<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Voice of VOIPSA &#187; IETF</title>
	<atom:link href="http://voipsa.org/blog/category/ietf/feed/" rel="self" type="application/rss+xml" />
	<link>http://voipsa.org/blog</link>
	<description>Collective thoughts and musings on the state of VoIP security today.</description>
	<lastBuildDate>Wed, 25 Apr 2012 14:58:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<cloud domain='voipsa.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Internet-Draft out about ICMP attacks against TCP</title>
		<link>http://voipsa.org/blog/2010/02/01/internet-draft-out-about-icmp-attacks-against-tcp/</link>
		<comments>http://voipsa.org/blog/2010/02/01/internet-draft-out-about-icmp-attacks-against-tcp/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 16:01:26 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/?p=853</guid>
		<description><![CDATA[While this isn&#8217;t about VoIP, per se, there&#8217;s a new version of an Internet-Draft out, draft-ietf-tcpm-icmp-attacks, about how ICMP can be used to attack TCP. The abstract is: This document discusses the use of the Internet Control Message Protocol (ICMP) to perform a variety of attacks against the Transmission Control Protocol (TCP). Additionally, describes a [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/02/ietflogo-1.jpg" alt="ietflogo-1.jpg" border="0" width="151" height="85" align="right" />While this isn&#8217;t about <em>VoIP</em>, per se, there&#8217;s a new version of an Internet-Draft out, <a href="http://tools.ietf.org/html/draft-ietf-tcpm-icmp-attacks-10">draft-ietf-tcpm-icmp-attacks</a>, about how ICMP can be used to attack TCP. The abstract is:</p>
<blockquote><p><em>This document discusses the use of the Internet Control Message<br />
   Protocol (ICMP) to perform a variety of attacks against the<br />
   Transmission Control Protocol (TCP).  Additionally, describes a<br />
   number of widely implemented modifications to TCP&#8217;s handling of ICMP<br />
   error messages that help to mitigate these issues.</em></p></blockquote>
<p>The document has been around in the IETF space since 2005, but is now moving further down the path toward being issued as an RFC.  Seems to be a solid doc for people wanting to understand ICMP attacks.</p>
<hr />
<p><em>If you found this post interesting or helpful, please consider either <a href="http://feeds2.feedburner.com/VoiceOfVoipsa">subscribing via RSS</a> or <a href="http://twitter.com/voipsa">following VOIPSA on Twitter</a>.</em></p>
<hr />
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2010/02/01/internet-draft-out-about-icmp-attacks-against-tcp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5th Emergency Services Workshop to be held Oct 21-23 in Vienna</title>
		<link>http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/</link>
		<comments>http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/#comments</comments>
		<pubDate>Tue, 07 Oct 2008 11:32:37 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/?p=525</guid>
		<description><![CDATA[How does an emergency call to 9-1-1 or 1-1-2 (or whatever your local emergency number may be) work in a world of voice-over-IP? It&#8217;s not a topic we cover hardly at all here on this blog, yet it&#8217;s definitely one of the security and social/cultural aspects of our migration to IP that we definitely have [...]]]></description>
			<content:encoded><![CDATA[<p>How does an emergency call to 9-1-1 or 1-1-2 (or whatever your local emergency number may be) work in a world of voice-over-IP?</p>
<p>It&#8217;s not a topic we cover hardly at all here on this blog, yet it&#8217;s definitely one of the security and social/cultural aspects of our migration to IP that we definitely have to get right.  If we as an industry don&#8217;t, people can die. (Or the migration to VoIP will be significantly delayed.)</p>
<p>To that end, a number of emergency services experts are meeting to discuss ongoing work on IP-based emergency services <em>in Vienna, Austria on 21st to 23rd October 2008</em>. The first workshop day is focusing on tutorials to help those interested in the classical 1-1-2 (or 9-1-1) emergency call to get up-to-speed with architectures and standards developed for next generation emergency calling. During the second day various recent activities of standardization organizations around the world will be presented. The third workshop day is dedicated to early warning standardization efforts and the outlook to future emergency services activities.</p>
<p>Participation from those working in standardization organizations as well as persons with interest into the subject is highly appreciated. The event is open to the public and anyone may attend.<br />
For socializing an evening program has been organized. There is a nominal fee of 120 Euros charged to cover the facilities cost, food, drinks, etc.  Arrangements are also being made for participants to join remotely.</p>
<p>More information about the workshop can be found behind the following link:</p>
<blockquote><p><em><a href="http://www.emergency-services-coordination.info/esw5.html">http://www.emergency-services-coordination.info/esw5.html</a></em></p></blockquote>
<p>This page also points to previous workshops that took place in New York, Washington, Brussels and Atlanta.</p>
<p><em>(Thanks to Hannes Tschofenig for providing the majority of this text.)</em></p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/emergency" rel="tag">emergency</a>, <a href="http://technorati.com/tag/911" rel="tag">911</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/sip" rel="tag">sip</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>, <a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US government rolling out largest DNSSEC deployment</title>
		<link>http://voipsa.org/blog/2008/09/22/us-government-rolling-out-largest-dnssec-deployment/</link>
		<comments>http://voipsa.org/blog/2008/09/22/us-government-rolling-out-largest-dnssec-deployment/#comments</comments>
		<pubDate>Mon, 22 Sep 2008 20:40:49 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Standards]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/?p=501</guid>
		<description><![CDATA[It&#8217;s not &#8220;VoIP security&#8221;-related, but this piece in NetworkWorld today is worth a read: &#8220;Feds tighten security on .gov&#8220;. Here&#8217;s the intro: When you file your taxes online, you want to be sure that the Web site you visit &#8212; www.irs.gov &#8212; is operated by the Internal Revenue Service and not a scam artist. By [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s not &#8220;VoIP security&#8221;-related, but this piece in NetworkWorld today is worth a read: &#8220;<em><a href="http://www.networkworld.com/news/2008/092208-government-web-security.html">Feds tighten security on .gov</a></em>&#8220;. Here&#8217;s the intro:<br />
<blockquote><em>When you file your taxes online, you want to be sure that the Web site you visit &#8212; www.irs.gov &#8212; is operated by the Internal Revenue Service and not a scam artist. By the end of next year, you can be confident that every U.S. government Web page is being served up by the appropriate agency.</p>
<p>That’s because the feds have launched the largest-ever rollout of a new authentication mechanism for the Internet’s DNS. All federal agencies are deploying DNS Security Extensions (DNSSEC) on the .gov top-level domain, and some expect that once that rollout is complete, banks and other businesses might be encouraged to follow suit for their sites. </em></p></blockquote>
<p>The article goes on at some length into what the US government is doing, the issues involved and why it all matters.   From a larger &#8220;Internet infrastructure&#8221; point-of-view, actions such as securing the DNS infrastructure will only help in securing services such as VoIP.  There&#8217;s still a long way to go to getting DNSSEC widely available, but I applaud the US government for helping push efforts along.</p>
<p>FYI, the article references the  obsolete RFC 2065 for DNSSEC. For those wishing the read the standard itself, DNSSEC is now defined in RFC&#8217;s <a href="http://tools.ietf.org/rfcmarkup/4033">4033</a>, <a href="http://tools.ietf.org/rfcmarkup/4034">4034</a> and <a href="http://tools.ietf.org/rfcmarkup/4035">4035</a> with a bit of an update in RFC <a href="http://tools.ietf.org/rfcmarkup/4470">4470</a>.</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/internet" rel="tag">internet</a>, <a href="http://technorati.com/tag/dns" rel="tag">dns</a>, <a href="http://technorati.com/tag/dnssec" rel="tag">dnssec</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/09/22/us-government-rolling-out-largest-dnssec-deployment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Info on how to listen remotely to today&#8217;s RUCUS session at IETF</title>
		<link>http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/</link>
		<comments>http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 11:46:54 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/</guid>
		<description><![CDATA[If you are interested in listening in to today&#8217;s session here at IETF about &#8220;Reducing Unwanted Communications Using SIP&#8221; (RUCUS) which I&#8217;ve mentioned previously, I&#8217;ve posted information about how to participate in IETF remotely. The RUCUS session takes place from 1300-1500 US Eastern time today. Streaming audio should be available on ietf71-ch4. Jabber group chat [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/02/ietflogo-1.jpg" alt="ietflogo-1.jpg" border="0" width="151" height="85" align="right" />If you are interested in listening in to today&#8217;s session here at IETF about <a href="http://www.shingou.info/bof-rucus.html">&#8220;Reducing Unwanted Communications Using SIP&#8221; (RUCUS)</a> which I&#8217;ve mentioned previously, <a href="http://blogs.voxeo.com/speakingofstandards/2008/03/09/how-to-participate-in-ietf-71-remotely-through-real-time-audio-and-im-groupchat/">I&#8217;ve posted information about how to participate in IETF remotely</a>. The RUCUS session takes place from 1300-1500 US Eastern time today.  </p>
<p><a href="http://videolab.uoregon.edu/events/ietf/">Streaming audio</a> should be available on <a href="http://videolab.uoregon.edu/events/ietf/ietf714.m3u">ietf71-ch4</a>. </p>
<p>Jabber group chat should be available as well, but I don&#8217;t know yet in which chat room it will be.  There isn&#8217;t yet a chat room on the IETF server for &#8216;rucus&#8217;.  I&#8217;ll update this post once I know where the chat room is.</p>
<p><strong>UPDATE</strong>: A request is in to create the &#8216;rucus@jabber.ietf.org&#8217; room.  If that room isn&#8217;t created in time, we&#8217;ll use the SIPPING room at &#8216;sipping@jabber.ietf.org&#8217;.  We&#8217;ll announce on the streaming audio which one we are using.</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br /><a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a></p>
<p><!-- Technorati Tags End --></p>
<p><font style="position: absolute;overflow: hidden;height: 0;width: 0"><br />
<a href="http://www.bigbadbookblog.com/?menu=1" title="buy viagra">buy viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=2" title="buy viagra online">buy viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=3" title="viagra online">viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=4" title="discount viagra">discount viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=5" title="order viagra">order viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=6" title="cheap viagra">cheap viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=7" title="generic viagra">generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=8" title="generica viagra">generica viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=9" title="viagra buy">viagra buy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=10" title="viagra price">viagra price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=11" title="order viagra online">order viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=12" title="viagra generic">viagra generic</a><br />
<a href="http://www.bigbadbookblog.com/?menu=13" title="viagra pill">viagra pill</a><br />
<a href="http://www.bigbadbookblog.com/?menu=14" title="where buy viagra">where buy viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=15" title="buy viagra cheap">buy viagra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=16" title="viagra order">viagra order</a><br />
<a href="http://www.bigbadbookblog.com/?menu=17" title="get viagra">get viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=18" title="buy online viagra">buy online viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=19" title="online viagra">online viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=20" title="viagra sale online">viagra sale online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=21" title="where to buy viagra">where to buy viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=22" title="cheapest viagra">cheapest viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=23" title="purchase viagra">purchase viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=24" title="cheap viagra online">cheap viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=25" title="viagra buy online">viagra buy online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=26" title="buying viagra">buying viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=27" title="buy viagra on">buy viagra on</a><br />
<a href="http://www.bigbadbookblog.com/?menu=28" title="generic viagra canada">generic viagra canada</a><br />
<a href="http://www.bigbadbookblog.com/?menu=29" title="prescription viagra">prescription viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=30" title="buy viagra norway">buy viagra norway</a><br />
<a href="http://www.bigbadbookblog.com/?menu=31" title="generic viagra pack">generic viagra pack</a><br />
<a href="http://www.bigbadbookblog.com/?menu=32" title="buy viagra in nevada">buy viagra in nevada</a><br />
<a href="http://www.bigbadbookblog.com/?menu=33" title="buy viagra now online">buy viagra now online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=34" title="viagra online buy">viagra online buy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=35" title="find viagra online">find viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=36" title="buy cheap viagra online">buy cheap viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=37" title="cheap generic viagra">cheap generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=38" title="buy cheap viagra">buy cheap viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=39" title="generic viagra online">generic viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=40" title="viagra sale">viagra sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=41" title="generic viagra cheap">generic viagra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=42" title="buy viagra on line">buy viagra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=43" title="where buy generic viagra">where buy generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=44" title="viagra online bestellen">viagra online bestellen</a><br />
<a href="http://www.bigbadbookblog.com/?menu=45" title="viagra prescription online">viagra prescription online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=46" title="generic online viagra">generic online viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=47" title="low price viagra">low price viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=48" title="cheapest viagra price">cheapest viagra price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=49" title="buy generic viagra">buy generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=50" title="viagra uk">viagra uk</a><br />
<a href="http://www.bigbadbookblog.com/?menu=51" title="viagra online prescription">viagra online prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=52" title="cheap est viagra">cheap est viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=53" title="viagra soft tab">viagra soft tab</a><br />
<a href="http://www.bigbadbookblog.com/?menu=54" title="viagra discount">viagra discount</a><br />
<a href="http://www.bigbadbookblog.com/?menu=55" title="viagra cheap">viagra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=56" title="where to buy viagra on line">where to buy viagra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=57" title="buying viagra online">buying viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=58" title="buy viagra now">buy viagra now</a><br />
<a href="http://www.bigbadbookblog.com/?menu=59" title="purchase viagra online">purchase viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=60" title="viagra pharmacy">viagra pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=61" title="natural viagra">natural viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=62" title="buy viagra in canada">buy viagra in canada</a><br />
<a href="http://www.bigbadbookblog.com/?menu=63" title="viagra paypal">viagra paypal</a><br />
<a href="http://www.bigbadbookblog.com/?menu=64" title="viagra on line">viagra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=65" title="viagra 100mg">viagra 100mg</a><br />
<a href="http://www.bigbadbookblog.com/?menu=66" title="viagra without prescription">viagra without prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=67" title="cheapest place to buy viagra online">cheapest place to buy viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=68" title="generic Cialis">generic Cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=69" title="buy cialis">buy cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=70" title="buy cialis online">buy cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=71" title="cialis online">cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=72" title="online cialis">online cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=73" title="order cialis">order cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=74" title="cheap cialis">cheap cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=75" title="discount Cialis">discount Cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=76" title="generic cialis price">generic cialis price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=77" title="cialis prescription">cialis prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=78" title="buy cialis generic">buy cialis generic</a><br />
<a href="http://www.bigbadbookblog.com/?menu=79" title="cialis online discount">cialis online discount</a><br />
<a href="http://www.bigbadbookblog.com/?menu=80" title="cheapest cialis">cheapest cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=81" title="buy discount cialis">buy discount cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=82" title="purchase cheap cialis online">purchase cheap cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=83" title="order cialis online">order cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=84" title="cialis for sale">cialis for sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=85" title="cialis price">cialis price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=86" title="purchase cialis">purchase cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=87" title="cialis online pharmacy">cialis online pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=88" title="buy Cheap Cialis">buy Cheap Cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=89" title="cialis story">cialis story</a><br />
<a href="http://www.bigbadbookblog.com/?menu=90" title="generic cialis online">generic cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=91" title="best cialis price">best cialis price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=92" title="cheapest cialis generic">cheapest cialis generic</a><br />
<a href="http://www.bigbadbookblog.com/?menu=93" title="order generic cialis">order generic cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=94" title="low cost cialis">low cost cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=95" title="buy cialis generic online">buy cialis generic online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=96" title="levitra">levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=97" title="buy levitra">buy levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=98" title="cheap levitra">cheap levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=99" title="levitra online">levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=100" title="buy levitra online">buy levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=101" title="order levitra">order levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=102" title="order levitra online">order levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=103" title="cialis levitra">cialis levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=104" title="generic levitra">generic levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=105" title="online levitra">online levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=106" title="buy cheap levitra">buy cheap levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=107" title="discount levitra">discount levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=108" title="levitra sale">levitra sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=109" title="buy generic levitra">buy generic levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=110" title="levitra online pharmacy">levitra online pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=111" title="levitra price">levitra price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=112" title="purchase levitra">purchase levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=113" title="cheap levitra online">cheap levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=114" title="levitra story">levitra story</a><br />
<a href="http://www.bigbadbookblog.com/?menu=115" title="levitra on line">levitra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=116" title="levitra prescription">levitra prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=117" title="levitra cheap">levitra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=118" title="best price for levitra">best price for levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=119" title="buy xanax">buy xanax</a><br />
<a href="http://www.bigbadbookblog.com/?menu=120" title="buy phentermine">buy phentermine</a><br />
<a href="http://www.bigbadbookblog.com/?menu=121" title="buy lasix">buy lasix</a><br />
<a href="http://www.bigbadbookblog.com/?menu=122" title="tramadol">tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=123" title="buy tramadol">buy tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=124" title="buy tramadol online">buy tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=125" title="tramadol online">tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=126" title="cheap tramadol">cheap tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=127" title="order tramadol">order tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=128" title="tramadol hcl">tramadol hcl</a><br />
<a href="http://www.bigbadbookblog.com/?menu=129" title="ultram tramadol">ultram tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=130" title="tramadol prescription">tramadol prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=131" title="online tramadol">online tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=132" title="tramadol sale">tramadol sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=133" title="purchase tramadol">purchase tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=134" title="buy cheap tramadol">buy cheap tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=135" title="order tramadol online">order tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=136" title="overnight tramadol">overnight tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=137" title="tramadol cheap">tramadol cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=138" title="tramadol pharmacy">tramadol pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=139" title="discount tramadol">discount tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=140" title="tramadol hydrochloride">tramadol hydrochloride</a><br />
<a href="http://www.bigbadbookblog.com/?menu=141" title="tramadol 50mg">tramadol 50mg</a><br />
<a href="http://www.bigbadbookblog.com/?menu=142" title="cheap tramadol online">cheap tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=143" title="generic tramadol">generic tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=144" title="buy clomid">buy clomid</a><br />
<a href="http://www.bigbadbookblog.com/?menu=145" title="buy prozac">buy prozac</a><br />
<a href="http://www.bigbadbookblog.com/?menu=146" title="buy cipro">buy cipro</a><br />
<a href="http://www.bigbadbookblog.com/?menu=147" title="buy diflucan">buy diflucan</a><br />
<a href="http://www.bigbadbookblog.com/?menu=148" title="buy acomplia">buy acomplia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=149" title="buy lexapro">buy lexapro</a><br />
<a href="http://www.bigbadbookblog.com/?menu=150" title="buy flagyl">buy flagyl</a><br />
<a href="http://www.bigbadbookblog.com/?menu=151" title="buy propecia">buy propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=152" title="order propecia">order propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=153" title="cheap propecia">cheap propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=154" title="propecia online">propecia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=155" title="order propecia online">order propecia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=156" title="buy propecia online">buy propecia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=157" title="generic propecia">generic propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=158" title="compare propecia">compare propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=159" title="propecia without prescription">propecia without prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=160" title="propecia prescription">propecia prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=161" title="propecia pill">propecia pill</a><br />
<a href="http://www.bigbadbookblog.com/?menu=162" title="discount propecia">discount propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=163" title="online propecia">online propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=164" title="cheapest propecia">cheapest propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=165" title="get propecia">get propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=166" title="propecia order">propecia order</a><br />
<a href="http://www.bigbadbookblog.com/?menu=167" title="propecia price">propecia price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=168" title="propecia uk">propecia uk</a><br />
<a href="http://www.bigbadbookblog.com/?menu=169" title="propecia cost">propecia cost</a><br />
<a href="http://www.bigbadbookblog.com/?menu=170" title="propecia sale">propecia sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=171" title="purchase propecia">purchase propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=172" title="buy cheap propecia">buy cheap propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=173" title="propecia sale online">propecia sale online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=174" title="buy online propecia">buy online propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=175" title="online pharmacy propecia">online pharmacy propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=176" title="online prescription propecia">online prescription propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=177" title="buy generic propecia">buy generic propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=178" title="buying propecia">buying propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=179" title="buy propecia now">buy propecia now</a><br />
<a href="http://www.bigbadbookblog.com/?menu=180" title="buy fosamax">buy fosamax</a><br />
<a href="http://www.bigbadbookblog.com/?menu=181" title="buy kamagra">buy kamagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=182" title="buy clomid online">buy clomid online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=183" title="buy prozac online">buy prozac online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=184" title="buy cipro online">buy cipro online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=185" title="buy diflucan online">buy diflucan online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=186" title="buy acomplia online">buy acomplia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=187" title="buy lexapro online">buy lexapro online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=188" title="buy flagyl online">buy flagyl online</a><br />
</font></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://videolab.uoregon.edu/events/ietf/ietf714.m3u" length="40" type="audio/x-mpegurl" />
		</item>
		<item>
		<title>Web page for RUCUS BOF at IETF 71 now at new URL</title>
		<link>http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/</link>
		<comments>http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/#comments</comments>
		<pubDate>Mon, 03 Mar 2008 18:07:58 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/</guid>
		<description><![CDATA[As I mentioned previously (here and here), the &#8220;RUCUS&#8221; BOF about voice spam at IETF 71 in Philadelphia is one of great interest with its focus on voice spam, a.k.a. &#8220;SPam for Internet Telephony&#8221; or &#8220;SPIT&#8221;. Unfortunately BOF co-chair Hannes Tschofenig ran into a problem with his domain and had to move the page to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/02/ietflogo-1.jpg" alt="ietflogo-1.jpg" border="0" width="151" height="85" align="right" />As I mentioned previously (<a href="http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/">here</a> and <a href="http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/">here</a>), the &#8220;RUCUS&#8221; BOF about voice spam at IETF 71 in Philadelphia is one of great interest with its focus on voice spam, a.k.a. &#8220;SPam for Internet Telephony&#8221; or &#8220;SPIT&#8221;. Unfortunately BOF co-chair Hannes Tschofenig ran into a problem with his domain and had to move the page to a new URL: <a href="http://www.shingou.info/bof-rucus.html">http://www.shingou.info/bof-rucus.html</a></p>
<p>If you saved the URL or sent it on to someone, you&#8217;ll need to update to using the new URL.  If you didn&#8217;t visit the RUCUS page before, please <a href="http://www.shingou.info/bof-rucus.html">do check it out</a> &#8211; and feel free to join <a href="https://www.ietf.org/mailman/listinfo/rucus">the RUCUS mailing list</a>. Of course, if you can, please do <a href="http://www.ietf.org/meetings/71-IETF.html">join us in person in Philadelphia</a>!</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>, <a href="http://technorati.com/tag/sip" rel="tag">sip</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join the new RUCUS mailing list if you want to look at ways to end SPIT!</title>
		<link>http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/</link>
		<comments>http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/#comments</comments>
		<pubDate>Fri, 15 Feb 2008 12:37:18 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/</guid>
		<description><![CDATA[As mentioned previously, there is a new session planned for IETF 71 in March called &#8220;Reducing Unwanted Communications Using SIP&#8220;, a.k.a. &#8220;RUCUS&#8221;. The RUCUS mailing list is now open for subscriptions and we encourage anyone interested in looking at how we address the issue of voice spam, aka &#8220;Spam for Internet Telephony&#8221; aka &#8220;SPIT&#8221; to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/01/imagesietflogo.jpg" alt="ietflogo.jpg" border="0" width="136" height="68" align="right" />As <a href="http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/">mentioned previously</a>, there is a new session planned for IETF 71 in March called &#8220;<a href="http://www.tschofenig.com/bof-rucus.html">Reducing Unwanted Communications Using SIP</a>&#8220;, a.k.a. &#8220;RUCUS&#8221;.</p>
<p>The <a href="http://www.ietf.org/mailman/listinfo/rucus">RUCUS mailing list is now open for subscriptions</a> and we encourage anyone interested in looking at how we address the issue of voice spam, aka &#8220;Spam for Internet Telephony&#8221; aka &#8220;SPIT&#8221; to <a href="http://www.ietf.org/mailman/listinfo/rucus">join into the conversation</a>.</p>
<p>We would ask you to please read <a href="http://www.tschofenig.com/bof-rucus.html">the group description</a> prior to joining so that you understand what we are trying to do. The primary goal of this session in March in Philadelphia is to look to understand the <em>architecture</em> necessary to address the issue and identify the pieces of that architecture that may already be there or may need to be put in place.</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/voice%20spam" rel="tag">voice spam</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>End-to-end VoIP security using DTLS-SRTP? (A new proposal&#8230;)</title>
		<link>http://voipsa.org/blog/2008/02/11/end-to-end-voip-security-using-dtls-srtp-a-new-proposal/</link>
		<comments>http://voipsa.org/blog/2008/02/11/end-to-end-voip-security-using-dtls-srtp-a-new-proposal/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 19:36:36 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/02/11/end-to-end-voip-security-using-dtls-srtp-a-new-proposal/</guid>
		<description><![CDATA[As we&#8217;ve discussed both here and on Blue Box, the issue of securing the keys for Secure RTP is one of the remaining challenges to have secure voice transmission in the open standards world of SIP. Out of the large number of proposals to secure the key exchange, &#8220;DTLS&#8221; emerged as the choice of the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ietf.org/"><img src="http://voipsa.org/blog/wp-content/uploads/2008/01/imagesietflogo.jpg" alt="ietflogo.jpg" border="0" width="271" height="139" align="right" /></a>As we&#8217;ve discussed both here and on<a href="http://www.blueboxpodcast.com/"> Blue Box</a>, the issue of securing the keys for Secure RTP is one of the remaining challenges to have secure voice transmission in the open standards world of SIP. Out of the large number of proposals to secure the key exchange, &#8220;DTLS&#8221; emerged as the choice of the IETF&#8230; but it still had the issue that an endpoint needed to be sure of the authenticity of the other endpoint&#8217;s certificate. SIP Identity (RFC 4474) and a draft &#8220;Identity-Media&#8221; from Dan Wing addressed the authenticity issue but broke in some common network configurations. Now Kai Fisher has put out an Internet Draft called &#8220;<em><a href="http://tools.ietf.org/rfcmarkup?doc=draft-fischer-sip-e2e-sec-media">End-to-End Security for DTLS-SRTP</a></em>&#8221; that proposes a mechanism to address that. In <a href="http://www.ietf.org/mail-archive/web/sip/current/msg21949.html">the post to the SIP mailing list</a>, Kai explains the motivation:<br />
<blockquote><em>I have submitted a draft proposing a solution to secure a DTLS-SRTP handshake and hence SRTP end-to-end (in terms of end-domain to end-domain). As discussed during the last IETF meetings and analyzed by Dan&#8217;s Identity-Media draft, current solutions like SIP Identity do not protect the authenticity of the fingerprint end-to-end in certain inter-domain scenarios. For example, a modification of SDP m-/c-lines or the From header field by intermediaries breaks the SIP-Identity or Identity-Media signature and causes a re-signing by a domain different to the originating one. The draft proposes a solution for such scenarios without the need to re-sign during domain traversal and which preserves the original identity information.</em></p></blockquote>
<p>The abstract to <a href="http://tools.ietf.org/rfcmarkup?doc=draft-fischer-sip-e2e-sec-media">the draft</a> provides more info:<br />
<blockquote><em>The end-to-end security properties of DTLS-SRTP depend on the authenticity of the certificate fingerprint exchanged in the signalling channel.  In current approaches the authenticity is protected by SIP-Identity or SIP-Identity-Media.  These types of signatures are broken if intermediaries like Session Border Controllers in other domains change specific information of the SIP header or the SIP body.  The end-to-end security property between the originating and terminating domain is lost if these intermediaries re-sign the SIP message and create a new identity signature using their own domain credentials.</p>
<p>This document defines a new signature type &#8216;Fingerprint-Identity&#8217; which is exchanged in the signalling channel.  Fingerprint-Identity covers only those elements of a SIP message necessary to authenticate the certificate fingerprint and to secure media end-to-end.  It is independent from SIP-Identity and SIP-Identity-Media and can be applied in parallel to them.</em></p></blockquote>
<p>More details can, of course, be found <a href="http://tools.ietf.org/rfcmarkup?doc=draft-fischer-sip-e2e-sec-media">in the draft</a>.  As noted in the post to the SIP mailing list, <a href="http://www.ietf.org/mail-archive/web/sip/current/msg21949.html">Kai is looking for feedback</a>.  This is an important issue to get done &#8211; and to get done <em>correctly</em> &#8211; so we strongly urge people to take a look at the document and provide feedback if you see ways the proposal can be improved.</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/SIP" rel="tag">SIP</a>, <a href="http://technorati.com/tag/SRTP" rel="tag">SRTP</a>, <a href="http://technorati.com/tag/IETF" rel="tag">IETF</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>, <a href="http://technorati.com/tag/sip%20security" rel="tag">sip security</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/DTLS" rel="tag">DTLS</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/02/11/end-to-end-voip-security-using-dtls-srtp-a-new-proposal/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Raising a RUCUS about SPIT at IETF 71!</title>
		<link>http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/</link>
		<comments>http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/#comments</comments>
		<pubDate>Mon, 04 Feb 2008 15:36:30 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/</guid>
		<description><![CDATA[UPDATE: The RUCUS mailing list is now open for subscription. Want to get together with others and discuss in further detail what we can do about Spam for Internet Telephony (SPIT)? A new session has been approved for the IETF 71 meeting coming up in Philadelphia in March called &#8220;Reducing Unwanted Communications using SIP&#8221; a.k.a. [...]]]></description>
			<content:encoded><![CDATA[<p><em>UPDATE:</em> <a href="http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/">The RUCUS mailing list is now open for subscription.</a></p>
<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/01/imagesietflogo.jpg" alt="ietflogo.jpg" border="0" width="136" height="68" align="right" />Want to get together with others and discuss in further detail what we can do about Spam for Internet Telephony (SPIT)?  A new session has been approved for <a href="http://www.ietf.org/meetings/71-IETF.html">the IETF 71 meeting</a> coming up in Philadelphia in March called &#8220;<em>Reducing Unwanted Communications using SIP</em>&#8221; a.k.a. &#8220;RUCUS&#8221; (Hey, it&#8217;s not a real IETF group until it has a cute acronym!) <a href="http://www.tschofenig.com/">Hannes Tschofenig</a>, who submitted the proposal, has created <a href="http://www.tschofenig.com/bof-rucus.html">a RUCUS web pag</a>e and is looking for feedback. The page says in part:<br />
<blockquote><em>The topic of dealing with unwanted traffic in SIP has surfaced several times in the IETF in the context of preventing Spam for Internet telephony. Previous attempts to have a structured discussion about this topic have (among other reasons) failed due to the strong focus on selected solution approaches.</p>
<p>Prior work in SIP on identity management has an important role in this activity since a strong identity mechanism in SIP has been seen as a prerequisity for establishing authorization policies. Hence, the &#8220;Discussion and Analysis of SIP Identity&#8221; (DASI) BoF is relevant for this event. Even though there is no direct dependency between the two activities the number of interested participants will quite likely overlap. </p>
<p>This BoF focuses on the discussion of architectural aspects. The underlying theme is that the work on building blocks is more fruitful once the larger framework is understood. A number of solutions components have been submitted to the IETF, have been published in the academic literature and found their way into other standardization bodies. Reduce unwanted communication requires authorization decisions to be made. These decisions can be made based on individual sessions but also on the interaction at a higher granularity (e.g., the interaction with a specific VoIP provider network). Examples of questions with relevance for an architecture might be: <br/><br />
- Where does information for decision making come from? <br/><br />
- What are useful information items for decision making? <br/><br />
- Where are policy decision points located? What about the placement of<br />
  policy enforcement points? <br/><br />
- Are privacy aspects to consider with the exchange of information? <br/><br />
- How does the underlying trust model look like? <br/><br />
- What assumptions are certain mechanisms based on? <br/><br />
- Can individual proposals be combined in a reasonable way?<br />
etc. </p>
<p>It is not the aim of the BoF to discuss specific solution approaches since it is likely that multiple techniques have to be used in concert.</em></p></blockquote>
<p>If you are attending IETF 71 in Philadelphia in March, do plan on joining in the RUCUS! (I&#8217;ll be there.)</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/voice%20spam" rel="tag">voice spam</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>An excellent overview of SIP security issues at the 3rd ETSI Security Workshop</title>
		<link>http://voipsa.org/blog/2008/01/16/an-excellent-overview-of-sip-security-issues-at-the-3rd-etsi-security-workshop/</link>
		<comments>http://voipsa.org/blog/2008/01/16/an-excellent-overview-of-sip-security-issues-at-the-3rd-etsi-security-workshop/#comments</comments>
		<pubDate>Wed, 16 Jan 2008 14:47:38 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/01/16/an-excellent-overview-of-sip-security-issues-at-the-3rd-etsi-security-workshop/</guid>
		<description><![CDATA[Hannes Tschofenig is over at the 3rd ETSI Security Workshop in France this week and yesterday gave a talk about SIP security. He has now posted the slides to his blog &#8211; My Slides from the 3rd ETSI Security Workshop: Yesterday I gave my presentation at the 3rd ETSI Security Workshop. My presentation title was [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.tschofenig.com/wp/">Hannes Tschofenig</a> is over at the <a href="http://portal.etsi.org/securityworkshop/Agenda08.asp">3rd ETSI Security Workshop</a> in France this week and yesterday gave a talk about SIP security. He has now posted the slides to his blog &#8211;  <a href="http://www.tschofenig.com/wp/?p=269">My Slides from the 3rd ETSI Security Workshop</a>:<br />
<blockquote><em>
<p>Yesterday I gave my presentation at the 3rd ETSI Security Workshop. My presentation title was â€˜IETF Securityâ€™ and that is obviously pretty fuzzy. After looking on the agenda I decided that the most useful topic to speak about would be SIP identity management and media security. In case you are interested in this topic, please take a look at the following <a href="http://www.tschofenig.com/wp/wp-content/uploads/2008/01/tschofenig-ietf-security.ppt" title="tschofenig-ietf-security.ppt">slide set</a>.</p>
<p></em></p></blockquote>
<p>His slide set does give an excellent overview of security issues in SIP, the various RFCs and approaches, etc. As he mentions, he focuses on identity and media security. A great contribution to the ongoing dialog on these issues.  In fact, much of the <a href="http://portal.etsi.org/securityworkshop/Agenda08.asp">workshop agenda</a> looks quite intriguing.  It will be interesting to see if other presenters make their slides available or if conclusions are posted anywhere.</p>
<p><em>Note to other presenters: If you do put your slides up somewhere, we&#8217;re glad to link to them here.  In fact, if you use <a href="http://www.slideshare.net/">SlideShare</a> (or a similar service), we&#8217;ll be glad to embed the presentations directly in this blog.</em></p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/sip" rel="tag">sip</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/hannes%20tschofenig" rel="tag">hannes tschofenig</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/01/16/an-excellent-overview-of-sip-security-issues-at-the-3rd-etsi-security-workshop/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>IETF seeking feedback on &#8220;Requirements from SIP Session Border Controller Deployments&#8221;</title>
		<link>http://voipsa.org/blog/2008/01/08/ietf-seeking-feedback-on-requirements-from-sip-session-border-controller-deployments/</link>
		<comments>http://voipsa.org/blog/2008/01/08/ietf-seeking-feedback-on-requirements-from-sip-session-border-controller-deployments/#comments</comments>
		<pubDate>Tue, 08 Jan 2008 21:35:08 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/01/08/ietf-seeking-feedback-on-requirements-from-sip-session-border-controller-deployments/</guid>
		<description><![CDATA[The IETF leadership recently announced that they are seeking final comments on an Internet-Draft called &#8220;Requirements from SIP Session Border Controller Deployments&#8221; (current draft also available here) as they decide whether to move this document to an Informational RFC. The abstract of the document is as follows: This document describes functions implemented in Session Initiation [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/01/imagesietflogo.jpg" alt="ietflogo.jpg" border="0" width="180" height="92" align="right" />The IETF leadership recently <a href="http://www.ietf.org/internet-drafts/draft-ietf-sipping-sbc-funcs-04.txt">announced that they are seeking final comments</a> on an Internet-Draft called &#8220;<a href="https://datatracker.ietf.org/drafts/draft-ietf-sipping-sbc-funcs/">Requirements from SIP Session Border Controller Deployments</a>&#8221; (current draft also available <a href="http://www.ietf.org/internet-drafts/draft-ietf-sipping-sbc-funcs-04.txt">here</a>) as they decide whether to move this document to an Informational RFC. The abstract of the document is as follows:</p>
<blockquote><p><em>This document describes functions implemented in Session Initiation Protocol (SIP) intermediaries known as Session Border Controllers (SBCs). The goal of this document is to describe the commonly provided functions of SBCs. A special focus is given to those practices that are viewed to be in conflict with SIP architectural principles. This document also explores the underlying requirements of network operators that have led to the use of these functions and practices in order to identify protocol requirements and determine whether those requirements are satisfied by existing specifications or additional standards work is required. </em></p></blockquote>
<p>If you work with SBCs, use them in your networks, or work for a SBC vendor, now is a good time to ensure that this document captures the requirements you have for deploying SBCs. Once finalized as an Informational RFC, the idea is that it will be used to assist in the potential creation of new SIP-related standards or the modification of existing standards.  Now is the time to voice your opinion (and the <a href="http://www.ietf.org/internet-drafts/draft-ietf-sipping-sbc-funcs-04.txt">note from the IETF</a> explains how to do that).  Comments have been requested to be received by January 16, 2008.</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/session%20border%20controllers" rel="tag">session border controllers</a>, <a href="http://technorati.com/tag/sbcs" rel="tag">sbcs</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/01/08/ietf-seeking-feedback-on-requirements-from-sip-session-border-controller-deployments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

