[VOIPSEC] On the topic of Vishing
Simon Horne
s.horne at packetizer.com
Fri Jul 14 01:28:12 CDT 2006
Recently I read this article
http://news.com.com/Phishers+come+calling+on+VoIP/2100-7349_3-6092366.html?tag=fd_nbs_ent&tag=nl.e433
Vishing is a major concern for SIP. Without any form of peer-entity
(end-to-end caller) authentication and secure call admission mechanism (or
the capability to support it) then there appears to be no real method for
addressing this incredibly major problem.
Let me explain using the example from the article and how Vishing can be
prevented in standard based VoIP.
As I have mentioned in previous emails that one possible solution is the
use of 2 factor authentication, Something I have (a PKI cert etc) and
something I know (username/password)
Certainly using end-to-end authentication will definitely help reduce the
risk as the caller will have some certainty to whom they are calling but it
is not a complete answer as the Vishers may acquire a valid digital
certificate which makes them appear that they are someone who they are not.
This is where the importance of the second factor comes in. The Bank issues
the user with a user and password and this is used to verify the client at
the bank so their is no need to enter user/pass or credit card information
(or in fact depending on the application there so no need for an IVR system
at all). Although human conditioning may still be an issue, but proper
education will go a long way to resolve a lot of the vishing problems in VoIP.
All this is possible to do today using the H.235 framework of H.323.
Simon
More information about the Voipsec
mailing list