[asterisk-users] How Secure Is Asterisk

Singer Wang wang at pythian.com
Tue Oct 21 15:39:14 CDT 2008


The visual eky in Windows Zfone is good, but it can be broken too. There 
is no way to be 100% secure. Nothing is 100% secure.  What you need to 
do is a standard business C/B analysis and based on that determine how 
much security is good enough.




SIP wrote:
> It's not 100% secure. Like any dual-key encryption, it's subject to the
> classic man-in-the-middle attack. This is why the Windows Zfone app has
> the addition of a visual key you can read and coordinate with the
> recipient to determine if a MITM attack is occurring. But only if you
> know what you're doing.
>
> There is no such thing as an unbreakable system. YOU might not be able
> to attack it with your limited resources, but someone determined enough
> to do so, will find a way.
>
> N.
>
> Jonn R Taylor wrote:
>   
>> What about zfone project???
>>
>> -----Original Message-----
>> From: asterisk-users-bounces at lists.digium.com [mailto:asterisk-users-bounces at lists.digium.com] On Behalf Of Sam Tam
>> Sent: Tuesday, October 21, 2008 12:49 AM
>> To: 'Asterisk Users Mailing List - Non-Commercial Discussion'
>> Subject: Re: [asterisk-users] How Secure Is Asterisk
>>
>> There are no 100% solution but we can only do our best.
>>
>> -----Original Message-----
>> From: asterisk-users-bounces at lists.digium.com
>> [mailto:asterisk-users-bounces at lists.digium.com] On Behalf Of broadband
>> Voice
>> Sent: Tuesday, October 21, 2008 4:37 AM
>> To: Asterisk Users Mailing List - Non-Commercial Discussion
>> Subject: Re: [asterisk-users] How Secure Is Asterisk
>>
>> lol 
>>
>>
>> On Mon, Oct 20, 2008 at 3:34 PM, Sam Tam <samtam888 at gmail.com> wrote:
>>
>>
>> 	VPN IP phone?
>> 	Then firewall up the asterisk to disable any outside access and
>> place the
>> 	vpn server with the asterisk in a locked cabinet .
>> 	
>> 	Sure that will stop someone trying to physically listen to their
>> call.
>> 	Or they can always use the good old landline or mobile phone and let
>> the
>> 	government listen to them too/
>> 	Sam
>> 	
>>
>> 	-----Original Message-----
>> 	From: asterisk-users-bounces at lists.digium.com
>> 	[mailto:asterisk-users-bounces at lists.digium.com] On Behalf Of Steve
>> Anness
>> 	Sent: Tuesday, October 21, 2008 3:02 AM
>> 	To: Asterisk Users Mailing List - Non-Commercial Discussion
>> 	Subject: [asterisk-users] How Secure Is Asterisk
>> 	
>> 	I am sure this has been discussed prior, however, I am sitting here
>> and
>> 	being asked this very question by my superiors.  They are loving
>> what I have
>> 	done with our two Asterisk servers here; however, they keep asking
>> me if it
>> 	is secure or not.  Of course, as with anything, I suspect that on a
>> secure
>> 	network they can be reasonably safe.  However, realistically if I am
>> using
>> 	the asterisk server to make internal calls and discussion very
>> private
>> 	matters, how possible is it for someone to listen to calls?  How
>> good is the
>> 	encryption if any over an IAX trunk?
>> 	
>> 	Steve Anness
>> 	
>> 	
>> 	
>> 	_______________________________________________
>> 	-- Bandwidth and Colocation Provided by http://www.api-digital.com
>> <http://www.api-digital.com/>  --
>> 	
>> 	asterisk-users mailing list
>> 	To UNSUBSCRIBE or update options visit:
>> 	  http://lists.digium.com/mailman/listinfo/asterisk-users
>> 	
>>
>>
>>
>>
>> _______________________________________________
>> -- Bandwidth and Colocation Provided by http://www.api-digital.com --
>>
>> asterisk-users mailing list
>> To UNSUBSCRIBE or update options visit:
>>    http://lists.digium.com/mailman/listinfo/asterisk-users
>>
>>
>>
>>
>> _______________________________________________
>> -- Bandwidth and Colocation Provided by http://www.api-digital.com --
>>
>> asterisk-users mailing list
>> To UNSUBSCRIBE or update options visit:
>>    http://lists.digium.com/mailman/listinfo/asterisk-users
>>   
>>     
>
>
> _______________________________________________
> -- Bandwidth and Colocation Provided by http://www.api-digital.com --
>
> asterisk-users mailing list
> To UNSUBSCRIBE or update options visit:
>    http://lists.digium.com/mailman/listinfo/asterisk-users
>   


-- 
*Singer Wang*
/System and Database Engineer/
The Pythian Group
------------------------------------------------------------------------
Office: 	      	(613) 565-8696 x298
Toll Free: 	      	(877) 798-4426 x298
Fax: 	      	(613) 565-8710
Email: 	      	wang at pythian.com
MSN: 	      	pythianwang at hotmail.com
Yahoo: 	      	pythianwang
AIM: 	      	pythianwang
ICQ: 	      	201253
Gadu-Gadu: 	      	6817795
Tencent QQ: 	      	858310404

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.digium.com/pipermail/asterisk-users/attachments/20081021/85af62cf/attachment.htm 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: wang.vcf
Type: text/x-vcard
Size: 145 bytes
Desc: not available
Url : http://lists.digium.com/pipermail/asterisk-users/attachments/20081021/85af62cf/attachment.vcf 


More information about the asterisk-users mailing list