<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Voice of VOIPSA &#187; David Endler</title>
	<atom:link href="http://voipsa.org/blog/author/david-endler/feed/" rel="self" type="application/rss+xml" />
	<link>http://voipsa.org/blog</link>
	<description>Collective thoughts and musings on the state of VoIP security today.</description>
	<lastBuildDate>Thu, 04 Mar 2010 17:07:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='voipsa.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Shall We Play a Game?</title>
		<link>http://voipsa.org/blog/2009/03/06/shall-we-play-a-game-2/</link>
		<comments>http://voipsa.org/blog/2009/03/06/shall-we-play-a-game-2/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 16:22:00 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Security Tools]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/?p=599</guid>
		<description><![CDATA[HD Moore of Metasploit Project fame has just released a new set of free War Dialing tools called WarVOX.  What makes these new tools so interesting is that they leverage VoIP service providers to scan and analyze hundreds of phone numbers, finding modems, faxes, voice mail boxes, PBXs, loops, dial tones, IVRs, and forwarders much much [...]]]></description>
			<content:encoded><![CDATA[<p>HD Moore of <a href="http://www.metasploit.com" target="_blank">Metasploit Project</a> fame has just released a new set of free War Dialing tools called <a href="http://www.warvox.org/" target="_blank">WarVOX</a>.  What makes these new tools so interesting is that they leverage VoIP service providers to scan and analyze hundreds of phone numbers, finding modems, faxes, voice mail boxes, PBXs, loops, dial tones, IVRs, and forwarders much much faster than any modem ever could.  Check out the <a href="http://www.warvox.org/gallery.html" target="_blank">WarVOX screenshots</a> which show the interface and slick reporting features.</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2009/03/06/shall-we-play-a-game-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Back Online</title>
		<link>http://voipsa.org/blog/2009/02/26/back-online/</link>
		<comments>http://voipsa.org/blog/2009/02/26/back-online/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 20:35:52 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[Voice of VOIPSA Info]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/?p=597</guid>
		<description><![CDATA[As some of you may have noticed, our servers were offline for the past 24 hours due to unforeseen circumstances.  It seems the recent global economic turmoil has not left VOIPSA unscathed.  Turns out our hosting provider was delinquent on paying their bills to their upstream data center provider.   Supposedly, the hosting provider&#8217;s management is [...]]]></description>
			<content:encoded><![CDATA[<p>As some of you may have noticed, our servers were offline for the past 24 hours due to unforeseen circumstances.  It seems the recent global economic turmoil has not left VOIPSA unscathed.  Turns out our hosting provider was delinquent on paying their bills to their upstream data center provider.   Supposedly, the hosting provider&#8217;s management is no where to be found and did not respond to repeated billing inquiries,  leaving the upstream data center no choice but to unplug all of the hosting provider&#8217;s customers.</p>
<p>Apologies for the inconvenience and we&#8217;re working on moving to a more permanant and solvent hosting provider in the near future!</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2009/02/26/back-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP makes the SANS Top 20 Internet Security Risks of 2007 (again)</title>
		<link>http://voipsa.org/blog/2007/11/27/voip-makes-the-sans-top-20-internet-security-risks-of-2007-again/</link>
		<comments>http://voipsa.org/blog/2007/11/27/voip-makes-the-sans-top-20-internet-security-risks-of-2007-again/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 20:51:58 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2007/11/27/voip-makes-the-sans-top-20-internet-security-risks-of-2007-again/</guid>
		<description><![CDATA[The SANS Institute just released its Top 20 Internet Security Risks of 2007 Annual update.  Yet again this year, VoIP made the list, with a collection of just some of the VoIP vulnerabilities that were disclosed this past year.  Check it out.  For those of you who don&#8217;t want to read the [...]]]></description>
			<content:encoded><![CDATA[<p>The SANS Institute just released its <a href="https://www2.sans.org/top20/" target="_blank">Top 20 Internet Security Risks of 2007</a> Annual update.  Yet again this year, <a href="https://www2.sans.org/top20/#n1" target="_blank">VoIP made the list</a>, with a collection of just some of the VoIP vulnerabilities that were disclosed this past year.  Check it out.  For those of you who don&#8217;t want to read the entire document, a decent <a href="https://www2.sans.org/top20/2007/press_release.php" target="_blank">executive summary is available here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2007/11/27/voip-makes-the-sans-top-20-internet-security-risks-of-2007-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VOIPSA Releases its VoIP Security Tools List</title>
		<link>http://voipsa.org/blog/2007/03/14/voipsa-releases-its-voip-security-tools-list/</link>
		<comments>http://voipsa.org/blog/2007/03/14/voipsa-releases-its-voip-security-tools-list/#comments</comments>
		<pubDate>Wed, 14 Mar 2007 14:28:09 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VoIP Security Tools]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2007/03/14/voipsa-releases-its-voip-security-tools-list/</guid>
		<description><![CDATA[I&#8217;m pleased to announce the public release of VOIPSA&#8217;s VoIP Security Tool List.  The list was developed to address the current void of VoIP security testing resources and sites, for vendors and VoIP users alike.  The list is separated into the following seven broad categories:

VoIP Sniffing Tools
VoIP Scanning and Enumeration Tools
VoIP Packet Creation [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m pleased to announce the public release of VOIPSA&#8217;s <a href="http://www.voipsa.org/Resources/tools.php" target="_blank">VoIP Security Tool List</a>.  The list was developed to address the current void of VoIP security testing resources and sites, for vendors and VoIP users alike.  The list is separated into the following seven broad categories:</p>
<ul>
<li>VoIP Sniffing Tools</li>
<li>VoIP Scanning and Enumeration Tools</li>
<li>VoIP Packet Creation and Flooding Tools</li>
<li>VoIP Fuzzing Tools</li>
<li>VoIP Signaling Manipulation Tools</li>
<li>VoIP Media Manipulation Tools</li>
<li>Miscellaneous Tools</li>
</ul>
<p>Special thanks to VOIPSA members <a href="http://voipsa.org/blog/author/shawnmer/" target="_blank">Shawn Merdinger</a> and <a href="http://voipsa.org/blog/author/dtrammell/" target="_blank">Dustin Trammell</a> who created the list and have graciously agreed to maintain it. For more information about the tools list, you can listen to Dan York and Jonathan Zar discuss it in Blue Box Podcast #54 and also with Shawn Merdinger in Blue Box Special Edition #16 available at <a href="http://www.blueboxpodcast.com" target="_blank">http://www.blueboxpodcast.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2007/03/14/voipsa-releases-its-voip-security-tools-list/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Phone &#8220;Phreakers&#8221; Steal Minutes</title>
		<link>http://voipsa.org/blog/2007/03/12/phone-phreakers-steal-minutes/</link>
		<comments>http://voipsa.org/blog/2007/03/12/phone-phreakers-steal-minutes/#comments</comments>
		<pubDate>Mon, 12 Mar 2007 14:54:29 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Attacks in the News]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2007/03/12/phone-phreakers-steal-minutes/</guid>
		<description><![CDATA[The March 19th edition of NewsWeek has an article about cyber thieves stealing VoIP minutes by hacking into VoIP providersâ€™ gateways. Itâ€™s the first time Iâ€™ve actually seen real numbers applied to VoIP theft:
&#8216;These thieves steal 200 million minutes a month, worth $26 million, says New York telecom Stealth Communications. With more than 5,000 wholesale-minutes [...]]]></description>
			<content:encoded><![CDATA[<p>The March 19th edition of NewsWeek has an <a target="_blank" href="http://www.msnbc.msn.com/id/17553800/site/newsweek/">article about cyber thieves stealing VoIP minutes</a> by hacking into VoIP providersâ€™ gateways. Itâ€™s the first time Iâ€™ve actually seen real numbers applied to VoIP theft:</p>
<blockquote><p>&#8216;These thieves steal 200 million minutes a month, worth $26 million, says New York telecom Stealth Communications. With more than 5,000 wholesale-minutes markets worldwide, located mainly on Internet forums, fraud is hard to track. Emmanuel Gadaix, head of TSTF, a Hong Kong firm that investigates VoIP thefts, says it&#8217;s &#8220;very easy to set up a temporary link&#8221; through a hacked gateway. His company was recently hired by a Panamanian telecom that lost $110,000 to phreakers. TSTF followed tracks, in vain, that snaked through Bulgaria, Canada, Costa Rica, Hong Kong and the United States. Phreaker trails are &#8220;way too complicated&#8221; to track successfully, says Gadaix.&#8217;</p></blockquote>
<p class="MsoPlainText">
<p class="MsoPlainText">This brings up memories of the <a target="_blank" href="http://www.infoworld.com/article/06/06/07/79053_HNvoiphack_1.html">Edwin Pena case</a>, in which he was able to rake in over $1 million USD in profits from stealing and reselling VoIP minutes from several providers.</p>
<p class="MsoPlainText">Does anyone know for sure how these VoIP provider gateways are being broken into?  Default passwords?  Well known vulnerabilities in the operating system?  Stolen  access codes?</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2007/03/12/phone-phreakers-steal-minutes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>New VoIP Phishing Scheme</title>
		<link>http://voipsa.org/blog/2007/03/08/new-voip-phishing-scheme/</link>
		<comments>http://voipsa.org/blog/2007/03/08/new-voip-phishing-scheme/#comments</comments>
		<pubDate>Thu, 08 Mar 2007 21:55:46 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Attacks in the News]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2007/03/08/new-voip-phishing-scheme/</guid>
		<description><![CDATA[Brian Krebs from the Washington Post reports on a new VoIP Phishing (Vishing) scheme targeting Bank of America customers.  The scam appears as an official looking Bank of America email and tries to convince the victim to dial a toll free number to sort out some account problems.  Once the victim dials that [...]]]></description>
			<content:encoded><![CDATA[<p>Brian Krebs from the Washington Post <a target="_blank" href="http://blog.washingtonpost.com/securityfix/2007/03/vishing_dialing_for_dollars_pa_1.html">reports on a new VoIP Phishing (Vishing) scheme</a> targeting Bank of America customers.  The scam appears as an official looking Bank of America email and tries to convince the victim to dial a toll free number to sort out some account problems.  Once the victim dials that number, they&#8217;re prompted to enter in their account number and secret pin number.  The evil doers are then able to easily access the bogus system and reconstruct all of the numbers you entered. Much like how traditional email phishing attacks flourished in the last couple of years, I absolutely believe that VoIP Phishing scams will skyrocket this year.</p>
<p>For some background, there was a compelling presentation at last year&#8217;s BlackHat security conference by Jay Schulman, entitled <a target="_blank" href="http://www.blackhat.com/presentations/bh-usa-06/BH-US-06-Schulman.pdf">Phishing with Asterisk (PDF)</a>.  In his presentation, Jay showed how easy it was for attackers to use Asterisk PBX to set up a spoofed banking automated attendant and route all calls to a toll free number through to that PBX.  Additionally, Mark Collier and I devoted an entire chapter to VoIP Phishing in our book, <a target="_blank" href="http://www.hackingvoip.com">Hacking Exposed: VoIP</a>.</p>
<p>I&#8217;ve included a snapshot below of one of the first VoIP Phishing emails targeting PayPal that emerged last year that we showcased in our book.  Click on it to see the larger image.</p>
<p><a href="http://www.hackingvoip.com/presentations/paypal_vishing.jpg"><img width="50%" src="http://www.hackingvoip.com/presentations/paypal_vishing.jpg" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2007/03/08/new-voip-phishing-scheme/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype Protocol Cracked?</title>
		<link>http://voipsa.org/blog/2006/07/14/skype-protocol-cracked/</link>
		<comments>http://voipsa.org/blog/2006/07/14/skype-protocol-cracked/#comments</comments>
		<pubDate>Fri, 14 Jul 2006 15:41:54 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2006/07/14/skype-protocol-cracked/</guid>
		<description><![CDATA[Several news sources are reporting that an unnamed 10-person Chinese company has successfully reverse engineered the Skype protocol.  This company is supposedly planning to release their own software in two weeks that take advantage of Skype&#8217;s networks.
The main source of this information seems to be from the blog posting of Charlie Paglee, the CEO [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" src="http://www.skype.com/i/logos/skype_logo.png" />Several news sources are reporting that an unnamed 10-person Chinese company has successfully reverse engineered the Skype protocol.  This company is supposedly planning to release their own software in two weeks that take advantage of Skype&#8217;s networks.</p>
<p>The main source of this information seems to be from the <a target="_blank" href="http://www.voipwiki.com/blog/?p=16">blog posting of Charlie Paglee</a>, the CEO of Vozin Communications.  The posting details a Skype call Paglee supposedly received from his Chinese contact at this unnamed company, through a non-Skype client.  Several news outlets reporting on this:</p>
<p><a target="_blank" href="http://www.vnunet.com/vnunet/news/2160383/skype-protocol-hacked">VuNet</a><a target="_blank" href="http://www.vnunet.com/vnunet/news/2160383/skype-protocol-hacked"><br />
</a><a target="_blank" href="http://www.networkworld.com/news/2006/071406-chinese-company-claims-skype-protocol.html">NetworkWorld</a><br />
<a target="_blank" href="http://www.vnunet.com/vnunet/news/2160383/skype-protocol-hacked" /><a target="_blank" href="http://www.techworld.com/security/news/index.cfm?newsID=6451&#038;pagtype=all">TechWorld<br />
</a><a target="_blank" href="http://www.securitypronews.com/insiderreports/insider/spn-49-20060714SkypeCrackedInChina.html">SecurityProNews</a><a target="_blank" href="http://www.vnunet.com/vnunet/news/2160383/skype-protocol-hacked"><br />
</a></p>
<p>So far, no mention of this on <a target="_blank" href="http://share.skype.com/sites/security/">Skype&#8217;s security blog</a>.<br />
<a target="_blank" href="http://www.vnunet.com/vnunet/news/2160383/skype-protocol-hacked" /></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2006/07/14/skype-protocol-cracked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cisco Unified CallManager Vulnerabilities</title>
		<link>http://voipsa.org/blog/2006/07/12/cisco-unified-callmanager-vulnerabilities/</link>
		<comments>http://voipsa.org/blog/2006/07/12/cisco-unified-callmanager-vulnerabilities/#comments</comments>
		<pubDate>Wed, 12 Jul 2006 17:51:20 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VoIP Vulnerabilities]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2006/07/12/cisco-unified-callmanager-vulnerabilities/</guid>
		<description><![CDATA[Cisco announced vulnerabilities today in Unified CallManager versions 5.x:
Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI) 	 and Session Initiation Protocol (SIP) related vulnerabilities. There are 	 potential privilege escalation vulnerabilities in the CLI which may allow an 	 authenticated administrator to access the base operating system with root 	 privileges. There is [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco <a target="_blank" href="http://www.cisco.com/en/US/products/products_security_advisory09186a00806e0b9f.shtml">announced vulnerabilities</a> today in <a target="_blank" href="http://www.cisco.com/en/US/products/sw/voicesw/ps556/index.html">Unified CallManager</a> versions 5.x:</p>
<blockquote><p><span class="content">Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI) 	 and Session Initiation Protocol (SIP) related vulnerabilities. There are 	 potential privilege escalation vulnerabilities in the CLI which may allow an 	 authenticated administrator to access the base operating system with root 	 privileges. There is also a buffer overflow vulnerability in the processing of 	 hostnames contained in a SIP request which may result in arbitrary code 	 execution or cause a denial of service. These vulnerabilities only affect Cisco 	 Unified CallManager 5.0.</span></p></blockquote>
<p>The remote code execution SIP vulnerability is obviously the most concerning of all of these issues.Â  Luckily, it looks like the issue was discovered internally, which means an exploit may not publicly emerge for a while since Cisco&#8217;s advisory lacks detail on the actual malformed SIP message required to trigger the flaw.</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2006/07/12/cisco-unified-callmanager-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype security</title>
		<link>http://voipsa.org/blog/2006/06/22/skype-security/</link>
		<comments>http://voipsa.org/blog/2006/06/22/skype-security/#comments</comments>
		<pubDate>Thu, 22 Jun 2006 14:51:57 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VoIP Security Research]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2006/06/22/skype-security/</guid>
		<description><![CDATA[RECON (Reverse Engineering Conference) was recently held from June 16-18 in Montreal.  One of the presentations involved some in-depth Skype reverse engineering and analysis.  The slides for the presentation are available in pdf format for part1 and part2.  Among other things, the talk covered Skype&#8217;s crypto scheme, easter eggs, and general traffic [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.recon.cx/">RECON</a> (<strong>R</strong>everse <strong>E</strong>ngineering <strong>Con</strong>ference) was recently held from June 16-18 in Montreal.  One of the <a target="_blank" href="http://www.recon.cx/en/s/vskype.html">presentations</a> involved some in-depth Skype reverse engineering and analysis.  The slides for the presentation are available in pdf format for <a target="_blank" href="http://www.recon.cx/en/f/vskype-part1.pdf">part1</a> and <a target="_blank" href="http://www.recon.cx/en/f/vskype-part2.pdf">part2</a>.  Among other things, the talk covered Skype&#8217;s crypto scheme, easter eggs, and general traffic analysis.  Worth a read.</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2006/06/22/skype-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Internet pioneers speak out on VoIP wiretapping</title>
		<link>http://voipsa.org/blog/2006/06/14/internet-pioneers-say-voip-wiretapping-complicated/</link>
		<comments>http://voipsa.org/blog/2006/06/14/internet-pioneers-say-voip-wiretapping-complicated/#comments</comments>
		<pubDate>Wed, 14 Jun 2006 15:27:50 +0000</pubDate>
		<dc:creator>David Endler</dc:creator>
				<category><![CDATA[CALEA]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2006/06/14/internet-pioneers-say-voip-wiretapping-complicated/</guid>
		<description><![CDATA[As a followup to Dustin Trammell&#8217;s posting about CALEA compliance, the Information Technology Association of America released a report today entitled Security Implications of Applying the Communications Assistance to Law Enforcement Act to Voice over IP.  To quote from a an InfoWorld article covering the report:

The study, co-authored by several people including TCP/IP co-creator [...]]]></description>
			<content:encoded><![CDATA[<p>As a followup to Dustin Trammell&#8217;s <a target="_blank" href="http://voipsa.org/blog/2006/06/13/voip-providers-must-adhere-to-calea-by-next-may-14/">posting about CALEA compliance</a>, the <span class="artText">Information Technology Association of America released a report today entitled <a target="_blank" href="http://www.itaa.org/isec/headline.cfm?ID=2322">Security Implications of Applying the Communications Assistance to Law Enforcement Act to Voice over IP</a>.  To quote from a an <a target="_blank" href="http://www.infoworld.com/article/06/06/13/79252_HNvoipwiretapworry_1.html">InfoWorld article</a> covering the report:</span></p>
<blockquote><p><span class="artText" /></p>
<p class="ArticleBody">The study, co-authored by several people including TCP/IP co-creator Vinton Cerf and former U.S. National Security Agency encryption scientist Clinton Brooks, comes days after a U.S. appeals court upheld the FCC&#8217;s VOIP wiretapping rules. On Friday, the U.S. Court of Appeals for the District of Columbia upheld the ruling, requiring that VOIP providers offering a substitute for traditional telephone service comply with a 1994 telephone wiretapping law called the Communications Assistance for Law Enforcement Act (CALEA).</p>
<p class="ArticleBody">The FCC did not immediately respond to a request for comments about the ITAA study. But on Friday, FCC Chairman Kevin Martin said allowing law enforcement wiretapping of VOIP calls is of &#8220;paramount importance&#8221; to U.S. security.</p>
<p class="ArticleBody">Tracking VOIP calls would be more difficult than tracking calls on the traditional telephone network, because VOIP providers have little control over how their calls are routed across the Internet, said Whitfield Diffie, chief security officer at Sun Microsystems Inc. VOIP providers &#8220;have no special Internet privileges&#8221; to control traffic, said Diffie, one of the study&#8217;s authors.</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2006/06/14/internet-pioneers-say-voip-wiretapping-complicated/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
