[VOIPSEC] VoIP and Fraud
Brian Rosen
br at brianrosen.net
Wed Feb 16 07:44:20 CST 2005
The self signed cert is part of a hop-by-hop security system whose primary
purpose is protecting the location information from disclosure to
unauthorized parties. There is not an expectation that TLS will necessarily
authenticate the caller.
If there IS a carrier, the incoming TLS to the PSAP would have a verifiable
cert. By using P-Asserted-Identity, or Jon Peterson's
identity draft we could authenticate the caller, but since there isn't
necessarily a carrier, and even if there is, it may not be a carrier
recognized by the PSAP, we can't assume that we can authenticate.
Even if there is a supposedly good authentication mechanism, if it
failed, the PSAPs usually prefer to get the call first, and look to
see why authentication failed later.
We will supply the call taker with information that equates to,
"this may be valid, but be suspicious", if, for example, you got
an unsigned, or signature failed location, from a carrier without
a good cert or no carrier at all. There will be controls that
allow the PSAP to refuse such calls if it wishes to or needs to.
Clearly, we are balancing several needs here:
* We do want the system to be secure to prevent fraudulent calls
* We do want location to be protected from inadvertent disclosure
* We want emergency calls to work when infrastructure starts to fail
I don't think there is a way to GUARANTEE, with any reasonable
certainty, that we can achieve all the needs all the time. We
can have an acceptably high probability, and we can supply
the call taker with information that will allow them to
reasonably supply the services needed.
Brian
> -----Original Message-----
> From: Geoff Devine [mailto:gdevine at cedarpointcom.com]
> Sent: Tuesday, February 15, 2005 11:37 PM
> To: Brian Rosen; Voipsec at voipsa.org
> Subject: RE: [VOIPSEC] VoIP and Fraud
>
> Brian Rosen wrote:
> > We will protect the signaling with TLS, but we will accept a self
> signed cert.
>
> Great stuff. Since this is a fraud thread, isn't there a fraud issue with
> a self-signed certificate? You're essentially allowing people to self-
> declare that they're really themselves. In this case, not only can you
> not trust the endpoint, but you're also not even really authenticating
> them. That's reasonable in a 911 application where you don't want to have
> someone die because they can't produce the digital equivalent of a valid
> photo ID but you certainly are vulnerable.
>
> Geoff
>
More information about the Voipsec
mailing list