[VOIPSEC] Re: Voipsec Digest, Vol 2, Issue 33
Robert Foxworth
rfoxwor1 at tampabay.rr.com
Sun Feb 27 12:21:00 CST 2005
>The key
>is that simply using switches does not eliminate the possibility of
>sniffing, it just makes it a little harder. This is of course why many
>firms are concerned about the introduction of legal intercept features
>into networking devices -- because it makes it _easier_ for someone to
>intercept and tap traffic. CALEA (47 U.S.C. § 1001 et seq.) and other
>regulations mean that not only can the traffic be intercepted but it
>should not be detectable (by the subject or even by others who have
>lawful intercept orders).
>
>Regards,
>G. Q. Maguire Jr.
A minor point, but it occurs to me that it is not clear as to whether
you
meant (1) that the subject of the intercept order should not be able to
detect that the sniffing is taking place, i. e. detect that the sniffing
is
even happening, or (2) that the subject, and/or the others with lawful
orders etc. be able to capture the actual data stream itself. I think
that (1) was your meaning. For (2) then you'd either need to
config a second span, or add a hub and tee it off, all of which
implies admin/phy access to the switch. Can a second span even
be added nowadays?
I would think that at the least, one would need access to read the
config of the switch to realize than a span port was configured. I
think the point is that, in your own lab, you know about this, but as
just
a user (as far as the switch is concerned) you don't know this.
- Bob
More information about the Voipsec
mailing list