Blog.DanYork.com - It's a VoIP security issue simply *because* VoIP was used? Huh?
Personal journal of Dan York - for my VoIP blog, see www.disruptivetelephony.com
dyork
[info]dyork
It's a VoIP security issue simply *because* VoIP was used? Huh?
One of the articles making the rounds today is a Techweb piece called "Phishers Snare Victims with VoIP" which, frankly, seems mostly like a promotional piece for the security firm Cloudmark. That I can see, it really has next to NOTHING to do with VoIP.

The scenario is that phishers sent out a bogus email to people asking them to call a phone number. When the victims called the number, they wound up in an interactive voice response (IVR) system (as we do pretty much everywhere these days). The system prompted them to enter their account number and PIN and was set up identically to the way that the target bank's IVR system was set up. Victims enter personal data. Bingo, thieves get the data and clean out the bank accounts. Nice and simple.

Okay, so where's the VoIP?

Ummm... gee, according to the report, the phishers: a) used Asterisk; and b) might have used phone numbers (up to three!) provided by a VoIP service provider, which could be easily directed to the aforementioned Asterisk system.

So Asterisk was used instead of a "traditional" PBX and some VoIP service provided the numbers - THIS merits saying that the phishers "snared victims with VoIP"? Huh?

Sure, it was probably easier for the phishers to modify Asterisk's voicemail prompts - and sure, it was easy to get phone numbers - but it's the same old scam! Absolutely nothing new and unique other than being a bit easier for the phishers to set up.

Let's look at it in a different context - say a gang of thieves rob a bank and use a beat-up station wagon as their get-away car. The headline is probably going to read
"Local bank robbed by thieves"
Say they do it again, only this time they use a Ferrari as their get-away car. Should the headline now be?
"Local bank robbed by a Ferrari"
C'mon people, get a clue! The victims were NOT snared by VoIP. They were snared by an obviously well-written piece of spam and their own misplaced trust in the authenticity of email messages. THAT is what snared them. The fact that the crooks used VoIP is only a sidebar to the story.... just as mention of the Ferrari in my scenario above would only be a sidebar to the main point that the bank was robbed.

It's not a VoIP security issue... it is just a plain old human gullibility issue.

Tags: , ,

Comments
From: (Anonymous) Date: June 18th, 2007 03:53 am (UTC) (Permanent Link)
Hello, you need drug? No problem, go to http://www.pharmamedics.us {all:links}
1 comment or Leave a commentPermanent Link
Profile
Dan York
User: [info]dyork
Name: Dan York
My Other Weblogs
- Disruptive Conversations
   (social media, blogs, PR, etc.)
- Disruptive Telephony
   (Voice over IP, telecom)
- Blue Box: The VoIP Security Podcast
- Voice of VOIPSA
   (VoIP Security Alliance)
about this journal
Copyright 2004-9 Dan York

All opinions expressed here are entirely mine and have no connection to my employer or any other person or organization.

If you enjoy my writing (style or content) and would be interested in a contribution of text to a book, magazine, website, etc., please feel free to contact me as I am always open to considering writing opportunities.
Full Disclosure
Dan York, CISSP, is Director of Conversations at Voxeo. He is also the Best Practices Chair for the VOIP Security Alliance. However, there is no connection between Voxeo and this weblog and nothing stated here should in any way be interpreted as statements or positions of Voxeo or VOIPSA.
Categories/Tags

Select a tag/category to view all entries in that category.

Links
page summary
Anonymous (no subject)