Home > Midmarket CIO Tips > > VoIP privacy on the WAN
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


VoIP privacy on the WAN


Tom Lancaster, Contributor
06.12.2006
Rating: -5.00- (out of 5)


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


With all the recent talk about AT&T and the NSA and secret rooms and wiretapping, many readers may be wondering not just about their privacy but about how to protect their companies. Whether or not this activity in particular is a threat will be the subject of much debate, but what is certain is that the situation is complex and easily abused. Not only is it possible to "sniff" individual circuits that comprise the Internet backbone, but the apparent lack of oversight and security controls (according to various news sources) means that if you're sending something interesting, there's little to prevent whoever is listening from selling your corporate secrets to your competitors, be the listeners government spies, "law enforcement," or your WAN provider's technicians and help desk.

Now, you're probably thinking several things about my little paranoid theory:

First, it's worth noting that although your government may not be spying on domestic traffic, many of you may work for multinational companies that do business globally. Thus, much of your traffic may route through several jurisdictions, each of which may be discouraged from spying on its domestic traffic but left free to spy on anything coming into or going out of the country. This was the theory behind Echelon.

Second, many people have pointed out that recording all the traffic that traverses the Internet would be quite a feat. Most have dismissed it as impossible. But text-to-speech and speech-to-text conversion software is pretty mature these days, and recording only those conversations with certain key words or with certain sources or destinations is a much simpler task. This possibility is one reason that encrypting voice traffic with SRTP (RFC 3711) is considered a best practice on the Internet, even though it isn't supported by most residential providers (such as Vonage).

This last thought is the most


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Security tools for the midmarket
IT security spending a bright spot in '09, with more growth predicted
Security and risk management in the midmarket
Identity and access management planning guide for the midmarket
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Unified communications: Securing access to OCS
Unified communications security: How safe is it?
Database security: Who should have access?
San Francisco network lockup justifies CIO fears

VoIP and unified messaging for the midmarket
Midmarket data center management guides: Tips and best practices
FAQ: What is unified communications, and why would I want it?
Mobile unified communications options for the midmarket
Fixed-mobile convergence saves firms costly mobile phone charges
Unified communications plans should tap CIO
CIOs grapple with tying Wi-Fi, VoIP into unified communications plan
Unified communications: Savvy business move or security meltdown?
Unified communications: Securing access to OCS
Unified communications security: How safe is it?
CIO Joseph Edward: In-house app ties parishes together

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


important point of this tip: You should realize that -- fundamentally -- the technology is the same for Internet and private WAN circuits. In fact, in many places, these circuits are probably logical provisions on the same physical fibers. From a practical standpoint, therefore, there's little difference between the public and private networks as far as privacy from sniffing is concerned.

Also, your private WAN traffic shares the same physical circuits with lots of other customers. This is true whether you use MPLS or a virtual circuit or point-to-multipoint technology such as ATM or Frame Relay. It's even true if your WAN is built from leased-lines such as T1s, which are circuit switched but still provisioned as small circuits over much larger physical connections in the backbone. Even as an innocent bystander, your company's data may still be at risk if an investigator obtains a warrant to sniff another company's data that happens to be serviced from the same POP. There are several ways to restrict the sniffing to a specific target, but no guarantee that they'll use one, or accountability if they don't.

Of course, each organization has to balance the cost of protecting its data with the risk of exposure, and most will conclude that additional security measures on their private WAN are not justified. But if you are concerned because you deal with sensitive data (e.g., medical records or technology research), then you should consider using SRTP on the WAN, just as you would on the Internet. And you might also consider encrypting each entire WAN circuit, if your topology permits.

About the author: Tom Lancaster, CCIE# 8829 CNX# 1105, is a consultant with 15 years experience in the networking industry. He has co-authored several books on networking -- most recently,CCSP: Secure PIX and Secure VPN Study Guide published by Sybex. This article originally appeared on SearchVoIP.com.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts