Category Archives: VoIP Security

Security Roundtable podcast on VoIP security

FYI, I was the guest on the recent Security Roundtable podcast #5 focused on VoIP security.  I gave an overview of VoIP security issues, discussed some best practices and answered numerous questions from the group of hosts.  It was a wide-ranging discussion that covered Skype, recent legislation, enterprise network issues and much more.  It was a fun podcast to be part of and I do appreciate the SRT team inviting my participation.  If you are new to VoIP security issues in general, do give it a listen.

Blue Box #40: VoIP fraudster a fugitive, VoIP security news, business continuity, Namibians jailed for VoIP, and much more…

Synopsis:VoIP fraudster now a fugitive, Namibians jailed for VoIP, business continuity, Skype security and more.


Welcome to Blue Box: The VoIP Security Podcast #39, a 36-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.

Download the show here (MP3, 15MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:


 Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #39: VoIP security news, VON conference update, 802.11 and PKI, listener comments, more

Synopsis:VoIP security news, comments and opinions – Skype security, fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF and more.


Welcome to Blue Box: The VoIP Security Podcast #39, a 42-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions. In this week’s show, we cover recent news, what happened at the VON show, 802.11 wireless security and more…

Download the show here (MP3, 17MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:


 Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #38: VoIP security news, Skype security, fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF and more…

Synopsis:VoIP security news, comments and opinions – Skype security, fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF and more.


Welcome to Blue Box: The VoIP Security Podcast #38, a 49-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions. In this week’s show, we cover fugitive CEOs, Phil Zimmermann, Paris Hilton, the IETF, Skype and more…

Download the show here (MP3, 20MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:


NOTE: This show was originally recorded on September 6th and was delayed due to some of the audio quality issues that you will note in the show itself.

 Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box SE #11: IMS Security interview with Morgan Stern

Synopsis:Interview about IP Multimedia Subsystem (IMS) security with Morgan Stern.


Welcome to Blue Box: The VoIP Security Podcast special edition #11, a 17-minute podcast  from Dan York and Jonathan Zar containing an interview with Morgan Stern, Principal Consultant at Lucent Worldwide Services about the security of IMS systems.

Download the show here (MP3, 7MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

In this interview, I spoke with Morgan Stern, Principal Consultant, Global Convergence Center of Excellence, Lucent Worldwide Services, about the security of the IP Multimedia Subsystem (IMS) architecture.  Morgan has just been part of a panel session at Fall VON 2006 in Boston entitled "Securing Communication for IMS" and we covered a range of security topics, including:

  • The differences between centralized and distributed architectures
  • The various standards bodies involved with IMS
  • The emergence of "A-IMS"
  • How do we do distributed security?
  • How do we verify the authenticity of end devices?
  • Is IMS hype or reality?
  • Are there really new and innovative services coming out for IMS?
  • What are the major security issues for IMS?
  • Lawful intercept and its issues
  • His role at Lucent and what his work there is about

Morgan also provided a copy of his IMS security presentation that you may download and also mentioned a Light Reading webinar he did on IMS in general that listeners may find of interest.

If you are interested in IMS security, you may also want to listen to Blue Box podcast #35, where we interviewed author Miguel Garcia for his perspective on IMS security.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box SE #10: Interview with Gary Miliefsky, Founder and CTO of Netclarity

Synopsis:Interview with Gary Miliefsky, Founder and CTO of Netclarity around how his products provide VoIP security and his views on VoIP security in general.


Welcome to Blue Box: The VoIP Security Podcast special edition #10, a 22-minute podcast  from Dan York and Jonathan Zar containing an interview with Gary Miliefsky, Founder and CTO of Netclarity.

Download the show here (MP3, 8MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

In this interview, we spoke with Gary Miliefsky, CISSP, Founder and CTO of Netclarity, on a wide range of VoIP security topics, including:

  • Netclarity and its products
  • How did he/Netclarity get into VoIP security?
  • Relationship of their products to firewalls
  • VoIP CVEs and the National Vulnerability Database
  • NIST recommendations
  • His perspective on where VoIP security is going

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org’ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #37: Phil Zimmermann interview, VoIP security news, listener comments and more

Synopsis: Phil Zimmermann interview, VoIP security news, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #37, a 60-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show also includes a 15-minute interview with Phil Zimmermann about the status of ZFone, ZRTP and more

Download the show here (MP3, 56MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.

 Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #35: IMS Security, VoIP security news, listener comments and more

Synopsis: IMS security interview, VoIP security news, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #35, a 71-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show also includes a 25-minute interview with Miguel Garcia about IMS security.

NOTE – Due to production issues, this show is coming out after show 36 and about a month after it was originally recorded.  We do sincerely apologize for the delay!  Please note also that also that the audio comment line number is wrong in the recording.  As noted on the show website, the new number is +1-206-350-2583.

Download the show here (MP3, 65MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.

 Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #36: Black Hat super-sized edition – VoIP security news, interviews with David Endler, Mark Collier, Ofir Arkin and much, much more…

Synopsis: Black Hat 2006 super-sized edition – VoIP security news, interviews with David Endler, Mark Collier, Ofir Arkin and much, much more


Welcome to Blue Box: The VoIP Security Podcast show #36, a 83-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This is a special edition focusing on the 2006 Black Hat Briefing in Las Vegas and the voice security talks that were given at the conference.

NOTE:  As explained in the show, this podcast #36 is being released before show #35, which will be released next week.  You didn’t miss #35… it just hasn’t been released yet.

Download the show here (MP3, 77MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 (new comment phone number!) to leave a comment there.


NOTE: As I will explain in more detail on our next show (#37), there were a number of issues with the audio in this show both in the recording as well as in the post-production.  One of the issues was some very annoying noise artifacts in the Endler/Collier interview that sound like cell phone interference.  There are also a couple of gaps… and those with finally attuned ears will hear some clipping of the audio.  Suffice it to say that I would not want our podcast to be judged by the audio quality of this episode!  I’ll explain more in our next episode about exactly why this episode didn’t hit our usual quality level.


Show Content:

(NOTE – More detailed show notes with links will be made available next week.  For right now, we just want to get the show posted.)

  • 00:20 – Intro to the show, contact information and how to provide comments.  Welcome to all the new listeners.
  • 08:10 – Interview with Dave Endler and Mark Collier about their Black Hat talk and the VoIP security tools they released this week. (News articles from ZDNet and the Register.)
  • 35:41 – Discussion of Hendrik Sholz’s new smap tool and his zero-day exploit against Cisco PIX firewalls
  • 39:46 – Discussion of Jay Schulman’s session on phishing with Asterisk
  • 45:29 – Discussion of Doug Mohney’s session on using voice analytics to defeat social engineering
  • 46:13 – Discussion of Nicolas Fischbach’s session on carrier VoIP security
  • 48:38 – Interview with Ofir Arkin about his session on NAC, Insightix, his role in VOIPSA, security research, etc.
  • 1:05:42 – Mention of Alan Schimmler and his Still Secure blog and NAC
  • 1:06:35 – Chat with Brenno de Winter about RFID (including this movie), his Dutch IT news podcast, and his podcast about learning Dutch that he started for his American girlfriend
  • 1:11:41 – Mention of session on Network Neutrality and Dan Kaminsky’s tools to help measure the neutrality of carriers
  • 1:12:30 – Dark Reading: Skype’s Fire(wall) Fight (quotes Shawn Merdinger and sent in by Craig Bowser)
  • 1:13:30 – Upcoming shows:
  • 1:15:03 – Comment (email) from Martyn Davies
  • 1:16:30 – Comment (email) from John Haluska
  • 1:17:48 – Comment (email) from David Belle-Isle
  • 1:19:17 – Comment (email) from Bobby Fentress
  • 1:19:48 – Comment (weblog) from Michael Boman
  • 1:20:37 – Comment (email) from Craig Bowser
  • 1:22:11 – Wrap-up of the show
  • 1:22:40 – End of show

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-350-2583 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box #34: IPv6 security, VoIP security news, more

Synopsis: IPv6 security, VoIP security news and more…


Welcome to Blue Box: The VoIP Security Podcast show #34, a 49-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show covers the usual VoIP security news and then includes a 27-minute interview with Yurie Rich and John Spence from Command Information about IPv6 security.

Download the show here (MP3, 45MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.