<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Suggestions for a &#8220;security roadmap&#8221; for Asterisk</title>
	<atom:link href="http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/feed/" rel="self" type="application/rss+xml" />
	<link>http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/</link>
	<description>Collective thoughts and musings on the state of VoIP security today.</description>
	<pubDate>Fri, 25 Jul 2008 16:36:43 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Voice of VOIPSA &#187; Blog Archive &#187; &#8220;Hacking and Attacking VoIP Systems&#8221; - Slides from my Astricon 2007 presentation about Asterisk and VoIP security</title>
		<link>http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-145111</link>
		<dc:creator>Voice of VOIPSA &#187; Blog Archive &#187; &#8220;Hacking and Attacking VoIP Systems&#8221; - Slides from my Astricon 2007 presentation about Asterisk and VoIP security</dc:creator>
		<pubDate>Thu, 17 Jan 2008 13:12:37 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-145111</guid>
		<description>[...] about VoIP security and then got into some specific suggestions for securing Asterisk (which I posted on this blog). A number of folks have asked for the slides&#8230; and so here they [...]</description>
		<content:encoded><![CDATA[<p>[...] about VoIP security and then got into some specific suggestions for securing Asterisk (which I posted on this blog). A number of folks have asked for the slides&#8230; and so here they [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin Gruber</title>
		<link>http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-105920</link>
		<dc:creator>Martin Gruber</dc:creator>
		<pubDate>Mon, 15 Oct 2007 09:01:24 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-105920</guid>
		<description>hi,

I would be very interested in your presentation about Security @ Asterik. Is it possible to get your presenation for download?

thanks for your answer.

kind regards
Martin</description>
		<content:encoded><![CDATA[<p>hi,</p>
<p>I would be very interested in your presentation about Security @ Asterik. Is it possible to get your presenation for download?</p>
<p>thanks for your answer.</p>
<p>kind regards<br />
Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan York</title>
		<link>http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104703</link>
		<dc:creator>Dan York</dc:creator>
		<pubDate>Thu, 11 Oct 2007 10:18:56 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104703</guid>
		<description>Mikael,

Many thanks for providing that information.  I was not aware that the SRTP patch also included the key exchange methods.  Thanks for that information.

MIKEY is an interesting one.  It has a great amount of capabilities, but it is being implemented by VERY few vendors.  Largely the response I get back when I ask about it is that it is "too complex" and perhaps offers too many choices.  Vendors seem to focus on sdescriptions for its utter simplicity, but it does assume transport encryption (and also has problems with forking and early media which we've discussed before).

Thanks for the info on what the patch does,
Dan</description>
		<content:encoded><![CDATA[<p>Mikael,</p>
<p>Many thanks for providing that information.  I was not aware that the SRTP patch also included the key exchange methods.  Thanks for that information.</p>
<p>MIKEY is an interesting one.  It has a great amount of capabilities, but it is being implemented by VERY few vendors.  Largely the response I get back when I ask about it is that it is &#8220;too complex&#8221; and perhaps offers too many choices.  Vendors seem to focus on sdescriptions for its utter simplicity, but it does assume transport encryption (and also has problems with forking and early media which we&#8217;ve discussed before).</p>
<p>Thanks for the info on what the patch does,<br />
Dan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sugerencias para la seguridad en Asterisk at Mi Brain-Training Personal</title>
		<link>http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104701</link>
		<dc:creator>Sugerencias para la seguridad en Asterisk at Mi Brain-Training Personal</dc:creator>
		<pubDate>Thu, 11 Oct 2007 09:58:14 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104701</guid>
		<description>[...] Leo en VOIPSA una lista de sugerencias para la seguridad en Asterisk. Bastante interesantes, por cierto. PodÃ©is echarle un vistazo aquÃ­. [...]</description>
		<content:encoded><![CDATA[<p>[...] Leo en VOIPSA una lista de sugerencias para la seguridad en Asterisk. Bastante interesantes, por cierto. PodÃ©is echarle un vistazo aquÃ­. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mikma</title>
		<link>http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104693</link>
		<dc:creator>mikma</dc:creator>
		<pubDate>Thu, 11 Oct 2007 09:11:23 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104693</guid>
		<description>Hi, I'm the developer of the SRTP+SDESC+MIKEY patch for Asterisk. I'd like to point out that this patch implements both SRTP (2) and a secure SRTP key exchange (3).

This patch supports two different key negotiation algorithms both standardized by IETF, "sdescriptions" (SDESC) which requires transport encryption as you mentioned. The other algorithm is MIKEY which doesn't require additional transport encryption since  the messages already are integrity protected, and the keys encrypted. MIKEY supports multiple methods: pre-shared, Diffie Hellman (DH), DH-HMAC, Public-key (RSA), and RSA in reverse mode (RSA-R). The patch is based on the minisip libraries, and uses DH-HMAC for outgoing calls.

Mikael</description>
		<content:encoded><![CDATA[<p>Hi, I&#8217;m the developer of the SRTP+SDESC+MIKEY patch for Asterisk. I&#8217;d like to point out that this patch implements both SRTP (2) and a secure SRTP key exchange (3).</p>
<p>This patch supports two different key negotiation algorithms both standardized by IETF, &#8220;sdescriptions&#8221; (SDESC) which requires transport encryption as you mentioned. The other algorithm is MIKEY which doesn&#8217;t require additional transport encryption since  the messages already are integrity protected, and the keys encrypted. MIKEY supports multiple methods: pre-shared, Diffie Hellman (DH), DH-HMAC, Public-key (RSA), and RSA in reverse mode (RSA-R). The patch is based on the minisip libraries, and uses DH-HMAC for outgoing calls.</p>
<p>Mikael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Security Briefing: October 9th</title>
		<link>http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104284</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Security Briefing: October 9th</dc:creator>
		<pubDate>Tue, 09 Oct 2007 12:59:11 +0000</pubDate>
		<guid isPermaLink="false">http://voipsa.org/blog/2007/10/09/suggestions-for-a-security-roadmap-for-asterisk/#comment-104284</guid>
		<description>[...] Suggestions for a â€œsecurity roadmapâ€ for Asterisk [...]</description>
		<content:encoded><![CDATA[<p>[...] Suggestions for a â€œsecurity roadmapâ€ for Asterisk [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
