<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Click-to-Harass</title>
	<atom:link href="http://voipsa.org/blog/2006/11/21/click-to-harass/feed/" rel="self" type="application/rss+xml" />
	<link>http://voipsa.org/blog/2006/11/21/click-to-harass/</link>
	<description>Collective thoughts and musings on the state of VoIP security today.</description>
	<pubDate>Thu, 07 Aug 2008 23:46:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Voice of VOIPSA &#187; Blog Archive &#187; Tell Me Your PIN, So I Can Go Shopping</title>
		<link>http://voipsa.org/blog/2006/11/21/click-to-harass/#comment-8455</link>
		<dc:creator>Voice of VOIPSA &#187; Blog Archive &#187; Tell Me Your PIN, So I Can Go Shopping</dc:creator>
		<pubDate>Fri, 15 Dec 2006 15:16:20 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2006/11/21/click-to-harass/#comment-8455</guid>
		<description>[...] Martin Geddes of at Telepocalypse raises an interesting point that has bothered me also, which comes back to the security of phones, and the ability for hackers to pass themselves off as legitimate organisations, such as your own bank. Today, the problem is that there is no way an inbound call can ever be secure, because any Caller ID number you receive could be faked, and many outbound call centres withhold the number anyway.Â  Also, with technology like Asterisk servers and IVRs with synthesized speech, it is quite possible to build a reasonable facsimile of your bank at a very low cost. [...]</description>
		<content:encoded><![CDATA[<p>[...] Martin Geddes of at Telepocalypse raises an interesting point that has bothered me also, which comes back to the security of phones, and the ability for hackers to pass themselves off as legitimate organisations, such as your own bank. Today, the problem is that there is no way an inbound call can ever be secure, because any Caller ID number you receive could be faked, and many outbound call centres withhold the number anyway.Â  Also, with technology like Asterisk servers and IVRs with synthesized speech, it is quite possible to build a reasonable facsimile of your bank at a very low cost. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan York</title>
		<link>http://voipsa.org/blog/2006/11/21/click-to-harass/#comment-6011</link>
		<dc:creator>Dan York</dc:creator>
		<pubDate>Wed, 22 Nov 2006 15:34:07 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2006/11/21/click-to-harass/#comment-6011</guid>
		<description>Dustin,

Nice piece.  TechCrunch also had a post yesterday &lt;a href="http://www.techcrunch.com/2006/11/21/google-pulls-click-to-call/" rel="nofollow"&gt;speculating that Google had pulled Click-To-Call because of harrassment issues&lt;/a&gt;, although it seems to have just been a temporary service outage, as the service is back running today (used it myself this morning).

The interesting thing, though, is that you can see the immense value to the &lt;i&gt;consumer&lt;/I&gt; for this type of service.  Over the past few days I've been testing it myself with calling various local businesses here in Vermont.  I have to say it has worked great.  Find them in Google Maps, click the "call" button, wait for the ring of my phone, press the "Talk" button on my wireless handset and... ta da... I'm connecting to the business. It is a little strange for other people in the house (i.e. my wife) to hear the phone ring once before I pick up, but outside of that, it works fine. From a consumer point of view, it's a wonderfully easy way to find businesses and connect.  Why should I remember my dentist's number when I can just find them in Google Maps and click "call"?  Simple.  Easy.  Convenient.

Interestingly, the Caller ID that I see is that of the business I am calling, so I'm not entirely sure how that is all working.  You are right, though, that this does raise serious issues around the accuracy of call records.  I'll have to look at my next phone statement and see how (or if) these calls are recorded.

From a security point-of-view, too, it's not entirely clear to me personally where all these calls are going.  Presumably Google is using some VoIP Service Provider (some posts have indicated it is VoIP, Inc., in Florida) who is initiating the calls to myself and the other business.  How long is my call actually in "VoIP" versus the traditional PSTN?  What IP networks does it traverse?  What is the window of exposure for interruption or interception?  All good questions without ready answers (at least that I can see).

What is interesting to consider, also, is how fundamentally disruptive this and other similar services are to the traditional carrier market.  Why should I pay Verizon (my carrier here in VT) anything beyond the very, very basic service if I can use these services for my connections?  Given that the model &lt;i&gt;today&lt;/i&gt; here in the US is that &lt;i&gt;incoming&lt;/i&gt; calls are free, what is my incentive to go beyond the very basic plan?  Suddenly instead of paying $50 or $70/month for an unlimited NA calling plan, I'm paying $15/month for rudimentary service.  Just use a click-to-call service... especially a &lt;i&gt;free&lt;/I&gt; one from Google, and you're set.  Now, granted, I need to use some other service for calling residences, since Google is only businesses, but still, the point is that these services have to be giving carrier execs severe cases of agita.

It will also be curious to see the effect this Google effort has on JaJah and friends, where Google is making it &lt;i&gt;free&lt;/i&gt;.   Given that JaJah's business model seems to be around charging people for calls longer than 5 minutes, a move like this has got to be a threat to that model.  On the other hand, they may be wagering on the "stickiness" of customers... once they have started using Jajah, they'll stick with it.  However, customers are fickle and we've seen time and time again that free beats everything else (witness Skype's growth).

What I am not entirely clear on is the business model &lt;i&gt;for Google&lt;/I&gt;. Obviously this service can drive people to use Google Maps, but okay... so what?  As of this moment, there is no blatant advertising on any of the queries I've done.  Now this may just be that no one has sponsored any links relevant to my very local queries.  I note that when I did a query on "map store, boston, ma", I got sponsored links above and below my search results.  So maybe that is it... which seems kind of weak to me personally.  If I'm looking up a business,  for &lt;i&gt;me&lt;/i&gt; odds are pretty certain that I'm going to call &lt;i&gt;that&lt;/i&gt; business.  But maybe that's just me.  Maybe enough other people are clicking on the sponsored links that giving away calling minutes is an effective loss leader to bring people to the site.  I'm sure Google being the behemoth that they are they can get very aggressive pricing, so all the collective minutes may just be noise in their balance sheet.

Anyway, it's fascinating to watch all of these services evolve, and yes, as you indicate, there are serious security issues that do need to be addressed.  We shall see how this all shakes out.

Thanks for writing this post,
Dan</description>
		<content:encoded><![CDATA[<p>Dustin,</p>
<p>Nice piece.  TechCrunch also had a post yesterday <a href="http://www.techcrunch.com/2006/11/21/google-pulls-click-to-call/" rel="nofollow">speculating that Google had pulled Click-To-Call because of harrassment issues</a>, although it seems to have just been a temporary service outage, as the service is back running today (used it myself this morning).</p>
<p>The interesting thing, though, is that you can see the immense value to the <i>consumer</i> for this type of service.  Over the past few days I&#8217;ve been testing it myself with calling various local businesses here in Vermont.  I have to say it has worked great.  Find them in Google Maps, click the &#8220;call&#8221; button, wait for the ring of my phone, press the &#8220;Talk&#8221; button on my wireless handset and&#8230; ta da&#8230; I&#8217;m connecting to the business. It is a little strange for other people in the house (i.e. my wife) to hear the phone ring once before I pick up, but outside of that, it works fine. From a consumer point of view, it&#8217;s a wonderfully easy way to find businesses and connect.  Why should I remember my dentist&#8217;s number when I can just find them in Google Maps and click &#8220;call&#8221;?  Simple.  Easy.  Convenient.</p>
<p>Interestingly, the Caller ID that I see is that of the business I am calling, so I&#8217;m not entirely sure how that is all working.  You are right, though, that this does raise serious issues around the accuracy of call records.  I&#8217;ll have to look at my next phone statement and see how (or if) these calls are recorded.</p>
<p>From a security point-of-view, too, it&#8217;s not entirely clear to me personally where all these calls are going.  Presumably Google is using some VoIP Service Provider (some posts have indicated it is VoIP, Inc., in Florida) who is initiating the calls to myself and the other business.  How long is my call actually in &#8220;VoIP&#8221; versus the traditional PSTN?  What IP networks does it traverse?  What is the window of exposure for interruption or interception?  All good questions without ready answers (at least that I can see).</p>
<p>What is interesting to consider, also, is how fundamentally disruptive this and other similar services are to the traditional carrier market.  Why should I pay Verizon (my carrier here in VT) anything beyond the very, very basic service if I can use these services for my connections?  Given that the model <i>today</i> here in the US is that <i>incoming</i> calls are free, what is my incentive to go beyond the very basic plan?  Suddenly instead of paying $50 or $70/month for an unlimited NA calling plan, I&#8217;m paying $15/month for rudimentary service.  Just use a click-to-call service&#8230; especially a <i>free</i> one from Google, and you&#8217;re set.  Now, granted, I need to use some other service for calling residences, since Google is only businesses, but still, the point is that these services have to be giving carrier execs severe cases of agita.</p>
<p>It will also be curious to see the effect this Google effort has on JaJah and friends, where Google is making it <i>free</i>.   Given that JaJah&#8217;s business model seems to be around charging people for calls longer than 5 minutes, a move like this has got to be a threat to that model.  On the other hand, they may be wagering on the &#8220;stickiness&#8221; of customers&#8230; once they have started using Jajah, they&#8217;ll stick with it.  However, customers are fickle and we&#8217;ve seen time and time again that free beats everything else (witness Skype&#8217;s growth).</p>
<p>What I am not entirely clear on is the business model <i>for Google</i>. Obviously this service can drive people to use Google Maps, but okay&#8230; so what?  As of this moment, there is no blatant advertising on any of the queries I&#8217;ve done.  Now this may just be that no one has sponsored any links relevant to my very local queries.  I note that when I did a query on &#8220;map store, boston, ma&#8221;, I got sponsored links above and below my search results.  So maybe that is it&#8230; which seems kind of weak to me personally.  If I&#8217;m looking up a business,  for <i>me</i> odds are pretty certain that I&#8217;m going to call <i>that</i> business.  But maybe that&#8217;s just me.  Maybe enough other people are clicking on the sponsored links that giving away calling minutes is an effective loss leader to bring people to the site.  I&#8217;m sure Google being the behemoth that they are they can get very aggressive pricing, so all the collective minutes may just be noise in their balance sheet.</p>
<p>Anyway, it&#8217;s fascinating to watch all of these services evolve, and yes, as you indicate, there are serious security issues that do need to be addressed.  We shall see how this all shakes out.</p>
<p>Thanks for writing this post,<br />
Dan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Merdinger</title>
		<link>http://voipsa.org/blog/2006/11/21/click-to-harass/#comment-5995</link>
		<dc:creator>Shawn Merdinger</dc:creator>
		<pubDate>Wed, 22 Nov 2006 09:29:36 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2006/11/21/click-to-harass/#comment-5995</guid>
		<description>Look out for those Nigerian Embassy calls!
http://maps.google.com/maps?q=nigerian+embassy+washington+dc</description>
		<content:encoded><![CDATA[<p>Look out for those Nigerian Embassy calls!<br />
<a href="http://maps.google.com/maps?q=nigerian+embassy+washington+dc" rel="nofollow">http://maps.google.com/maps?q=nigerian+embassy+washington+dc</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
