PGP for VoIP, Anyone?

Source: asteriskblog.com

Most of us who lived in the days pre-WWW remember PGP. Actually anyone who has ever needed to send email or any message securely would remember PGP, which stands for Pretty Good Privacy. These days, it’s the de facto standard for encryption. But this is for data. What about voice? Specifically, what about VoIP?

Apparently, PGP’s creator Phill Zimmerman is still working on making our lives more secure from eavesdropping, and yes, his work now is about VoIP. VoIP news shares a feature where Zimmerman’s latest project is introduced.

The concept behind this latest endeavor is the possibility of man-in-the-middle attacks in VoIP conversations. In public switched telephony (your plain old telephone system), it was easy for governments to eavesdrop into conversations because they have power/control over the telcos. But it’s not so, the other way around. But with VoIP, the playing field is leveled. Now individuals can eavesdrop on anyone (with the right tools), even government officials. Therefore there’s a need to ensure top grade security, especially for sensitive calls.

Zimmerman and company created a product, Zfone, which incorporates the best features of PGP into voice communications. And this is done by doing away with the public key setup that most security systems use. This is purely peer-to-peer, meaning only you and the person on the other line should have this “key” and you can be sure that it’s the same person you are talking to. It’s like meeting someone face to face the first time. The next time you meet, you’ll know it’s that same person.

Zfone, the ZRTP-based product Zimmermann sells through a company with the same name, also incorporates “key continuity,” where you hash the keys just used in the conversation, and they become part of the keys for the next conversation, thus assuring that you’re talking with the same person as the last time.

“You check to see if there was a previous, retained shared secret from the earlier call,” Zimmermann says, “and if there was, you mix it in with the key that you’re generating for this call, so that if there was no man in middle in the last call, there cannot be one in this call.”

The numbers generated by this process should match up, even a hundred conversations later, Zimmermann says. “You don’t have to lie awake at night worrying about whether they heard you talking six months ago in that call that you forgot to check.”

Zfone offers plenty of features, including a GUI for management, and a packet interceptor that turns software and hardware VoIP clients into secure connections. Zfone also has licensing deals with other VoIP providers and open-source solutions, including Asterisk. Zimmerman is hoping this could be adopted as a standard in the VoIP industry and community.

Published on April 16th, 2007 under ,


Last 20 posts tagged "Security"

Nortel Using Certicom Security Technology

Source: www.voip-news.com

-news.comNortel is using Certicom’s security technology to improve cryptographic performance and simply application creation for its UC platform for U.S. Federal Government agencies.
According…

Published on September 29th, 2008 under , , , , ,

VoIP Security Examined

Source: www.voip-news.com

Do you remember when anti-virus was a sometimes thing, when people didn’t worry about impending hackings and attempts to steal or corrupt critical data? That’s sort of like VoIP’s stat…

Published on May 19th, 2008 under , , , , ,

Asterisk Vulnerability Discovered

Source: asteriskblog.com

Here is something for all Asterisk users out there.  Though we may all be very enthusiastic about Asterisk and the service it provides, we have to be practical and keep our eyes open for vulnerabilities. …

Published on April 23rd, 2008 under , ,

New York Times Takes on VoIP Security

Source: www.voip-news.com

Ahhh, finally. I knew it had to happen sometime: the New York Times talking about VoIP (or more specifically, VoIP security).
So, what do they have to say about VoIP? Well, for starters, it is…

Published on April 3rd, 2008 under , , , , ,

Got VOIP Spam?

Source: asteriskblog.com

Did you know that they can spam VOIP just like they spam e-mails? Whoever “they” may be, the threat may very well be quite real and has actually been given a name. “Spit” stands for…

Published on March 12th, 2008 under ,

Keeping Your Voice Calls Confidential

Source: asteriskblog.com

Everyone knows this – IP voice calls can be prone to eavesdroppers. Yup, even the virtual walls have ears. Whether you are using VOIP for business or for personal purposes, I am quite sur…

Published on March 5th, 2008 under ,

Top VOIP Security Threats Continued

Source: asteriskblog.com

So in the last post, you saw how DoS attacks and eavesdropping would be big concerns this year. Here are the last 3 points that Jim Higdon wrote about earlier this year:
3. Microsoft Offic…

Published on February 29th, 2008 under , ,

Paypal says avoid Safari

Source: saunderslog.com

Paypal is warning users to avoid Safari, and choose IE, Firefox or Opera instead.  Why?  Safari doesn’t implement the modern anti-phishing systems that other browsers do.  It’s…

Published on February 29th, 2008 under , , , , , , , ,

Top VOIP Security Threats

Source: asteriskblog.com

VOIP is definitely a cost effective way to manage communications, both for business and personal use alike. As with many other things in life, though, VOIP does have some downsides to it…

Published on February 27th, 2008 under ,

Introducing: The Wing

Source: asteriskblog.com

Last Tuesday, May 22, T-Mobile launched its newest gadget, The Wing. Like the iPhone, which is scheduled to ship in about a month, the Wing is a Wi-Fi equipped combined PDA and mobile phon…

Published on May 31st, 2007 under , , , , ,

Keep Your Phone Numbers Private

Source: asteriskblog.com

Yes, we know that with the advent of the internet, privacy has become almost obsolete. But if you’re one of those who still believe that there’s some way to keep your landline, cell or VOIP…

Published on May 23rd, 2007 under , ,

Installing Asterisk on a Linksys Router

Source: asteriskblog.com

Here’s one of the better Asterisk-related hacks I’ve seen lately (though it’s nothing really new). The Linksys WRT54G series is, after all, flash-able, and it’s mostly Linux-based (saved…

Published on April 23rd, 2007 under , , , ,

How Secure Is Your VoIP System?

Source: asteriskblog.com

Recently, we wrote about PGP for VoIP, and how developers are integrating such security systems into Asterisk. But here’s one fundamental question: how secure is your VoIP system? are you awar…

Published on April 18th, 2007 under ,

PGP for VoIP, Anyone?

Source: asteriskblog.com

Most of us who lived in the days pre-WWW remember PGP. Actually anyone who has ever needed to send email or any message securely would remember PGP, which stands for Pretty Good Privacy. Thes…

Published on April 16th, 2007 under ,

Traditional Telcos Are Still Out To Get VoIP Companies

Source: asteriskblog.com

VoIP is getting more popular with business and home users. But while business users have the funds and manpower to set up and maintain their own gateways and VoIP equipment (such as with self-installed…

Published on March 28th, 2007 under , , , ,

What price, security?

Source: saunderslog.com

Security is a sensitive topic for Americans.  In the post 911/War on Terror/Iraq era, it’s easy to see why.  Men are in harms way, and the country remains on a war footing.
At…

Published on March 25th, 2007 under

Claim your MyBlogLog accounts!

Source: asteriskblog.com

Over at Google Tutor we’ve got the discovery of another hole in the MBL system. It’s not all that bad but we want our members to have the heads up. So, please check out the full details on…

Published on March 12th, 2007 under

VOIP Security. VOIPSA comes to our aid.

Source: snapvoip.blogspot.com

VOIP security is not a subject we read or write much about because we are busy with getting products to the market. But VOIPSA, which I wrote about a year ago "VoIP Security Threat Taxonomy&quot…

Published on November 30th, 2006 under , , , ,

VoIP: Security Threat #5

Source: saunderslog.com

Dan York has written a lengthy post on how SANS (SysAdmin, Audit, Network, Security) Insitute has identified VoIP among their top 20 Internet Security Threats for 2006.  They’ve identified…

Published on November 16th, 2006 under , , , ,

Asterisk remote heap overflow

Source: snapvoip.blogspot.com

Notice to all Asterisk users:A security Advisory has been issued on Asterisk open source PBX, IPPBX. Please fix as soon as possible, any application or servers using Asterisk like TRIXBOX, should…

Published on October 20th, 2006 under , , , , , ,
Member of "Hype Media! Network"