Web Pioneers Warn of VoIP Wiretapping Problems

Tue, June 13, 2006CIO

U.S. government efforts to require most voice-over-IP (VoIP) providers to permit law enforcement agencies to wiretap phone calls could introduce new cybersecurity problems to the Internet, a group of Internet security experts said Tuesday.

A U.S. Federal Communications Commission (FCC) rule requiring VoIP providers to allow wiretapping by May 2007 would either require a massive re-engineering of the Internet or introduce broad security risks, said authors of a new study released by the Information Technology Association of America (ITAA), an IT vendor trade group.

In addition, the requirements would stall Internet innovations in the United States by adding hundreds of thousands of dollars in setup and maintenance costs to VoIP providers and potentially to other Internet applications that provide voice services, including instant messaging and online games, according to the study.

The study, co-authored by several people including TCP/IP co-creator Vinton Cerf and former U.S. National Security Agency encryption scientist Clinton Brooks, comes days after a U.S. appeals court upheld the FCC’s VoIP wiretapping rules. On Friday, the U.S. Court of Appeals for the District of Columbia upheld the ruling, requiring that VoIP providers offering a substitute for traditional telephone service comply with a 1994 telephone wiretapping law called the Communications Assistance for Law Enforcement Act (CALEA).

The FCC did not immediately respond to a request for comment about the ITAA study. But on Friday, FCC Chairman Kevin Martin said allowing law enforcement wiretapping of VoIP calls is of "paramount importance" to U.S. security.

Tracking VoIP calls would be more difficult than tracking calls on the traditional telephone network, because VoIP providers have little control over how their calls are routed across the Internet, said Whitfield Diffie, chief security officer at Sun Microsystems. VoIP providers "have no special Internet privileges" to control traffic, said Diffie, one of the study’s authors.

VoIP wiretapping would require law enforcement to have access to both customer data from the VoIP providers and real-time tracking of calls routed across the Internet, he said. Requiring ISPs to respond in real-time to requests for them to record VoIP calls would open up the Internet to new vulnerabilities, he added.

"You find yourself in a technologically very, very complicated problem," Diffie added. "It’s not inconceivable that a system of that kind could be built. You have a magnitude of vulnerability. I can’t think of any parallel in any system we’ve seen so far."

Such a wiretapping system would require a "major research and development effort" in order to reduce security vulnerabilities, he added. In addition, it would be difficult to apply the FCC wiretapping rules to VoIP calls worldwide, he said.

Loading...
Network MarketSpace
White Papers
The Challenge of a Demanding Network Infrastructure
Today's data centers are expanding as demand for data and storage continues to grow exponentially. Learn more »
Reduce Infrastructure and Administrative Costs
The Brocade® FastIron® CX Series of switches provides new levels of performance. Learn more »
A New Generation of Application Delivery Controllers (ADCs)
Learn more about Brocade® ServerIron® intelligent application delivery and traffic management solutions. Learn more »
Want to Offer a Superior User Experience?
Control a "boundary-less" enterprise with scalable solutions. Learn more »
Realize Potential Without Increasing Your Risk
Combining Brocade's high-performance infrastructure and McAfee's Web gateway solution ensures trusted environments. Learn more »
Brocade and Imperva: Providing Best-of-Breed Products
Web applications have become the backbone of business in nearly every segment of the economy. Learn more »
 
SPONSORED LINKS
 

Maximizing the Business Value of the PC Infrastructure

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Seven Ways ITIL Can Help You in an Economic Downturn

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Reduce risk, gain agility. See how Progress can help your business.

Improve ROI, lower TCO and reduce energy consumption.

Introducing the new HP ProLiant G6 server family

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

64-page prescriptive guide to security, compliance, and IT operations.

Get Google Enterprise Search for your business information.

Accenture IT Consulting: Enabling high performance. More...

 
 
RESOURCE CENTER