Synopsis:Interview about IP Multimedia Subsystem (IMS) security with Morgan Stern.
Welcome to Blue Box: The VoIP Security Podcast special edition #11, a 17-minute podcast from Dan York and Jonathan Zar containing an interview with Morgan Stern, Principal Consultant at Lucent Worldwide Services about the security of IMS systems.
In this interview, I spoke with Morgan Stern, Principal Consultant, Global Convergence Center of Excellence, Lucent Worldwide Services, about the security of the IP Multimedia Subsystem (IMS) architecture. Morgan has just been part of a panel session at Fall VON 2006 in Boston entitled "Securing Communication for IMS" and we covered a range of security topics, including:
The differences between centralized and distributed architectures
The various standards bodies involved with IMS
The emergence of "A-IMS"
How do we do distributed security?
How do we verify the authenticity of end devices?
Is IMS hype or reality?
Are there really new and innovative services coming out for IMS?
What are the major security issues for IMS?
Lawful intercept and its issues
His role at Lucent and what his work there is about
If you are interested in IMS security, you may also want to listen to Blue Box podcast #35, where we interviewed author Miguel Garcia for his perspective on IMS security.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to '[email protected]' to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis:Interview with Gary Miliefsky, Founder and CTO of Netclarity around how his products provide VoIP security and his views on VoIP security in general.
Welcome to Blue Box: The VoIP Security Podcast special edition #10, a 22-minute podcast from Dan York and Jonathan Zar containing an interview with Gary Miliefsky, Founder and CTO of Netclarity.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to '[email protected]' to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: Phil Zimmermann interview, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP Security Podcast show #37, a 60-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show also includes a 15-minute interview with Phil Zimmermann about the status of ZFone, ZRTP and more
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583(new comment phone number!) to leave a comment there.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
15:04 - The Age (Australia): WiFi Skype phones to set you free (not security, per se, but combining Skype with WiFi… two of our favorite topics) Also mentioned the DualPhone.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: IMS security interview, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP Security Podcast show #35, a 71-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show also includes a 25-minute interview with Miguel Garcia about IMS security.
NOTE - Due to production issues, this show is coming out after show 36 and about a month after it was originally recorded. We do sincerely apologize for the delay! Please note also that also that the audio comment line number is wrong in the recording. As noted on the show website, the new number is +1-206-350-2583.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583(new comment phone number!) to leave a comment there.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: Black Hat 2006 super-sized edition - VoIP security news, interviews with David Endler, Mark Collier, Ofir Arkin and much, much more
Welcome to Blue Box: The VoIP Security Podcast show #36, a 83-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This is a special edition focusing on the 2006 Black Hat Briefing in Las Vegas and the voice security talks that were given at the conference.
NOTE: As explained in the show, this podcast #36 is being released before show #35, which will be released next week. You didn't miss #35... it just hasn't been released yet.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583(new comment phone number!) to leave a comment there.
NOTE: As I will explain in more detail on our next show (#37), there were a number of issues with the audio in this show both in the recording as well as in the post-production. One of the issues was some very annoying noise artifacts in the Endler/Collier interview that sound like cell phone interference. There are also a couple of gaps... and those with finally attuned ears will hear some clipping of the audio. Suffice it to say that I would not want our podcast to be judged by the audio quality of this episode! I'll explain more in our next episode about exactly why this episode didn't hit our usual quality level.
Show Content:
(NOTE - More detailed show notes with links will be made available next week. For right now, we just want to get the show posted.)
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners.
08:10 - Interview with Dave Endler and Mark Collier about their Black Hat talk and the VoIP security tools they released this week. (News articles from ZDNet and the Register.)
35:41 - Discussion of Hendrik Sholz's new smap tool and his zero-day exploit against Cisco PIX firewalls
39:46 - Discussion of Jay Schulman's session on phishing with Asterisk
45:29 - Discussion of Doug Mohney's session on using voice analytics to defeat social engineering
46:13 - Discussion of Nicolas Fischbach's session on carrier VoIP security
48:38 - Interview with Ofir Arkin about his session on NAC, Insightix, his role in VOIPSA, security research, etc.
1:05:42 - Mention of Alan Schimmler and his Still Secure blog and NAC
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-350-2583 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: IPv6 security, VoIP security news and more...
Welcome to Blue Box: The VoIP Security Podcast show #34, a 49-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show covers the usual VoIP security news and then includes a 27-minute interview with Yurie Rich and John Spence from Command Information about IPv6 security.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners. Mention of our listener survey
01:32 - Mention of IETF meeting and the audio streaming and the actual IETF agenda (also, if you have no understanding of how the IETF works, you may want to read The Tao of IETF )
02:20 - Mention of Podcast Awards - NOTE: Nominations closed on July 15th.
02:51 - Dan will be at Fall VON in Boston and Internet Telephony in San Diego - we'll plan dinners there.
03:09 - Dan will be on a panel of VoIP bloggers at Fall VON in Boston (listeners may not know of his blog at blog.danyork.com )
04:01 - Still looking for anyone with Wordpress expertise for suggestions about fighting blog spam over at Voice of VOIPSA.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: VoIP fraud case and CALEA revisited, VoIP security news, listener comments and much, much more...
Welcome to Blue Box: The VoIP Security Podcast show #33, a 44-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show covers the usual VoIP security news, but then through some excellent listener comments gets back into a continued discussion of the Pena/Moore VoIP fraud case and also CALEA.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners. Mention of our listener survey - PLEASE TAKE A MOMENT TO COMPLETE THE SURVEY! (Thank you!)
02:35 - Mention of upcoming Telecom Junkies podcast where this VoIP fraud case will be discussed.
02:56 - Mention of IETF meeting and the audio streaming and the actual IETF agenda (also, if you have no understanding of how the IETF works, you may want to read The Tao of IETF )
04:33 - Dan will be at Fall VON in Boston and Internet Telephony in San Diego - we'll plan dinners there.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: ENUM tutorial, VoIP security news, listener comments and much, much more...
Welcome to Blue Box: The VoIP Security Podcast show #32, a 49-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show includes a 14-minute tutorial on ENUM - what it is and what implications it has for security - as well as the usual coverage of VoIP security news and comments from listeners
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners. Mention of our listener survey - PLEASE TAKE A MOMENT TO COMPLETE THE SURVEY! (Thank you!)
02:38 - Discussion of why the first release of show #31 sounded like a really bad rap mashup
06:23 - I will be a guest on the upcoming Telecom Junkies podcast where the recent Pena/Moore VoIP fraud case will be discussed.
07:50 - Dan will be at the IETF 66th Meeting in Montreal, June 9-14 - Please drop us a note if you are going to be there.
08:11 - Dan will be attending Fall VON 2006 in Boston in September and will also be speaking out at the Internet Telephony conference in San Diego in October… so we’ll definitely have to do something there.
08:29 - Anyone have any opinions about WordOfBlog.net – they have contacted us about putting a graphic in there and I’m still not sure what all it is.
16:40 - Dave Endler and Mark Collier launch a website and a weblog about their upcoming book “Hacking VoIP Exposed”. They will also be out at Black Hat in August.
18:09 - CNet: FCC approves new Internet phone taxes
39:18 - Audio and email comment from Miguel Castillo Holgado
42:27 - Email comment from Reid Palmeira
43:18 - Audio comment from Andy Zmolek and mention of audio comment from Perry Engle
44:11 - Email comment from Miguel Castillo Holgado asking about Juniper’s white papers
46:15 - Review of the last week's traffic on the VOIPSEC public mailing list, mostly focused on softphone vulnerabilities and a continued heavy discussion of Skype security
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: VoIP fraud case, CALEA tutorial/commentary, VoIP security news, listener comments and much, much more...
Welcome to Blue Box: The VoIP Security Podcast show #31, a 53-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security. This show includes a 10-minute segment on the recent Pena/Moore VoIP fraud case and about a 15-minute discussion of the recent FCC decision about CALEA and what that means. There is of course the usual coverage of VoIP security news and comments from listeners
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
NOTE:I would welcome any comments about the audio quality of this MP3 file as compared to our other shows would be appreciated - I am trying out a new audio encoder. Thanks.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners. Mention of our listener survey - PLEASE TAKE A MOMENT TO COMPLETE THE SURVEY! (Thank you!) It looks like Dan will most likely be at the IETF 66th Meeting in Montreal, June 9-14 - Please drop us a note if you are going to be there. Check out VOIPSA's blog if you have not already done so.
10:28 - Feature discussion of recent VoIP fraud scam that was all over the news:
42:47 - Email comment from Mark Trifiro about having links launch in new windows
44:44 - Audio comment from Adrian Braun
45:27 - Email comment from Miguel Garcia – will be at IETF
45:51 - Email comment from “verizon user” pointing to ITAA report being on RISKS list
46:24 - Email comment from David Belle-Isle (threat vs vulnerability)
47:40 - Email comment from Chris Serafin about giving a customer case study
49:28 - Review of the last week's traffic on the VOIPSEC public mailing list, mostly focused on softphone vulnerabilities and a continued heavy discussion of Skype security
51:26 - Shoutout to Sasha, the host of the Skype podcast
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Synopsis: VoIP security news for the week, Skype security issues, VOIPSA weblog, our listener survey, listener comments and more
Welcome to Blue Box: The VoIP Security Podcast show #29, a 32-minute podcast from Dan York and Jonathan Zar with news and commentary about the world of VoIP security.
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
NOTE:I would welcome any comments about the audio quality of this MP3 file as compared to our other shows would be appreciated - I am trying out a new audio encoder. Thanks.
Show Content:
00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners. Mention of our listener survey - PLEASE TAKE A MOMENT TO COMPLETE THE SURVEY! (Thank you!)
01:39 - We have turned off moderation on the weblog comments because TypePad has introduced a form of CAPTCHA to combat automated spam
02:22 - List of podcast topics – please give it a look and do send us your comments (or call them in!)
02:40 - It looks like Dan will most likely be at the IETF 66th Meeting in Montreal, June 9-14 - Drop us a note if you are going to be there.
03:26 - Check out VOIPSA's blog if you have not already done so
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at +1-206-338-6654 to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Jonathan Zar is affiliated with Pingalo and is the Secretary of VOIPSA and member of the Board of Directors.
This is a personal project and neither the Internet Society, Pingalo nor VOIPSA have any formal connection to this podcast. In the interest of transparency we just thought you should know our affiliations.
Why "Blue Box"?
We chose the name "Blue Box" primarily as a nod to the era of phone phreaking in part to illustrate that threats to telephony are not new - they just continue to change and evolve. That and admittedly the name just sounded cool.
Recent Comments