other matters.

We thank both Mark Spencer and Alex Pavlovsky for taking the time to speak with us.

Download the show here (MP3, 29MB) or subscribe to the RSS feed to download the show automatically.  The show runs about 32 minutes.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.
Audio comments sent as attached MP3 files are definitely welcome and
will be played in future shows.  You may also call the listener comment
line at +1-206-338-6654 to leave a comment there.

Blue Box Podcast #15 – Feb 3, 2006 – VoIP Security news, Avaya interview, Internet Telephony reports

Synopsis: Interview about Avaya teleworker solution, reports from Internet Telephony conference, VoIP security news and much more


Welcome to Blue Box: The VoIP Security Podcast show #15, a 61-minute podcast  from Dan York and Jonathan Zar around news and commentary in the world of VoIP security.  This show features a 20-minute interview with Rick Robinson and Jerry Ryan from Avaya about their new teleworker solution.  The show also includes reports from the recent Internet Telephony Conference and Exposition held in January in Florida.

Download the show here (MP3, 57MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast #14 – Jan 24, 2006 – VoIP Security news and comments from the Emerging Telephony Conference

Synopsis: VoIP security news, Cisco vulnerabilities, conference news comments, news, VOIPSEC review


Welcome to Blue Box: The VoIP Security Podcast show #14, a 27-minute podcast  from Dan York and Jonathan Zar around news and commentary in the world of VoIP security. This show was actually recorded at the San Francisco Airport Marriott where the O’Reilly Emerging Telephony conference was taking place. One interesting fact is that after working together for most of a year on VOIPSA-related activities this was the first time Dan and Jonathan had actually physically met.

Download the show here (MP3, 25MB) or subscribe to the RSS feed to download the show automatically.

(This show was, in fact, recorded on January 24th and is only now
being posted primarily due to travel and other deadlines. Our apologies
for the delay.)

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box ETel2006 Podcast #2: Brad Templeton of EFF on CALEA

Synopsis: Presentation by Brad Templeton, Chairman of the Electronic Frontier Foundation, at O’Reilly’s Emerging Telephony Conference on January 26, 2006


Welcome a special edition of Blue Box: The VoIP Security Podcast from the floor of the Emerging Telephony Conference in San Francisco, CA. In this presentation, Brad Templeton, Chairman of the Board of Directors of the Electronic Frontier Foundation (EFF), channels his "evil twin" and uses humor and sarcasm to attack the recent FCC ruling applying CALEA to VoIP Service Providers, hits the Universal Service Fund, announces a lawsuit and rips into wiretapping.  It was quite an entertaining and humorous – yet serious – session.

We thank Brad Templeton and the conference team at O’Reilly for giving us permission to make this recording available to you all.

Download the show here (MP3, 19MB) or subscribe to the RSS feed to download the show automatically.  The show runs about 21 minutes.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.
Audio comments sent as attached MP3 files are definitely welcome and
will be played in future shows.  You may also call the listener comment
line at +1-206-338-6654 to leave a comment there.