Blue Box Podcast #29: VoIP security news, Skype security, VOIPSA blog, comments and more

Synopsis: VoIP security news for the week, Skype security issues, VOIPSA weblog, our listener survey, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #29, a 32-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. 

Download the show here (MP3, 37MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

NOTE: I would welcome any comments about the audio quality of this MP3 file as compared to our other shows would be appreciated – I am trying out a new audio encoder. Thanks.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

FYI – Comments are now NOT moderated

As TypePad (where this site is hosted) has recently implemented a CAPTCHA system to prevent automated comment spam, I am now turning OFF comment moderation.  Assuming you type in the correct text shown in the CAPTCHA graphic, your comment will be posted as soon as you submit it.

So please feel free to comment away!

NOTE: If you are sending a Trackback ping from another weblog, I unfortunately have to keep those moderated (due to trackback spam!) as there is as yet no easy way to do some type of CAPTCHA for Trackbacks.

Blue Box Podcast #28: David Endler Interview, VoIP security news, comments and more

Synopsis: Interview with VOIPSA Chair David Endler, VoIP security news for the week, our listener survey, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #28, a 62-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security.  This show includes a 14-minute interview with David Endler, Chair of the VoIP Security Alliance (VOIPSA).

Download the show here (MP3, 56MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

In this show we also mentioned the final week of our promotion – anyone submitting audio comments (either by email or calling the comment line) before the next show will be eligible for a drawing for a free copy of "Practical VoIP Security" from Syngress Press. Many thanks to Bruce Stewart and the folks at O’Reilly & Associates (who distribute Syngress books) for providing this book.
Five people have so far submitted audio comments, so your odds of winning are very good if you submit a comment before the end of the month!

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast #27: Eavesdropping tutorial, VoIP security news, comments and more

Synopsis: Eavesdropping tutorial, VoIP security news for the week, our listener survey, US DoD conference report, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #26, a 51-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security.  This show includes a 19-minute tutorial on eavesdropping issues, discussion of our our listener survey and a brief report about Dan’s visit to the US Dept of Defense Telecommunications Services Interoperability Conference last week in Arizona.

Download the show here (MP3, 43MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

In this show we also mentioned our new promotion – anyone submitting audio comments (either by email or calling the comment line) before the end of May will be eligible for a drawing for a free copy of "Practical VoIP Security" from Syngress Press. Many thanks to Bruce Stewart and the folks at O’Reilly & Associates (who distribute Syngress books) for providing this book.
Three people have so far submitted audio comments, so your odds of winning are very good if you submit a comment before the end of the month!

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Topics for future podcasts? (VOIPSA survey provides some ideas)

Recently VOIPSA surveyed the members of its Technical Advisory Board and one of the questions asked was what topics TAB members would like to hear about in a future podcast.  The list of responses is below.  Are there any that you would specifically be interested in?  If so, please do leave a comment to this blog entry or send us an email.  Thanks.

  • IMS/3GPP
    security model
  • IMS convergence, UMA phones
  • How to 0wn a VOIP call manager, and how to defend against such
    0wnage.
  • VoIP IDS
  • Softphone vunerabilities
  • Wireless voip security
  • A  roadmap of issues, i.e. how & when the VoIPsa believes
    the issues will happen
  • Best Practices and testing
  • Service provider/carrier opinions, implementation discussions, etc…
  • VoIP over MPLS networks
  • VoIP threats and countermeasures
  • I like the sessions that take a specific VoIP Security topic
    and try to educate the listeners on that topic.
  • Real World VoIP Threats
  •  VoIP Security Best Practices
  •  PacketCable Security
  • More related to peer to peer voice, and its growth, and what
    impediments need to be addressed.
  • Privacy and security

(Note that this was a completely separate survey from the ongoing Blue Box listener survey.  Folks have been suggesting ideas there, too, and we’ll discuss that in an upcoming show.)

Blue Box Podcast #26: VoIP security news, comments and opinions

Synopsis: VoIP security news for the week, our listener survey, many listener comments and more


Welcome to Blue Box: The VoIP Security Podcast show #26, a 41-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security.  This show also introduces our listener survey.

Download the show here (MP3, 38MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

In this show we also mentioned our new promotion – anyone submitting audio comments (either by email or calling the comment line) during April or May will be eligible for a drawing for a free copy of "Practical VoIP Security" from Syngress Press. Many thanks to Bruce Stewart and the folks at O’Reilly & Associates (who distribute Syngress books) for providing this book.

Show Content:

  • 00:20 – Intro to the show, contact information and how to provide comments.  Welcome to all the new listeners.  Mention of our listener survey – PLEASE TAKE A MOMENT TO COMPLETE THE SURVEY!  (Thank you!)
  • Show notes will be posted tomorrow.
  • 41:25 – End of show

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast SE009: VoIP Security Presentation to IP Telephony for Government Conference – April 18, 2006

Synopsis: Special edition with a presentation on VoIP Security given by Dan York at the IP Telephony for Government conference on April 18, 2006, in Arlington, VA.


Welcome to a special edition of Blue Box: The VoIP Security Podcast where we present a recording of a presentation that Dan York gave on April 18, 2006, in Arlington, Virginia, at the IP Telephony Solutions for Government conference sponsored by the Homeland Defense Journal and IT*Security Magazine.  In this presentation, Dan provides an introduction to VoIP security issues, discusses threats and briefly touches on best practices to protect against those threats.

Download the show here (MP3, 38MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

You may also download the presentation slides to follow along during the recording.  The total show runs about 41 minutes.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Listener Survey – Please help us out!

We would like your help!  In order for us to get a better sense of who listens to our show, could you please take a couple of minutes to fill out our listener survey?  It is at:

http://www.surveymonkey.com/s.asp?u=495372074777

It should take only a few minutes and it will greatly help us.

Why are we asking these questions?  Well, mostly it is to understand better who is listening so that we can know better how to target our commentary, interviews, etc.  We are also always looking for feedback on the show and ways we can make it that much stronger.  Finally, we’d like to collect some demographic info so that when we are requesting interviews and are asked about who listens, we can provide some overall statistics to show the value of being interviewed on this show.

All individual responses will be kept strictly confidential but we will make overall summary data available here on the show website.  We greatly appreciate any and all responses you can give.

P.S. Yes, on show #25 I said the survey was 25 questions… after the recording I added 5 more… I hope you can still take the time to answer it. 🙂

Blue Box Podcast #25: VoIP Security news, listener survey and more

Synopsis: A brief show with VoIP security news, our listener survey and more


Welcome to Blue Box: The VoIP Security Podcast show #25, a 20-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security.  This show also introduces our listener survey.

Reminder: There will not be a show next week as Dan will be away.

Download the show here (MP3, 18MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

In this show we also mentioned our new promotion – anyone submitting audio comments (either by email or calling the comment line) during April will be eligible for a drawing for a free copy of "Practical VoIP Security" from Syngress Press. Many thanks to Bruce Stewart and the folks at O’Reilly & Associates (who distribute Syngress books) for providing this book.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

Blue Box Podcast #24: Supersized show – VoIP security news, 2 interviews, comments and much more

Synopsis: Super-sized edition – Two interviews, one with David Schwartz, CTO of Kayote networks and one with Rodolfo Rosini, CEO of Cellfire Security.  VoIP security news, opinions and many comments from listeners, along with a way to potentially win a copy of a new book on VoIP security.


Welcome to Blue Box: The VoIP Security Podcast show #24, a 109-minute podcast  from Dan York and Jonathan Zar with news and commentary about the world of VoIP security.  This show also features a 38-minute interview with David Schwartz, CTO of Kayote Networks about his perspective on the IETF meeting in Dallas in March and SIP Identity and SPIT as well as another 18-minute interview with Rodolfo Rosini, CEO of Cellfire Security about his new startup.

This show is extra-large this week because there will be no show next week due to vacation travel and we wanted to make these interviews available.

Download the show here (MP3, 100MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

In this show we also mentioned our new promotion – anyone submitting audio comments (either by email or calling the comment line) during April will be eligible for a drawing for a free copy of "Practical VoIP Security" from Syngress Press. Many thanks to Bruce Stewart and the folks at O’Reilly & Associates (who distribute Syngress books) for providing this book.

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at +1-206-338-6654 to leave a comment there.

Thank you for listening and please do let us know what you think of the show.