Are you attending Black Hat next week in Las Vegas (July 29-Aug 2)? Or the Defcon show that follows? If so, would you be willing to provide a report (either audio or written) for us to include in a future Blue Box podcast (or potentially post on the VOIPSA blog)? Neither Jonathan nor I (nor Martyn) are going to be attending Black Hat or Defcon but there do look to be a number of quite interesting talks involving VoIP security. If you would be willing to send in a report from Black Hat or Defcon just briefly talking about what is discussed at the sessions there, please do drop us an email as we'd love to have such contributions.
FYI, if you want to try audio, contributions could be either: 1) recorded using something like Audacity and then sent by email; or 2) simply called into our comment line (+1-206-350-2583 or sip:[email protected]).
Synopsis: Blue Box #63: Cisco and Asterisk VoIP vulnerabilities, the "Athens affair" (Greek wiretapping), iPhones and Duke, IETF and SPIT, SunRocket flares out, Skype phishing, VoIP security news and more...
Welcome to Blue Box: The VoIP Security Podcast #63, a 38-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners - and to all those listeners who have been here for so long!
01:14 - Programming notes
Special Edition coming out with VON session.
Anyone going to Black Hat or Defcon next week? We'd love a report.
34:41 - comment (email) from listener Frank Leonhardt on possible Skype phishing email
37:03 - Review of the last week's traffic on the VOIPSEC public mailing list
37:35 - Wrap-up of the show
38:25 - End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to '[email protected]' to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Have you ever wished you could know when the slides are being changed when you listen to one of our Special Edition podcasts? Well, now you can courtesy of a new "slidecasting" interface made available from the folks at SlideShare.net. I have now made available synced versions of Blue Box SE#15 and Blue Box SE#16 as shown in the embedded objects below. SE#15 is, to me, a great example of the power of SlideShare's syncing interface. It is about 243 slides in 15 minutes and without the sync, it's not as easy to see how the slides are used to support the story. SE#16 is the much-longer 90-minute workshop that Jonathan, Shawn Merdinger and I did which again shows how the slide sync can be used in a longer setting. In any event, you can check them out in the embedded shows below. First the 15-minute "Black Back Security Review":
And then here our 90-minute workshop:
We would naturally love to hear your feedback about whether you find this useful. We anticipate putting up future presentations in this fashion. What do you think?
Synopsis: Blue Box #62: CAPTCHA for SPIT, covert channels, SIP Identity, is VoIP safe?, Fiji, Google, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #62, a 41-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.
Note: Originally recorded back on July 6th. There were some, well, "challenges" with the quality of the recording and so post-production took far longer than usual and you will still hear some audio artifacts every once in a while when Jonathan is speaking.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners - and to all those listeners who have been here for so long!
01:21 - Programming notes
Facebook group has grown to 22 members. If you are on Facebook, do check out the group.
Special Edition #18 – we hope you enjoyed that and thank Martyn for doing the interviews. We welcome such contributions.
38:29 - comments from Martyn about Peter Cox and Takehiro about the Covert Channels and comment (blog) from Adrian P. on Blue Box #51 (show on Feb 22)
40:02 - Review of the last week's traffic on the VOIPSEC public mailing list
40:32 - Wrap-up of the show
41:20 - End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to '[email protected]' to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: Session Border Controller (SBC) Special - Martyn Davies interviews Rod Hodgman from Covergence and Jeff Carr from Borderware about their products and the role of the SBC.
Welcome to Blue Box: The VoIP Security Podcast Special Edition #18, a 33-minute podcast of interviews by Martyn Davies of Rod Hodgman from Covergence and Jeff Carr from Borderware about their products and the role of the SBC and the question "Do SBCs break the rules of SIP?"
This Session Border Controller (SBC) special
features two back-to-back interviews with Rod Hodgman from Covergence (www.covergence.com) and Jeff Carr from
Borderware (www.borderware.com).
In the first interview, Martyn Davies speaks
to Rod Hodgman, VP of Marketing at Covergence, about their SBC product
line, Eclipse. Rod talks about SBCs that support peering and access edge
applications, and then focuses on access edge features such as NAT traversal and
DoS protection. The discussion also covers software vs. appliance; OS
hardening, ATCA and media acceleration. Rod answers the question "do SBCs
break the rules of SIP?", and tells us a user story.
In the second part, Martyn speaks to Jeff Carr, VP of the SIP Solutions Group at Borderware, about their software SBC, SIPAssure. Jeff talks about the access edge, SPIT (Internet Telephony SPAM): content filtering and reputation management; firewall vs. SBC. He also tackles the question "do SBCs break the rules of SIP?", and goes on to tell us a story about one of their OEM customers.
We thank Martyn for contributing these interviews.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to '[email protected]' to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
(P.S. In the spirit of full disclosure, I'll note that one of the customer stories turns out to be my employer, but I had no clue about that as this was entirely Martyn's production.)
Jonathan Zar is affiliated with Pingalo and is the Secretary of VOIPSA and member of the Board of Directors.
This is a personal project and neither the Internet Society, Pingalo nor VOIPSA have any formal connection to this podcast. In the interest of transparency we just thought you should know our affiliations.
Why "Blue Box"?
We chose the name "Blue Box" primarily as a nod to the era of phone phreaking in part to illustrate that threats to telephony are not new - they just continue to change and evolve. That and admittedly the name just sounded cool.
Recent Comments