voip
VoIP Can Be Sniffed? Get Real!
Filed in archive Dangers by Dameon Welch-Abemathy on November 27, 2007
27354585.jpg
This mass hysteria about being able to make WAV files of VoIP conversations, while only recently brought into the forefront with a tool called SIPtap, is completely unwarranted. In short: if someone can run this tool on your network and make WAV files of your phone calls, you've got far bigger problems.

Back in March of 2004, I wrote a fairly detailed piece for Voxilla about VoIP and security issues. There are several things I did not cover in this rather lengthy article, reading back on it now, but some things remain true with SIP. More after the jump.



Even if you don't employ encryption for either the call control information or the voice channel, here's the real truth: Unless you can somehow see all the traffic between the two parties, you can't sniff a VoIP call. And you know what? That's difficult to do. As I wrote in 2004:

In order to actually intercept the call setup or voice data for an in-progress SIP call, you have to be at a location where the call is traveling through, either at the telephone service provider or the ISP. Since it's possible for a connection to change routes midstream, there are only a couple of points where it is practical to intercept a SIP call: On either the SIP client or proxy's premises, or at the ISP used by either endpoint. This isn't unique to SIP: a PSTN call can be intercepted in similar locations.


If you're looking for more meat, Mr Blog's got it.

Bottom line: This SIPtap thing is overblown. Not only is it infeasible to employ, it can easily be worked around by employing encryption. What do you think?

Permalink: VoIP Can Be Sniffed? Get Real!
Tags: voip+security  siptap  voip  2007  call  sniffed+real  voip+sniffed  openads+delivery 
Trackback: http://publish.creative-weblogging.com/publish/mt-tb.pl/103802
img Addthis img Ask img Blinklist img del.icio.us img Digg img Fark img Facebook img Google img Lycos img Ma.gnolia Add this page to Mister Wong Mr Wong img Netscape img Netvousz img Newsvine img Reddit img StumbleUpon img Slashdot img Tailrank img Technorati img Wink img Yahoo

Vote for VoIP Can Be Sniffed? Get Real!:

  • Currently 7.00/10
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
Rating: 7.00 out of 1 vote(s) cast.
 
Subscribe
Share It
RSSrss
See all blog subscribe options
Google google
What is RSS?
Yahoo! yahoo
Addthis Subscribe using any feed reader!
Bloglines Bloglines
Newsletter

TwitterFollow us on Twitter!