Synopsis: VoIP in SANS Top 20, launch of VOIPSA Best Practices project, VoIP security news, Skype security, IETF, security policies, listener comments and more
Welcome to Blue Box: The VoIP Security Podcast #45, a 49-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.
Download the show here (MP3, 23MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Show Content:
- 00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners - and to all those listeners who have been here for so long!.
- 01:32 - Dan discusses Martyn Davies recent visit to Vermont and the great photo Martyn took of Dan podcasting, upcoming shows and more
- 04:50 - Voice of VOIPSA: VoIP included for first time in SANS Top 20 pointing to SANS Top 20 – thanks to UK listener Rhodri Davies
- 09:06 - IETF 67 was going on last week… no major news yet – but pointer to RTPSEC mailing list, mention of Phil Zimmermann's presentation (involving ZRTP and patents) and this Tutorial on ICE by Jonathan Rosenberg
- 11:02 - Voice of VOIPSA: Skype releases new Network Administrators Guide pointing to new Network Administrator’s Guide – note the final 9 pages that deal with enterprise use of VoIP - see also CRN: Skype sets eyes on enterprise customers
- 13:54 - Jan Geiernat in Watching, Testing & Digesting:Skype Software & Hardware Gadgets has been writing more about Skype security lately, including this this this and this
- 14:35 - SearchVoIP.com: VoIP security safeguards – they may be there already – and Voice of VOIPSA reaction – and Voxilla reaction – and Andy Abramson at VoIPWatch
- 16:29 - Ovum report creates news:
- silicon.com: Get ready for VoIP attacks
- CXOToday: Unknown Threat, Real Risk: VoIP Security
- RedHerring: VoIP Security Gets Noisy
- NewTelephony: Ovum: Reduce VoIP Security Risks Before Further Deployment
- Of course, the Ovum report on VoIP security came out in August 2006 and costs $1,728!!!
- 20:02 - IPCommunications.com: Covergence and NewHeights Team to Offer Secure SIP-Enabled Soft-Client Offering
- 20:56 - TechRepublic: Get the skinny on proprietary protocols
- 21:28 - ITPro: Over half of UK businesses have no IM or VoIP policy (note that survey sponsor is Symantec)
- 22:16 - Network World: The New York Times taps Nortel to build secure VoIP net (interesting for the tour through what the NYT is doing)
- 23:05 - Computer Business Review Online: Finding your voice
- 24:18 - InterGovWorld.com: Putting a PAL to work
- 25:37 - ComputerWeekly.com: How to keep your VoIP net safe
- 25:57 - VoIP Service Blog: New FTC rule to put an end to SPIT pointing to FTC ruling
- 28:00 - VON Magazine: BT swallows Counterpane – see also Bruce Schneier’s blog (including the comment)
- 28:54 - Creamer Media’s Engineering News Online: Power-line-based broadband offers security advantages
- 29:30 - TMC.net: Electrocom Intros VoIP Intercom System for K-12 Schools see also news release: Rauland-Borg Offers VoIP Intercom as Safety and Security Solution for K-12 Schools
- 30:12 - Upcoming shows:
- Nov 29-30, Tokyo, Japan, PacSec 2006
- Dec 4-6, Atlanta, GA, VON Enterprise
- Dec 5, London, UK, Secure Mobile Computing
- Jan 23-26, 2007, Ft. Lauderdale, FL, Internet Telephony Conference and Expo – East
- Feb 5-9, 2007, San Francisco, CA, RSA Conference 2007
- Feb 27-Mar 1, 2007, San Francisco, Emerging Telephony 2007
- Mar 1-2, 2007, London, EUSecWest
- Mar 19-21, 2007, San Jose, CA, Spring 2007 VON
- Mar 23-25, Washington, DC, ShmooCon ‘07
- Apr 16-20, Vancouver, BC, Canada CanSecWest 2006
- 31:40 - Feature segment - impending launch of VOIPSA Best Practices project page
- What it is
- Why the need
- End goal
- How people can participate
- 40:43 - comment (email) from Craig Bowser
- 42:37 - comment (email) from Craig Bowser (again) pointing to 50 Most Influential People in VoIP (VoIPSA was on the list, but not us – but Craig added us in the comments!)
- 43:14 - comment (email) from Shawn Merdinger about AT&T security presentation mentioned briefly in this article
- 44:19 - comment (email) from Rhodri Davies
- 45:00 - comment (email) from Da Beave about iWar
- 47:34 - Review of the last week's traffic on the VOIPSEC public mailing list
- 48:21 - Wrap-up of the show
- Reminder that you can subscribe to the show via email as well as RSS
- Mention of our Frappr map
- 49:24 - End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to '[email protected]' to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Hey Dan, awesome job as always on the podcast.
I have to chuckle about the $1700 VoIP security report that is 23 pages long. Thats $80 a page. I guess we used the wrong pricing model for our book huh :)
Posted by: Mark Collier | December 06, 2006 at 12:14 PM