Go Back   Wireless and Wifi Forums > News > Newsgroups > uk.telecom.voip
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-22-2006, 04:21 PM
Doz
Guest
 
Posts: n/a
Default How secure is SIP ?

How secure is sip ?

I hear people banging Skype on security... just wondered if SIP was secure ?

Reply With Quote
  #2 (permalink)  
Old 08-22-2006, 05:09 PM
Ivor Jones
Guest
 
Posts: n/a
Default Re: How secure is SIP ?


"Doz" <ssskkk@zmail.ru> wrote in message
news:10yntt60h5fx3$.8jptkbef4lkw$.dlg@40tude.net
> How secure is sip ?
>
> I hear people banging Skype on security... just wondered
> if SIP was secure ?


Nothing is *totally* secure, it depends on how much time, money and
expertise you have available to crack it..!

Although I'd hazard a guess that unless you're GCHQ or the CIA, it would
be proably be easier to bug the room in which the person is making the
call..!

Ivor



Reply With Quote
  #3 (permalink)  
Old 08-22-2006, 06:24 PM
alexd
Guest
 
Posts: n/a
Default Re: How secure is SIP ?

Doz wrote:

> How secure is sip ?


Not at all. The signalling is in plaintext and the audio streams are
unencrypted RTP, by default.

> I hear people banging Skype on security... just wondered if SIP was
> secure?


SIP is as secure as the network you are using it on!

--
<http://ale.cx/> (AIM:troffasky) (UnSoEsNpEaTm@ale.cx)
18:23:42 up 28 days, 23:45, 3 users, load average: 0.01, 0.06, 0.15
This is my BOOOOOOOOOOOOOOOOOOOOOMSTICK


Reply With Quote
  #4 (permalink)  
Old 08-23-2006, 10:32 PM
Martin
Guest
 
Posts: n/a
Default Re: How secure is SIP ?

Ivor Jones wrote:
> "Doz" <ssskkk@zmail.ru> wrote in message
> news:10yntt60h5fx3$.8jptkbef4lkw$.dlg@40tude.net
>> How secure is sip ?
>>
>> I hear people banging Skype on security... just wondered
>> if SIP was secure ?

>
> Nothing is *totally* secure, it depends on how much time, money and
> expertise you have available to crack it..!
>
> Although I'd hazard a guess that unless you're GCHQ or the CIA, it would
> be proably be easier to bug the room in which the person is making the
> call..!


*If* (and it's a big if) you're in a position to watch the packets go
past on the internet (or on your local Ethernet on route to the
Internet) then you can use open-source software to record a nice .WAV
file! I think Ethereal does that now. That is, standard SIP just sends
all voice traffic in the clear.

If you watch the packets go past in Ethereal, you can see that there's
some attempt to protect the signalling traffic to try to guard against
call fraud, but it isn't immediately obvious how secure that is. That
is, I'm not sure whether I should be worried about the possibility of
call fraud.

In the absence of a robust security analysis, my gut feeling is that SIP
is probably good enough to use on ADSL, but should be avoided on
unencrypted wi-fi, cable internet (if the downlink is shared) and on any
other untrusted networks where packet interception is likely to occur.

- Martin.

Reply With Quote
  #5 (permalink)  
Old 08-23-2006, 11:10 PM
Darren J Longhorn
Guest
 
Posts: n/a
Default Re: How secure is SIP ?

On Wed, 23 Aug 2006 22:32:08 +0100, Martin <not-for-mail@example.com>
wrote:

>*If* (and it's a big if) you're in a position to watch the packets go
>past on the internet (or on your local Ethernet on route to the
>Internet) then you can use open-source software to record a nice .WAV


Not _quite_ as simple as saving to a .wav file - unless you happen to
be using G711.

>file! I think Ethereal does that now. That is, standard SIP just sends
>all voice traffic in the clear.


It's not really that SIP is in the clear that causes the problem, it's
just initiating the session after all, it's that RTP is used to carry
the voice data. I expect that SRTP, which allows for encryption of the
RTP payload, will become more popular in time.


Reply With Quote
  #6 (permalink)  
Old 08-25-2006, 10:33 AM
Doz
Guest
 
Posts: n/a
Default Re: How secure is SIP ?

On Tue, 22 Aug 2006 17:24:58 GMT, alexd wrote:

> Doz wrote:
>
>> How secure is sip ?

>
> Not at all. The signalling is in plaintext and the audio streams are
> unencrypted RTP, by default.
>
>> I hear people banging Skype on security... just wondered if SIP was
>> secure?

>
> SIP is as secure as the network you are using it on!


Thanks for the sensible and straight fwd reponses.. ta.

Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HPSBUX02178 SSRT061267 rev.1 - HP-UX Secure Shell Remote Denial of Service (DoS) Security Alert comp.security.misc 0 12-05-2006 07:44 PM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 05:37 AM
Google "Secure Access" FAQ + Download link frankdowling1@yahoo.com alt.internet.wireless 11 09-23-2005 09:22 PM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 05:26 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 05:25 AM


All times are GMT. The time now is 07:46 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45