[VOIPSEC] Using SRTP for University project

Hadriel Kaplan HKaplan at acmepacket.com
Sun Apr 2 00:03:20 CST 2006


Hi Randell, comments inline...

> -----Original Message-----
> From: Randell Jesup [mailto:rjesup at wgate.com]
> Sent: Thursday, March 30, 2006 5:14 PM
> To: Hadriel Kaplan
>
> >I'm curious what you mean by "transparent" SBC?  And who this tunnel link
> >would connect to, and what it would check?  Enterprise SBCs work
> differently
> >than service-provider ones, in general. (if by "transparent" you mean
> inline
> >like a firewall)
> 
> I mean transparent in the same manner as a transparent HTTP proxy, which
> intercepts port 80 transactions.  This would have to exist close to the
> end-user, such as associated with or in a cable CMTS or DSL/etc router,
> etc
> -- or it could exist on the service-providers' connection, which would be
> hard (but not impossible) to do without the agreement of the service
> provider.  It would have to act as a kind of B2BUA (with IP spoofing), and
> it would have to be in a position to filter all traffic in both
> directions.

Huh.  Are there such boxes?  Because that's not what an SBC is.  At least no
SBC I've ever seen.  There are "SBCs" in the enterprise space which do
something like that I presume (because their marketing literature sounds
like it), but I think of them as more like firewalls.  But for any big
network that model is fundamentally flawed for an SBC I think - for a
malicious box it would be ok to do it that way, maybe.

 
> >think).  It's about time someone realized IP addresses need not be a
> >component of end-to-end identity.  But it's too heavy for media gateways
> I
> >think, and I've been told most sip calls go to media gateways today.
> 
> That's since most are currently PSTN calls; that will change.  

Exactly.  But it will take a reeeaaally long time. :) And from a media
perspective it may need transcoding for even longer, to get to cell phones
(and they're not going away). Though the industry may settle on some common
codecs someday.

> People don't
> tend to worry about voice being intercepted (much) by random people, but
> they do start worrying when they know images are being transmitted -
> that's
> part of why we use SRTP for all video calls and why we have a physical
> shutter on our camera as well.

Funny, never thought of it that way.  I assumed the shutter was for
psychological benefit - ie, letting the user be comfortable that they can't
be seen by the person they really called, instead of using a soft-button,
for times when they're not "presentable".  

-hadriel





More information about the Voipsec mailing list