* Security experts say it's difficult to design an effective VoIP-tapping system
endif; ?>Businesses may have yet another reason to use VPNs: a means to get around legal wiretapping rules for VoIP that could endanger corporate data sent over the Internet.
The new ruling says that providers of Internet services must provide law enforcement officials with the means to tap VoIP calls on their networks. A report (PDF) written by well-respected security experts says this is not only difficult and expensive but it is also dangerous to anyone concerned about security.
To tap a VoIP call from the network pretty much requires taps at both the ingress and egress routers for that call. Such routers are in ISP facilities, which no doubt offer some physical security but by and large are not designed to be as secure, as say, telephone company local switching offices where tapping ability resides now.
In the hands of criminals, taps on these routers could subject traffic not only to eavesdropping but also to man-in-the-middle attacks that could replace content being sent with different content unbeknownst to the recipient.
The report points out how difficult it would be to design and implement an effective VoIP-tapping system. For instance, call setup for VoIP often takes place outside the network where the tap is placed, making it difficult to figure out where a call originates and ends – such information required to intercept a call. The report’s authors also note that use of end-to-end VPNs would pretty much thwart wiretapping efforts because even if intercepted, VPN traffic is encrypted.
The authors mention this in the context that VPNs could be used by criminals to hide their illegal activities, but corporations legitimately worried about the secrecy of their own data could use the same technique to protect their data from the chance that someone other than legally sanctioned agencies use the taps.
In fact, businesses should do so to protect their interests, as many have already done even before this new Internet security vulnerability was authorized.




