Light Reading

Five WiFi VOIP Security Issues

Dan Jones
LR Mobile News Analysis
Dan Jones, Mobile Editor
2/16/2006
50%
50%

As enterprise deployments of WiFi VOIP systems reach the staging point, security will be a key concern for enterprise users.

Shawn Merdinger, an independent security consultant based in Austin, Texas, has worked with Cisco Systems Inc. (Nasdaq: CSCO) and 3Com Corp. (Nasdaq: COMS)/Tipping Point. He's tested around a dozen WiFi VOIP handsets and deskphones and says that security problems range from potential denial-of-service attacks to more serious issues that allow "deep access" to the device that lets a remote attacker read sensitive information on the phone.

You can see his postings on many of the devices tested, along with some workarounds here. In the wake of Merdinger's findings, Cisco Systems Inc. (Nasdaq: CSCO), Hitachi Ltd. (NYSE: HIT; Paris: PHA), and UTStarcom Inc. (Nasdaq: UTSI) have issued firmware upgrades for the devices in question. (See WiFi VOIP: How Safe?.)

Such threats are inevitable. So it's up to vendors to forestall them, according to analyst Paul Stamp, of Forrester Research Inc. "It's security 101. If we see practices like this continue as these devices get more popular then the manufacturers will only have themselves to blame when there's a widespread attack," he notes.

Still there are steps users can take to protect themselves. Here's a Top 5 list of enterprise WiFi VOIP security issues, and some ways to guard against them:

Widespread deployment equals a security headache:
Because of the "ubiquity of deployment" in many enterprises, attacks can spread quickly and be targeted to take down multiple devices at once. IT managers should stay up to the minute with phone upgrades, and consider running phones over a separate physical or virtual LAN as a defense against these attacks.

Many points of attack:
As the phones get more sophisicated, so could the points of entry for malicious attacks increase. Bluetooth, email, client Web browsers, SMS, WiFi, media players, and image viewers could open back doors for hackers. Though users can use open-source and commercial tools to continually test their phones and networks, they'll ultimately have to rely on vendors to do proactive testing on these devices. "Some vendors may engage in this testing while the majority will not," warns Merdinger.

Targeting phones in public environments:
For example, a Bluetooth scanner could be hidden at the entrance to a major airport or train station and be used to grab user data. It may be best to keep Bluetooth and other wireless features swicthed off when not needed.

Rogue again:
Meanwhile, at the office and on the road, users and IT departments will have to keep their guard up and scan for rogue access points. Hackers will set up access points to specifically target WiFi phones in the corporate space as well as at hotels, conferences, and other places business people like to congregate. Good device authentication and encryption can help provide protection here.

Targeted attacks:
Targeted attacks on specific voice-over-wireless networks could also be an issue, albeit one that the victims may try to downplay. "There will be targeted attacks on VoIP networks [from hackers or competitors] that will be kept quiet if there is no legal requirement for disclosure or obvious public knowledge," Merdinger says.

Users, however, shouldn't get in a snit about VOIP calls that are often unencrypted and therefore easier to listen in on. Unless attackers are targeting a specific user, it is much simpler to find useful information sent by the user or held on the phone than to listen in on calls, even if you're the NSA.

"Most attackers are going to go after text information -- much easier to parse for the juicy information," says Merdinger.

— Dan Jones, Site Editor, Unstrung

(0)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
Flash Poll
From The Founder
The New IP is actually bigger even than business. Like another hugely important tech that Light Reading is digging into right now, the New IP has the potential to change the world by fundamentally advancing what it is possible for people to achieve with communications.
LRTV Huawei Video Resource Center
The Power of Five Convergences in OceanStor OS

3|4|15   |   6:24   |   (0) comments


OceanStor OS is Huawei's brand-new storage operating system. While inheriting the consistent high stability, reliability and performance from the company's previous storage products, OceanStor OS abounds in new converged storage features. Specifically, the new storage operating system achieves "five convergences" to lift storage convergence to a higher level.
LRTV Huawei Video Resource Center
4K Brings Extreme Video Experience

3|4|15   |   8:10   |   (0) comments


4K video is a hot topic in the video industry. It will certainly bring an extreme video experience to end users. At the same time, however, it will also pose a big challenge to operators. Check out this Huawei 4K experts' discussion about how operators can achieve success in 4K video service.
LRTV Interviews
DT's Virtualization Vision for Europe

3|4|15   |   10:23   |   (0) comments


Light Reading CEO Steve Saunders talks virtualization, cloudification and standards with Deutsche Telekom's Axel Clauberg at Mobile World Congress.
LRTV Custom TV
ZTE's Wireline at MWC 2015

3|4|15   |   6:35   |   (0) comments


Light Reading speaks with Jane Chen, ZTE's Senior VP of Wireline Business, about innovations in her product line at Mobile World Congress.
LRTV Custom TV
ZTE at MWC 2015

3|4|15   |   4:24   |   (0) comments


Dr. Dick Chen of ZTE USA gives Light Reading an overview of what's new at ZTE's pavilion at Mobile World Congress 2015.
LRTV Interviews
Ericsson CEO Talks Telco Data Center Tech

3|4|15   |   05:45   |   (0) comments


At Mobile World Congress, Ericsson CEO Hans Vestberg discusses telco data center technology, business models, small cells and more.
Between the CEOs
EXCLUSIVE: Cisco's Chambers on Reinvention

3|3|15   |   8:24   |   (1) comment


Light Reading CEO Steve Saunders talks transformation and virtualization – including Light Reading's independent testing of the vendor's virtualization solutions – with Cisco CEO John Chambers at Mobile World Congress in Barcelona.
LRTV Documentaries
The Three Cs of MWC15

3|2|15   |   2:33   |   (1) comment


My visit to this year's Mobile World Congress is going to dominated by three Cs – cloud, cells and coffee.
LRTV Huawei Video Resource Center
Huawei Shares Its Vision of the Future of Mobile Networks Innovations

2|26|15   |   2:30   |   (0) comments


Mobile broadband is changing our lives. It's reshaping the Internet, industry, and society. It allows us to freely connect with one another anytime, anywhere. At this year's Mobile World Congress, Huawei will share its latest insights and newest ideas and technologies that will shape the future of MBB. They will showcase their end-to-end MBB solutions that will ...
LRTV Huawei Video Resource Center
Accelerate Digitizing, Boost Digital Business

2|26|15   |   6:14   |   (0) comments


A new digital revolution is leading us to a better connected world. Together with millions of digital partners, Huawei will help CSPs to build their digital service ecosystem and aggregate a wide variety of digital services. In this video, we find out how Huawei is going to help CSPs implement digital operations.
LRTV Huawei Video Resource Center
The Secret Recipe to Enabling Hyper-Growth Industries

2|26|15   |   3:38   |   (0) comments


With a number of successful cases on network capability exposure, Huawei is going to share the secret recipe to enabling hyper-growth markets with a step-by-step approach.
LRTV Documentaries
BTE 2015 Is Bigger & Even Better

2|25|15   |   03:13   |   (4) comments


This year's Big Telecom Event (BTE) in Chicago is going to provide more opportunities than ever for networking, getting to grips with key industry challenges and opportunities and, equally as important, having some fun.
Upcoming Live Events
March 17, 2015, The Cable Center, Denver, CO
April 14, 2015, The Westin Times Square, New York City, NY
May 12, 2015, Grand Hyatt, Denver, CO
May 13-14, 2015, The Westin Peachtree, Atlanta, GA
June 8, 2015, Chicago, IL
June 9-10, 2015, Chicago, IL
June 9, 2015, Chicago, IL
June 10, 2015, Chicago, IL
All Upcoming Live Events
Infographics
Net neutrality, broadband services and the current outlook on data consumption, as presented by the New Jersey Institute of Technology.
Hot Topics
Internet Pioneers Decry Title II Rules
Carol Wilson, Editor-at-large, 3/2/2015
Wheeler: We'll Enforce Title II 'Case-By-Case'
Sarah Thomas, Editorial Operations Director, 3/3/2015
New CenturyLink CTO in Major Overhaul
Carol Wilson, Editor-at-large, 3/4/2015
Verizon Takes Radio Dot to Detroit, VoLTE Overseas
Sarah Thomas, Editorial Operations Director, 2/27/2015
Like Us on Facebook
Twitter Feed
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
Check out Light Reading's interview with Jay Samit, the newly appointed CEO of publicly traded SeaChange International Inc. With a resume that includes Sony, EMI, and Universal, Samit brings a reputation as an entrepreneur and a disruptor to his new role at the video solutions company. Hear what he had to say about the opportunities in video, as well as the outlook for cable, telco, OTT and mobile service providers.