FYI, I was the guest on the recent Security Roundtable podcast #5 focused on VoIP security. I gave an overview of VoIP security issues, discussed some best practices and answered numerous questions from the group of hosts. It was a wide-ranging discussion that covered Skype, recent legislation, enterprise network issues and much more. It was a fun podcast to be part of and I do appreciate the SRT team inviting my participation. If you are new to VoIP security issues in general, do give it a listen.
Category Archives: VoIP Security
Blue Box #40: VoIP fraudster a fugitive, VoIP security news, business continuity, Namibians jailed for VoIP, and much more…
Synopsis:VoIP fraudster now a fugitive, Namibians jailed for VoIP, business continuity, Skype security and more.
Welcome to Blue Box: The VoIP Security Podcast #39, a 36-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.
Download the show here (MP3, 15MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Show Content:
- 00:20 – Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
- 02:30 – Notes about changes to show format
- 06:25 – Dan will be attending the Podcast and Portable Media Expo Sept 29th and 30th out in Ontario, CA.
- 06:39 – Dan will be part of an upcoming Security Roundtable podcast on VoIP.
- 07:23 – Accused VoIP Fraudster Sought As Fugitive (tip to Martyn Davies at Voice of VOIPSA ) also link from Craig Bowser on the same subject VoIP Thief on the Run
- 08:49 – VoIP changing business continuity (from Voice of VOIPSA)
- 11:55 – VoIPNews AU: Five arrested for selling VoIP (tip to Jan in Malaysia) Also Skype Journal: Sell VoIP, Go to jail
- 13:24 – CIO: Experts: VoIP Represents Serious Security Risk
- 14:23 – CSO (Australia): When Voice Becomes Data
- 15:49 – NetworkWorld: Users want systems for managing VoIP quality
- 17:29 – NetworkWorld: Interop Reporter’s Notebook: VoIP security still spotty and TMC.Net: At Interop, Network Infrastructure Still Taking Priority over VoIP
- 18:41 – OSNews: Review: FiWin SS28S WiFi VoIP SIP/Skype Phone
- 21:17 – ArsTechnica: More universities banning Skype, Jan in Malaysia: The world is flat, even if some block it, SkypeJournal: Proposed SJSU Ban of Skype: Update and Mind if my friends move in?
- 24:08 – CIO: Skype Preps Enterprise-Friendly VoIP Software
- 26:00 – PC Magazine: Alarm.com Signs VOIP Deal; Looks Next To ISPs – see also news release – uControl Launches New Home Security Service
- 27:15 – TMC.Net: Our 100th Issue of IP Communications Thought Leadership (Rich Tehrani)
- 28:18 – Telrex CallRex is the First VoIP Call Recording Solution Verified to Record Encrypted Cisco Unified CallManager 5.0 Calls
- 29:34 -Upcoming Shows:
- Oct 10-13, San Diego, CA, Internet Telephony Conference and Expo – West
- Oct 25-26, Rome, Italy, VON Italy
- Nov 6-9, Berlin, Germany, VON Europe Autumn
- Dec 4-6, Atlanta, GA, VON Enterprise
- Jan 23-26, 2007, Ft. Lauderdale, FL, Internet Telephony Conference and Expo – East
- Feb 27-Mar 1, 2007, San Francisco, Emerging Telephony 2007
- Mar 19-21, 2007, San Jose, CA, Spring 2007 VON
- 30:27 – Comment (audio) from unidentified listener about SIP comment line
- 31:57 – Comment (audio) from Dean Elwood
- 33:10 – Review of the last week’s traffic on the VOIPSEC public mailing list
- 34:08 – Wrap-up of the show
- Note that Telcom Junkies has now made archives available
- Reminder that you can subscribe to the show via email as well as RSS
- Mention of our Frappr map
- 35:50 – End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box #39: VoIP security news, VON conference update, 802.11 and PKI, listener comments, more
Synopsis:VoIP security news, comments and opinions – Skype security, fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF and more.
Welcome to Blue Box: The VoIP Security Podcast #39, a 42-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions. In this week’s show, we cover recent news, what happened at the VON show, 802.11 wireless security and more…
Download the show here (MP3, 17MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Show Content:
- 00:20 – Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
- 02:40 – SIP comment line at bluebox@voipuser.org and also in the UK +44 844 933 6305
- 03:44 – Upcoming interviews
- 04:40 – MRT: Senate passes 911 legislation in port security bill see also TelecomWeb: E911/VoIP Mandate Slips Into Port Security Bill
- 07:30 – Converge NetworkDigest: Are Hackers Eyeing your VoIP Network? (Newport Networks – who incidentally has a blog The Session Blog )
- 08:50 – Converge NetworkDigest: Protecting IPTV Infrastructure from Security Risks
- 12:14 – TMC.Net: Mitel to use BorderWare’s SIPassure VoIP Security Solution in its 3600 Security Gateway also Ottawa Business Journal: Mitel improves IP phone security
- 14:00 – VOIPSA Blog: Winds of change: ‘University dumps Cisco VoIP for open-source Asterisk’ (by Shawn Merdinger)
- 15:22 – VOIPSA Blog: Schwarzenegger’s (‘hot’) recording in context of VoIP archive servers (also by Shawn)
- 18:14 – KoolSpan, Kayote Networks Team To Deliver Carrier-Class, Continuous Security Authentication To VoIP Communications Services
- 18:46 – Covergence Delivers the CXC-50, Providing Complete VoIP Security and Reliability for Branch Offices and Small Businesses; Eclipse CXC-50 Provides ’’Big Business’’ VoIP at Small Business Prices
- 19:26 – Bell Labs Innovations Set New Standard in Carrier-Grade VPN/Firewall Functionality
- 20:07 – i2Telecom
Announces Trusted Computing Integration Plans; Relationship to Enable
Launch of VoIP Services Authenticated by a Security Chip and Wave
Software - 21:40 – Mitel’s Dan York Appointed to VOIPSA Board of Directors and discussion of upcoming VOIPSA "Best Practices" project
- 25:27 – Upcoming Shows:
- Oct 10-13, San Diego, CA, Internet Telephony Conference and Expo – West
- Oct 25-26, Rome, Italy, VON Italy
- Nov 6-9, Berlin, Germany, VON Europe Autumn
- Dec 4-6, Atlanta, GA, VON Enterprise
- Jan 23-26, 2007, Ft. Lauderdale, FL, Internet Telephony Conference and Expo – East
- Feb 27-Mar 1, 2007, San Francisco, Emerging Telephony 2007
- Mar 19-21, 2007, San Jose, CA, Spring 2007 VON
- 26:25 – Feature segment about VON conference
- ENUM is dead! Long live ENUM!
- FMC convergence and security
- IMS architecture and security
- 32:06 – Comment (email) from Perry Engle about 802.11 wireless and the use of PKI
- 37:44 – Comment (email) from Miguel Garcia
- 38:24 – Comment (audio) from Martyn Davies just testing SIP comment line
- 39:49 – Review of the last week’s traffic on the VOIPSEC public mailing list
- 40:33 – Wrap-up of the show
- Reminder that you can subscribe to the show via email as well as RSS
- Mention of our Frappr map
- 41:35 – End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box #38: VoIP security news, Skype security, fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF and more…
Synopsis:VoIP security news, comments and opinions – Skype security, fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF and more.
Welcome to Blue Box: The VoIP Security Podcast #38, a 49-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions. In this week’s show, we cover fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF, Skype and more…
Download the show here (MP3, 20MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
NOTE: This show was originally recorded on September 6th and was delayed due to some of the audio quality issues that you will note in the show itself.
Show Content:
- 00:20 – Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
- 01:18 – Jonathan’s conference in Asia and travel there
- 09:10 – Fall VON 2006 and Dan’s rant about PR
- 10:55 – Request for ideas about products to sell through CafePress
- 12:15 – Martyn Davies will be attending, Dec 5, London, UK, The 4th IET Secure Mobile Communication Forum
- 12:39 – Shoutout to Bret Padres and Ovie Carroll over at CyberSpeak
– an excellent podcast on computer forensics and security - 14:07 – Upcoming Shows:
- Oct 10-13, San Diego, CA, Internet Telephony Conference and Expo – West
- Oct 25-26, Rome, Italy, VON Italy
- Nov 6-9, Berlin, Germany, VON Europe Autumn
- Dec 4-6, Atlanta, GA, VON Enterprise
- Jan 23-26, 2007, Ft. Lauderdale, FL, Internet Telephony Conference and Expo – East
- Feb 27-Mar 1, 2007, San Francisco, Emerging Telephony 2007
- Mar 19-21, 2007, San Jose, CA, Spring 2007 VON
- 14:29 – Black Hat presentation available: VoIP Security Essentials (Jeff Waldron talk at Black Hat 2006)
- 14:41 – Register: Fugitive CEO tracked down to Sri Lanka after Skype call and Ars Technica: Fugitive exec nabbed after Skype call – also Bruce Shneier: Skype call traced – also points to this PDF – also blogged in Jan in Webtown
- 17:01 – Webtown – Jan in Malaysia: Market for blocking Skype is probably as big (if not bigger) to enable Skype – pointing to this news release Lynanda Finds a Way to Block Skype
- 19:17 – CRN: VoIP Systems Vulnerable To Attack
- 19:33 – TechWorld: Taking a SIP of secure mobile telephony
- 19:57 – ZDNet: E-mail security hero takes on VoIP also IPCommunications.com: Pretty Good Security for SIP Communications and Dark Reading: Zimmermann, Borderware Join (sent in by Craig Bowser)
- 20:40 – VoIP-Sol.com: 15 Apps for Recording Skype Conversations (found through Ken Camp)
- 22:44 -VoIPSA Blog: Paris Hilton, hacker extraordinaire? also Asterisk VoIP News
- 26:41 – Internet Draft on VoIP security threats
- 28:27 – Internet Draft on IPv6 security overview
- 28:48 – Rohan Pinto: Instant Voicemails points to pinger
- 30:15 – WhatPC? Network configuration systems pay off
- 30:53 – Sipera IPCS 310 Supports More VoIP Environments (also eChannelOnline )
- 31:11 – MobiKEY Ensures Secure Remote Access to Network Resources
- 31:20 –IBM to acquire Internet Security Systems
- 31:34 –All Broadvoice VoIP Customers have 911 Service and Over 85% of Vonage U.S. Subscriber Lines Now Have E911
- 31:40 –NetIQ VoIP Security Solution From Attachmate Named 2006 Readers’ Choice Award Winner by Windows IT Pro
- 32:10 – Shoutout from Brenno DeWinter
- 33:39 – Upcoming events:
- 35:20 – Comment (blog) from tonderai
- 36:09 – Comment (blog) from Kand Palanisamy
- 38:37 – Comment (blog) from Ellie drey
- 39:38 – Comment (email) from Julien Goodwin about SIP comments and offering an Asterisk config file to do the trick
- 41:13 – Comment (email) from Leslie Asamoa (SIP connections)
- 41:48 – Comment (email) from Leslie Asamoa (comments and recommendations)
- 45:12 – Review of the last week’s traffic on the VOIPSEC public mailing list
- 48:00 – Wrap-up of the show
- Reminder that you can subscribe to the show via email as well as RSS
- Mention of our Frappr map
- 49:19 – End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box SE #11: IMS Security interview with Morgan Stern
Synopsis:Interview about IP Multimedia Subsystem (IMS) security with Morgan Stern.
Welcome to Blue Box: The VoIP Security Podcast special edition #11, a 17-minute podcast from Dan York and Jonathan Zar containing an interview with Morgan Stern, Principal Consultant at Lucent Worldwide Services about the security of IMS systems.
Download the show here (MP3, 7MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
In this interview, I spoke with Morgan Stern, Principal Consultant, Global Convergence Center of Excellence, Lucent Worldwide Services, about the security of the IP Multimedia Subsystem (IMS) architecture. Morgan has just been part of a panel session at Fall VON 2006 in Boston entitled "Securing Communication for IMS" and we covered a range of security topics, including:
- The differences between centralized and distributed architectures
- The various standards bodies involved with IMS
- The emergence of "A-IMS"
- How do we do distributed security?
- How do we verify the authenticity of end devices?
- Is IMS hype or reality?
- Are there really new and innovative services coming out for IMS?
- What are the major security issues for IMS?
- Lawful intercept and its issues
- His role at Lucent and what his work there is about
Morgan also provided a copy of his IMS security presentation that you may download and also mentioned a Light Reading webinar he did on IMS in general that listeners may find of interest.
If you are interested in IMS security, you may also want to listen to Blue Box podcast #35, where we interviewed author Miguel Garcia for his perspective on IMS security.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box SE #10: Interview with Gary Miliefsky, Founder and CTO of Netclarity
Synopsis:Interview with Gary Miliefsky, Founder and CTO of Netclarity around how his products provide VoIP security and his views on VoIP security in general.
Welcome to Blue Box: The VoIP Security Podcast special edition #10, a 22-minute podcast from Dan York and Jonathan Zar containing an interview with Gary Miliefsky, Founder and CTO of Netclarity.
Download the show here (MP3, 8MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
In this interview, we spoke with Gary Miliefsky, CISSP, Founder and CTO of Netclarity, on a wide range of VoIP security topics, including:
- Netclarity and its products
- How did he/Netclarity get into VoIP security?
- Relationship of their products to firewalls
- VoIP CVEs and the National Vulnerability Database
- NIST recommendations
- His perspective on where VoIP security is going
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org’ to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box #37: Phil Zimmermann interview, VoIP security news, listener comments and more
Synopsis: Phil Zimmermann interview, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP Security Podcast show #37, a 60-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show also includes a 15-minute interview with Phil Zimmermann about the status of ZFone, ZRTP and more
Download the show here (MP3, 56MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.
Show Content:
- 00:20 – Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
- 02:00 – Why is Jonathan in Asia?
- 05:29 – Programming notes
- 08:06 – Upcoming interviews
- 08:34 – Cisco Security Response: SIP User Directory Information Disclosure (about Dave & Mark)
- 09:10 – Cisco PIX firewall issue, as reported in LightReading , SecurityProNews and TechWorld and SearchSecurity.com
- 10:54 – IEEE Security & Privacy Magazine: Voices, I hear voices by Ivan Arce (posted to VOIPSEC)
- 11:38 – InternetNews.com: Phishers Hit The Phone Bank With Asterisk
- 14:06 – Business Week: Security Threats Come A-Callin’
- 14:26 – Converge!: Skype Detection: Traffic Classification In the Dark
- 15:04 – The Age (Australia): WiFi Skype phones to set you free (not security, per se, but combining Skype with WiFi… two of our favorite topics) Also mentioned the DualPhone.
- 17:07 – TMC.Net: Skype Certifies McAfee Internet Security Suite 2006 (also ZDNet and Skype/McAfee press release )
- 18:01 – VON Magazine: Zimmermann: Borderware Licenses Zfone Technology (you’ll hear about this in the interview)
- 20:03 – IPCommunications.com: Balancing Security with Performance at the VoIP Application Layer
- 20:34 – PRWeb: VoIP Call Monitoring Solution Provider Sets New Standard in Call Recording Security
- 21:34 – SonicWALL Internet Security Appliances Now Rated ‘Avaya Compliant’
- 21:56 – Persay
First to Deploy FreeSpeech™ Biometric Speaker Verification in VoIP
Contact Center; Provides Seamless, Second Factor Authentication and
Enhanced Risk Management for Phone Banking - 23:26 – Upcoming shows:
- Sept 11-14, Boston, MA, Fall VON 2006
- Sept 18-22, New York, Interop
- Oct 10-13, San Diego, CA, Internet Telephony Conference and Expo – West
- Oct 25-26, Rome, Italy, VON Italy
- Nov 6-9, Berlin, Germany, VON Europe Autumn
- Dec 4-6, Atlanta, GA, VON Enterprise
- Jan 23-26, 2007, Ft. Lauderdale, FL, Internet Telephony Conference and Expo – East
- Feb 27-Mar 1, 2007, San Francisco, “Emerging Telephony”
- Mar 19-21, 2007, San Jose, CA, Spring 2007 VON
- 25:44 – Feature interview with Phil Zimmermann
- Zfone update
- Borderware and what ZRTP inclusion means
- business model
- call recording – how can it work with ZRTP?
- status of release plans
- what’s next
- 40:08 – Comment (email) from Jeffrey Oxe
- 40:39 – Comment (email) from Craig Bowser
- 47:50 – Comment (audio) from Bobby Fentress
- 48:33 – Comment (email) from Crittenden IV
- 49:30 – Comment (blog) from Tom Poe asking about a SIP comment line
- 51:44 – Review of the last week’s traffic on the VOIPSEC public mailing list
- 55:57 – Wrap-up of the show
- Reminder that you can subscribe to the show via email as well as RSS
- Mention of our Frappr map
- 59:57 – End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box #35: IMS Security, VoIP security news, listener comments and more
Synopsis: IMS security interview, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP Security Podcast show #35, a 71-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show also includes a 25-minute interview with Miguel Garcia about IMS security.
NOTE – Due to production issues, this show is coming out after show 36 and about a month after it was originally recorded. We do sincerely apologize for the delay! Please note also that also that the audio comment line number is wrong in the recording. As noted on the show website, the new number is +1-206-350-2583.
Download the show here (MP3, 65MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.
Show Content:
- 00:20 – Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
- 01:45 – Programming notes – Black Hat, Fall VON
- 02:53 – Discussion about IETF 66 meeting
- 06:28 – Cisco Security Advisory: Multiple Cisco Unified CallManager Vulnerabilities (interesting especially because of the SIP URL buffer overflow)
- 10:17 – SipFoundry sipXtapi vulnerability
- 11:05 –VOIPSA Blog: Skype protocol cracked? pointing to: VuNet , NetworkWorld , TechWorld , SecurityProNews but no mention in Skype security blog – also Skype Journal and TechCrunch and GigaOM and Webtown – Jan in Malaysia
- 18:42 – VoIPWiki blog (Charlie Paglee): Supernoded!
- 20:35 – Dan’s blog: Skype on a USB stick… – and Ken Camp’s response
- 24:26 – PBS – I,cringely: The Skype is Falling: Even Viral Networks have to Function in a Real World (tip of the hat to Jan in Malaysia – If all 6.1 million Skype users tried to talk at the same time, it would probably bring down the system.)
- 27:07 – Skype Podcast episode on security
- 27:50 – VOIPSA Blog: FBI Drafting CALEA Expansion Legislation
- 30:56 – Senator Ted Stevens and Net Neutrality – Jeff Pulver Blog: A Cataract-Eyed Vision of an Internet-disabled Future and Bruce Stewart at Emerging Telephony: The Internet as Tubes? (audio can be heard here )
- 32:42 – Business Week: The Phone is the latest Phishing Rod, VoIPNews: VoIP Phishing Scams – Don’t Get Hooked! (and VoIPSA Blog ), VoIP Lowdown: Your next VoIP call may just ‘vish’ you doom
- 33:58 – Business Week CEO Guide to Technology
- 34:50 – TechWorld UK: The security pitfalls of VoIP
- 35:16 -ComputerWorld: Hunting for Hussein’s fibre-optic cable in Iraq
- 36:28 – News releases: CheckPoint VPN-1
- 36:35 – Security Researchers to Demonstrate 25 New Tools and 15 New Exploits at Black Hat USA and Over 1000 Government Agents and Corporate Security Professionals to Attend Black Hat
- 37:02 – Call for papers for PacSec – November 29, 30 in Tokyo
- 37:15 – Upcoming shows:
- August 8-10, Santa Clara, CA, 3rd Annual VoIP Developer Conference
- August 21-24, San Francisco, VoiceCon Fall 2006
- (new) – Show in Asia that Jonathan will be attending – details coming soon
- Sept 11-14, Boston, MA, Fall VON 2006
- Sept 18-22, New York, Interop
- Oct 10-13, San Diego, CA, Internet Telephony Conference and Expo – West
- Oct 25-26, Rome, Italy, VON Italy
- Nov 6-9, Berlin, Germany, VON Europe Autumn
- Nov 29-30, Tokyo, Japan, PacSec
- Dec 4-6, Atlanta, GA, VON Enterprise
- 37:55 – Feature interview with Miguel Garcia about security in the IP Multimedia Subsystem (IMS) framework
- Miguel’s background
- His book on IMS
- Basic security concepts in IMS
- Authentication
- Integrity protection
- Encrypting RTP
- Convergence of voice and data
- What’s next for security within IMS?
- References: Wikipedia, SIP Center, 3GPP Specifications
- 1:05:24 – Comment (email) from Morgan Stern
- 1:06:01 – Comment (email) from Derk van der Harst
- 1:06:35 – Comment (Dan’s blog): Martyn Davies on audio quality
- 1:08:52 – Review of VOIPSEC mailing list
- 1:09:30 – Wrap-up of the show
- Mention of our Frappr map
- Mention of the conference in Asia where Jonathan will be speaking
- Mention of our Frappr map
- 1:11:11 – End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box #36: Black Hat super-sized edition – VoIP security news, interviews with David Endler, Mark Collier, Ofir Arkin and much, much more…
Synopsis: Black Hat 2006 super-sized edition – VoIP security news, interviews with David Endler, Mark Collier, Ofir Arkin and much, much more
Welcome to Blue Box: The VoIP Security Podcast show #36, a 83-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This is a special edition focusing on the 2006 Black Hat Briefing in Las Vegas and the voice security talks that were given at the conference.
NOTE: As explained in the show, this podcast #36 is being released before show #35, which will be released next week. You didn’t miss #35… it just hasn’t been released yet.
Download the show here (MP3, 77MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.
NOTE: As I will explain in more detail on our next show (#37), there were a number of issues with the audio in this show both in the recording as well as in the post-production. One of the issues was some very annoying noise artifacts in the Endler/Collier interview that sound like cell phone interference. There are also a couple of gaps… and those with finally attuned ears will hear some clipping of the audio. Suffice it to say that I would not want our podcast to be judged by the audio quality of this episode! I’ll explain more in our next episode about exactly why this episode didn’t hit our usual quality level.
Show Content:
(NOTE – More detailed show notes with links will be made available next week. For right now, we just want to get the show posted.)
- 00:20 – Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
- 08:10 – Interview with Dave Endler and Mark Collier about their Black Hat talk and the VoIP security tools they released this week. (News articles from ZDNet and the Register.)
- 35:41 – Discussion of Hendrik Sholz’s new smap tool and his zero-day exploit against Cisco PIX firewalls
- 39:46 – Discussion of Jay Schulman’s session on phishing with Asterisk
- 45:29 – Discussion of Doug Mohney’s session on using voice analytics to defeat social engineering
- 46:13 – Discussion of Nicolas Fischbach’s session on carrier VoIP security
- 48:38 – Interview with Ofir Arkin about his session on NAC, Insightix, his role in VOIPSA, security research, etc.
- 1:05:42 – Mention of Alan Schimmler and his Still Secure blog and NAC
- 1:06:35 – Chat with Brenno de Winter about RFID (including this movie), his Dutch IT news podcast, and his podcast about learning Dutch that he started for his American girlfriend
- 1:11:41 – Mention of session on Network Neutrality and Dan Kaminsky’s tools to help measure the neutrality of carriers
- 1:12:30 – Dark Reading: Skype’s Fire(wall) Fight (quotes Shawn Merdinger and sent in by Craig Bowser)
- 1:13:30 – Upcoming shows:
- August 8-10, Santa Clara, CA, 3rd Annual VoIP Developer Conference
- August 21-24, San Francisco, VoiceCon Fall 2006
- (new) – Show in Asia that Jonathan will be attending – details coming soon
- Sept 11-14, Boston, MA, Fall VON 2006
- Sept 18-22, New York, Interop
- Oct 10-13, San Diego, CA, Internet Telephony Conference and Expo – West
- Oct 25-26, Rome, Italy, VON Italy
- Nov 6-9, Berlin, Germany, VON Europe Autumn
- Dec 4-6, Atlanta, GA, VON Enterprise
- 1:15:03 – Comment (email) from Martyn Davies
- 1:16:30 – Comment (email) from John Haluska
- 1:17:48 – Comment (email) from David Belle-Isle
- 1:19:17 – Comment (email) from Bobby Fentress
- 1:19:48 – Comment (weblog) from Michael Boman
- 1:20:37 – Comment (email) from Craig Bowser
- 1:22:11 – Wrap-up of the show
- 1:22:40 – End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Blue Box #34: IPv6 security, VoIP security news, more
Synopsis: IPv6 security, VoIP security news and more…
Welcome to Blue Box: The VoIP Security Podcast show #34, a 49-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show covers the usual VoIP security news and then includes a 27-minute interview with Yurie Rich and John Spence from Command Information about IPv6 security.
Download the show here (MP3, 45MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Show Content:
- 00:20 – Intro to the show, contact information and how to provide comments. Welcome to all the new listeners. Mention of our listener survey
- 01:32 – Mention of IETF meeting and the audio streaming and the actual IETF agenda (also, if you have no understanding of how the IETF works, you may want to read The Tao of IETF )
- 02:20 – Mention of Podcast Awards – NOTE: Nominations closed on July 15th.
- 02:51 – Dan will be at Fall VON in Boston and Internet Telephony in San Diego – we’ll plan dinners there.
- 03:09 – Dan will be on a panel of VoIP bloggers at Fall VON in Boston (listeners may not know of his blog at blog.danyork.com )
- 04:01 – Still looking for anyone with WordPress expertise for suggestions about fighting blog spam over at Voice of VOIPSA.
- 04:22 – CIO India: VOIP Security Services Taking Hold
- 05:30 – VOIPSEC: Call for Papers/Invitation to 2nd ETSI Security Workshop
- 06:18 – BBC: Taipei to embrace net telephones
- 07:19 – MARA Top 10 Wireless and Mobile security vulnerabilities
- 08:54 –Top 100 Network Security Tools
- 11:13 Vonage V-Phone: Robin Good: Portable VoIP USB Key Makes Low-Cost Calls From Any PC You Connect It To: Vonage V-Phone and Tom Keating: Vonage V-Phone Review
- 13:43 – Security Watch: VoIP disrupts Aussie national security efforts points to ComputerWorld Australia article of same title
- 14:37 – Information Week: In Depth: Five Things You Must Know About VoIP : VoIP security is dodgy= (tip of the hat to Ken Camp’s blog )
- 16:12 – Upcoming shows:
- July 19-21, Tokyo, Japan, VON Japan
- August 2-3, Las Vegas, Black Hat 2006
- August 8-10, Santa Clara, CA, 3rd Annual VoIP Developer Conference
- (new) August 21-24, San Francisco, VoiceCon Fall 2006
- Sept 11-14, Boston, MA, Fall VON 2006
- (new) Sept 18-22, New York, Interop
- Oct 10-13, San Diego, CA, Internet Telephony Conference and Expo – West
- Oct 25-26, Rome, Italy, VON Italy
- Nov 6-9, Berlin, Germany, VON Europe Autumn
- Dec 4-6, Atlanta, GA, VON Enterprise
- 17:20 – Feature interview with Yurie Rich and John Spence (bios at bottom of this page) from Command Information about IPv6 security. Topics discussed include:
- Introductions, background
- What is the difference with IPv6? Why the interest now?
- Microsoft and what is going on with IPv6 and MS products
- US government/Department of Defense IPv6 mandates
- Is IPv6 actually more secure?
- Security issues within IPv6
- What happened to all the broadcasts?
- Implications of multicasting on network architecture
- Allocations of IPv6 address blocks
- When will we see IPv6? What is the business case?
- IPv6 in Asia
- Final thoughts
- 45:37 – Comment section – but for a complete change, there are no comments!
- 46:28 – Review of the last week’s traffic on the VOIPSEC public mailing list
- 47:11 – Wrap-up of the show
- Mention of our Frappr map
- 48:40 – End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to blueboxpodcast@gmail.com. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.