I would have to err on the side of CDR to say that the only difference in analogy you provided (SSH vs Asterisk) is that people lose much more $$$$$$$$ in VoIP than they ever did in SSH hacking. So, if this is an exceptional case bending a rule or two of RFC in favor of security won't harm specially if it's provided as an option. After-all, RFC does stand for Referral For Comment as in always open to be improved. Secondly, there is no trade off with the responses as local and private IP networks are well know from the public range so the option for such a security measure can be tuned to be smart to that end.<div>
<br></div><div>The only thing I like about MS OSs is that it's secure out of box and that is really what a Linux OS should be as well but it's not and so it's not solely Digium's issue and I see your point giving the analogy. </div>
<div><br></div><div>I think it's a good idea if such a security "option" is provided by default in Asterisk knowing it can save a lot of headache. If budget is an issue maybe make it a bounty and watch support pouring in...........<div>
<br></div><div>- Bruce</div></div><br><div class="gmail_quote">On Tue, Jul 26, 2011 at 2:14 PM, Alex Balashov <span dir="ltr"><<a href="mailto:abalashov@evaristesys.com">abalashov@evaristesys.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;"><div class="im">On 07/26/2011 02:09 PM, CDR wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Only way to cope with hackers would be that Digium comes to its<br>
senses and accepts to disable any response to a REGISTER whose<br>
username is unknown. I cannot think of a good reason why Digium<br>
finds this proposal unacceptable, given the onslaught of hacking<br>
that we are seeing in the industry. It may take a single line of<br>
code and it would save millions of $$$. Not only because the<br>
hackers will never get in, but because we would save a huge CPU<br>
impact responding to hundreds of REGISTER attempts per minute. It<br>
is a NO brainer. Can please the Powers that Be reconsider and add<br>
this option to sip.conf? Please?<br>
</blockquote>
<br></div>
No, because that's absolutely ridiculous. The proper, RFC-compliant behaviour is to return an authentication failure in response to invalid credentials. This mechanism is relied upon for legitimate functionality, such as letting the UAs of intended users know that they are sending incorrect credentials.<br>
<br>
As was pointed out before, Asterisk is a mostly application-level construct. Applications usually have some rudimentary means of self-defense such as ACLs, but applications are often conceptually distinct from the most appropriate means of securing them. That's what firewalls, SBCs, intrusion detection systems, etc. are for.<br>
<br>
Your position is equivalent to saying that stock SSH should not return authentication errors for invalid passwords. The proper solution to dictionary attacks is to firewall the SSH service, use RSA keys, VPNs, etc., not to tell the maintainers of the OpenSSH project to come to its senses.<br>
<br>
-- <br><font color="#888888">
Alex Balashov - Principal<br>
Evariste Systems LLC<br>
260 Peachtree Street NW<br>
Suite 2200<br>
Atlanta, GA 30303<br>
Tel: <a href="tel:%2B1-678-954-0670" value="+16789540670" target="_blank">+1-678-954-0670</a><br>
Fax: <a href="tel:%2B1-404-961-1892" value="+14049611892" target="_blank">+1-404-961-1892</a><br>
Web: <a href="http://www.evaristesys.com/" target="_blank">http://www.evaristesys.com/</a></font><div><div></div><div class="h5"><br>
<br>
--<br>
______________________________<u></u>______________________________<u></u>_________<br>
-- Bandwidth and Colocation Provided by <a href="http://www.api-digital.com" target="_blank">http://www.api-digital.com</a> --<br>
New to Asterisk? Join us for a live introductory webinar every Thurs:<br>
<a href="http://www.asterisk.org/hello" target="_blank">http://www.asterisk.org/hello</a><br>
<br>
asterisk-users mailing list<br>
To UNSUBSCRIBE or update options visit:<br>
<a href="http://lists.digium.com/mailman/listinfo/asterisk-users" target="_blank">http://lists.digium.com/<u></u>mailman/listinfo/asterisk-<u></u>users</a><br>
</div></div></blockquote></div><br>