How secure are VoIP phone systems?

tswayne

I read an article in Forbes this morning about a guy who demonstrated an attack on Cisco VoIP phones, and he was able to access the mic data, and even have Google Speech to Text transcribe the data in near real time. Is this something to really be concerned about? How secure are VoIP telephone systems?

Answer this Question

Answers

5 total
zeevp
Vote Up (7)

Depite what most UC vendors and service providers want you to believe, VoIP systems are grossly insecure. Not only by themselves, but they also open new attack vectors at your data systems. See www.UCSecurity.org.

acliffe
Vote Up (6)

With anything that we are smart enough to build, there will always be people even smarter to compromise them! Like any computer system or software VoIP can bring some security issues but so can a traditional telephone system. (http://www.wired.com/threatlevel/2008/12/hacked-phone-sy/) This story demonstrates a hack resulting in a loss of $50,000. There are steps you can take to secure any phone system, and different brands other than cisco will have their own security measures. You should make sure you discuss these concerns with your provider. My company sells all phone systems - legacy, hosted and VoIP so you can see that i'm impartial to all! Read this blog on cloud security (concerning Hosted VoIP). http://www.elitetele.com/news/read/cloud-telephony-and-security

jimlynch
Vote Up (7)

Here's an article that covers VoIP security issues.

Security Issues
http://voip.about.com/od/security/Security_Issues.htm

"How secure is VoIP? Learn about the security issues related to VoIP, threats and dangers, prevention measures and precautions. Find more on VoIP security protocols and their use in VoIP networks."

dvarian
Vote Up (8)

Nothing is perfectly secure.  I remember as a kid that once in a while when I picked up the phone (the old school, wired with rotary dial) I would overhear a neighbor's conversation.  Just a few years ago, I was sitting on my porch talking on my cell phone and a neighbor came over and told me she could hear every word we said over her baby monitor.  

 

One point to remember from that Forbes article is that the "hacker" physically installed an external circuit board on one of the VoIP telephones at the "target's" office.  It's pretty hard to make any system so secure that someone with physical access to it can't figure out a way to exploit it somehow.  He could just have installed a traditional "bug" in an office phone.  So, yeah, he found a hole and exploited it, but....  Cisco has already patched it by the way.  I wouldn't lose a lot of sleep over this. 

Christopher Nerney
Vote Up (5)

Given what you read in the Forbes article, maybe this link offering tips from Cisco on VoIP phone security isn't the way to go here.

 

How secure VoIP systems are probably is slightly subjective, though there are enough questions that this white paper was able to compile a list of top 10 security issues for VoIP. Perhaps the most important point in the white paper is that "VoIP security is only as reliable as the underlying network security."

 

 

 

 

Ask a question

Join Now or Sign In to ask a question.
Twitter has acquired Ubalo, a company that provides various services aimed at speeding up the coding process, the social network announced Thursday.
Box has acquired Crocodoc in a move to significantly improve the way documents are rendered for viewing on its enterprise storage and file sharing service.
Not everything on YouTube is free any more. The video-sharing website will now charge users a monthly fee to view certain content offered through subscription channels, the Google-owned site announced Thursday.
With the backing of its new parent company, Yammer more than tripled its revenue year on year in the quarter that ended in March.
Facebook has attracted "just about" 1 million downloads of its Home application in its first month of availability.
Facebook reportedly is in talks to buy a popular Israeli-based crowd-sourced mapping and traffic app.
Google is rolling out a new IT administration console for its Apps email and collaboration cloud suite and for other enterprise products such as Maps Coordinate and Chrome OS devices.
According to YouTube, most of the country can't wait for season six of True Blood to begin.
The nation's tech hub plans to partner with social networks to help residents prepare for the worst.
A Dutch startup has launched a service that studies data from social networks to quickly identify online service outages -- sometimes, it says, before the service providers know about the outages themselves.