[VOIPSEC] Actual Attacks

Robert Moskowitz rgm at icsalabs.com
Fri Feb 25 12:56:26 CST 2005


At 09:36 AM 2/24/2005, Brian Rosen wrote:

>"Web of Trust" is a failed concept.  It works, but we have not been able to
>successfully deploy in a large scale.

But it CAN work for groups of friends.

>Certificate authority chains work only within an enterprise.  We have not
>really made them work well outside of that.

Check out ACES.

Check out the Federal PKI and work being done to duplicate it in commercial 
settings (drug industry for one).  Note I am the author of the Bridge CA 
model in the federal PKI.

Thing is you REALLY need a reason to get PKi s to work together.  Mail was 
never one.  Bout VoIP could be.


Robert Moskowitz
Senior Technical Director
ICSA Labs, a division of Cybertrust, Inc.
W:      248-968-9809
F:      248-968-2824
E:      rgm at icsalabs.com

There's no limit to what can be accomplished
if it doesn't matter who gets the credit






More information about the Voipsec mailing list