VoIP encryption not needed on cable modems

Opinion
Jul 25, 20052 mins

* Readers respond to article on VoIP and encryption, Part 1

In a recent newsletter, we discussed whether it was necessary to encrypt conversations being transmitted over an IP network. In fact, we went so far as to suggest that it might be too easy to encrypt voice conversations over an IP network. We ended by asking for your opinions – and boy, did we hear from you.

For that reason, we’ll offer our apologies if we did not respond to you personally. Rest assured, though, that you are heard. Many of you disagreed with us, so we want to share these comments and continue the discussion.

One reader responded:

“Granted, existing phone conversations are not encrypted. On the other hand, ‘regular’ phone calls go over a dedicated wire that runs from the user’s phone to the PBX/CO and from there on. For someone not authorized to tap to your conversation, they need to have physical access to your phone or your phone line. A VoIP call, though, is using a shared media. This means that, for example, if I use a cable modem, anyone on my network segment with a sniffer can have access to all my conversations. From my perspective VoIP encryption is not only a security issue but most importantly a privacy issue, as no encryption can even let ‘neighbors’ track the phone numbers you are calling.”

We understand the user’s point. However, we must point out that it is our understanding that essentially all cable modems adhere to a standard called DOCSIS (Data Over Cable Service Interface Specification), and one of the functions of DOCSIS is to ensure that the information “on the cable” is encrypted for each individual cable modem. See: https://www.cablemodem.com/faq/#FAQ7

So from this perspective, we must respectfully disagree with the reader. And it seems worthwhile to point out this disagreement since the reader is arguing from the perspective of one of the most common “telecom urban legends.”

By the way, the same level of encryption is not needed for DSL access since DSL runs over the same physical wires as the “normal” telephony conversation.

Here’s the original article on VoIP encryption: http://www.networkworld.com/newsletters/converg/2005/0620converge2.html?rl