Around twelve WiFi VoIP handsets and deskphones have been tested by top security professionals, who say that security problems range from potential DoS attacks to more serious problems that allow “deep access” to the device that lets a hacker get hold of any sensitive information on the phone.

Such threats are inevitable. So where is the onus to prevent such problems? it has been posited that if we see practices like this develop as these devices get more popular then the manufacturers will only have themselves to blame when the security issues put people off VoIP altogether.

VoIP hacking is the digital age’s version of war dialing - a strategy of automatically scanning telephone numbers using a modem, frequently dialing every telephone number in a local area to find where computers or fax machines are available, then attempting to access them by guessing passwords.

Still there are actions people can take to mitigate the risk. Here’s a list of WiFi VOIP security issues, and some useful ways to guard against them:

Multiple directions of attack:
As the telephones get more sophisticated, so could the points of entry for would be hackers. Email, client Web browsers, Bluetooth, SMS, WiFi, media players, and image viewers could all give hackers a point of entry. Though users can use open-source as well as commercial tools to regularly test their phones and networks, they’ll ultimately have to rely on vendors to also do proactive testing on these devices.

Targeting phones in public environments:
For example a Bluetooth scanner could be hidden at the entrance to a major public space and be used to steal user data. It may be best to keep Bluetooth and other wireless features swicthed off when not needed.

Rogue access points:
Meanwhile at the office or on the road, IT departments will have to keep their guard up and scan for rogue access points. Hackers will set up access points to specifically target WiFi phones in the corporate space as well as at conferences and other places business people like to get together. Good device authentication and encryption can help provide protection here.

Specific attacks:
Select attacks on specific voice-over-wireless networks may also be an issue, although perhaps one that the victims may try to downplay.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • OnlyWire
  • Socialize-It
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Netscape
  • YahooMyWeb
  • Reddit
  • Slashdot
  • Ma.gnolia
  • RawSugar

Comments are closed.