Simple clear advice in plain English

Phreak-out over VoIP

Users will get ripped off if operators don't implement encryption, warns industry specialist

Phreaking, the hacking of telephone systems, has entered the VoIP age and could become a big problem unless operators tighten up their security, according to a VoIP specialist.

Hacking phones became something of a cult activity in the 1970s after youngsters – including Steve Wozniac, who built the first Apple computers – discovered that tones pitched at certain frequencies could open lines for free calls.

Hackers tended to present phreaking as a victimless crime because nobody lost any actual money, though operators were deprived of the cost of the calls.

But phreaking's latest incarnation could put VoIP users out of pocket, warns Dave Gladwin, vice-president of products at Newport Networks.

The reason is that VoIP services such as BT's Broadband Talk provide access to paid-for calls, too.

"Actually I like Broadband Talk. It is very useful and basically turns my notebook into a phone," Gladwin says. "I can sit in a hotel room abroad and receive or make calls as if I am at home."

But when those calls are made to landlines or mobiles they have to be paid for. And Gladwin claims that VoIP log-in details are on sale on the web at prices higher than those charged for credit-card details.

Log-in details are relatively easy to harvest at public hotspots because, according to Gladwin, nine out of 10 VoIP providers using the standard SIP protocol do not support encryption. Skype users are not affected because that system uses its own protocols and does encrypt traffic.

Gladwin points out that knowledgeable users will always check that they are on a secure link if they are making an online transaction, but "they don't tend to think about it when they are making an VoIP call".

The trouble is that VoIP operators need to implement encryption – users cannot do it on their own. "At the moment there is no call for them to do it. Encryption will require some investment. They will only spend the money if there is a demand for it," said Gladwin.

Article tags

Reader Comments

Encryption is false sense of security

Ok....let encrypt fuzzed and malicious signalling so we really can't inspect the packets to see what is really in the signalling and media path. Yet again....an SBC trying to be a security device. Stick to infrastucture.....for the good of all us voice people.

Posted by Joe, 30 Aug 2008

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Two tin cans phone illustration

Make phone calls over the internet

Your broadband internet connection could save you a lot of money on phone bills. We explain the difference between Skype and SIP and how each one works

BT's Home Hub 3

Why did internet telephony fail to grab the public's interest?

A few years ago everyone was expected to transfer allegiance to VoIP but, apart from being popular in business, all but Skype have failed with the general public

AVM Fritz Box 7390 router can make internet calls too

Get the most from your phone line and broadband connection

Question & Answer

Q.How do I stop Windows 7 search?

> Read the answer

Q.Is it a genuine call from Microsoft?

> Read the answer

Q.How can I turn Autoplay back on?

> Read the answer

Best deals on the web

img

Apple MacBook Pro (MC724LL/A)

£999.99- Buy it now

img

Samsung 300E5A-A01DX

£449.99- Buy it now

img

Sony Vaio VPCF23P1E/B

£679.98- Buy it now

Great benefits for subscribers!

Most popular articles

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

Bios

Basic Input Output System. Essential software built into every PC that connects the vital components....

Great shopping deals from Computeractive