[VOIPSEC] SIP Security
Martyn.Davies at eicon.com
Wed Nov 16 16:50:02 GMT 2005
Testing with Ethereal, I was mildly alarmed* to see that changes of presence information and instant messages from Windows Messenger are sent "clear" so that anyone monitoring the net can pick this information up. The same seems to be true of GoogleTalk.
Does anyone here have any opinion on whether Voipsa should concern itself with the security of Instant Messaging & Presence? After all, SIP itself contains a mechanism to support these (SIMPLE), in addition to the telephony signalling services. I should say that neither Messenger nor GoogleTalk are apparently using SIMPLE today, but I imagine that many VoIP devices of the future will support it.
* British understatement
More information about the Voipsec