U.S. government efforts to require most voice-over-IP (VoIP) providers to permit law enforcement agencies to wiretap phone calls could introduce new cybersecurity problems to the Internet, a group of Internet security experts said Tuesday.A U.S. Federal Communications Commission (FCC) rule requiring VoIP providers to allow wiretapping by May 2007 would either require a massive re-engineering of the Internet or introduce broad security risks, said authors of a new study released by the Information Technology Association of America (ITAA), an IT vendor trade group.In addition, the requirements would stall Internet innovations in the United States by adding hundreds of thousands of dollars in setup and maintenance costs to VoIP providers and potentially to other Internet applications that provide voice services, including instant messaging and online games, according to the study.The study, co-authored by several people including TCP/IP co-creator Vinton Cerf and former U.S. National Security Agency encryption scientist Clinton Brooks, comes days after a U.S. appeals court upheld the FCC’s VoIP wiretapping rules. On Friday, the U.S. Court of Appeals for the District of Columbia upheld the ruling, requiring that VoIP providers offering a substitute for traditional telephone service comply with a 1994 telephone wiretapping law called the Communications Assistance for Law Enforcement Act (CALEA). The FCC did not immediately respond to a request for comment about the ITAA study. But on Friday, FCC Chairman Kevin Martin said allowing law enforcement wiretapping of VoIP calls is of “paramount importance” to U.S. security.Tracking VoIP calls would be more difficult than tracking calls on the traditional telephone network, because VoIP providers have little control over how their calls are routed across the Internet, said Whitfield Diffie, chief security officer at Sun Microsystems. VoIP providers “have no special Internet privileges” to control traffic, said Diffie, one of the study’s authors. VoIP wiretapping would require law enforcement to have access to both customer data from the VoIP providers and real-time tracking of calls routed across the Internet, he said. Requiring ISPs to respond in real-time to requests for them to record VoIP calls would open up the Internet to new vulnerabilities, he added.“You find yourself in a technologically very, very complicated problem,” Diffie added. “It’s not inconceivable that a system of that kind could be built. You have a magnitude of vulnerability. I can’t think of any parallel in any system we’ve seen so far.”Such a wiretapping system would require a “major research and development effort” in order to reduce security vulnerabilities, he added. In addition, it would be difficult to apply the FCC wiretapping rules to VoIP calls worldwide, he said.“These things do not respect borders,” he said. “It’s very hard to see how something of this kind can be done both effectively and securely.”If the FCC CALEA rules are enforced, all kinds of Internet applications would be monitored, added Cerf, the chief Internet evangelist at Google. “I don’t see any way to constrain or restrict the target of the intercept to simply voice, because, in fact, every application would have to be effectively treated in the same fashion,” he said. “There’s no way to tell what the bits mean in the packets that are flowing.”-Grant Gross, IDG News Service (Washington Bureau) Related Links: VoIP Wiretapping Upheld in Court ACLU Attempts to Halt Warrantless WiretapsCheck out our CIO News Alerts and Tech Informer pages for more updated news coverage. Related content feature Expedia poised to take flight with generative AI CTO Rathi Murthy sees the online travel service’s vast troves of data and AI expertise fueling a two-pronged transformation strategy aimed at growing the company by bringing more of the travel industry online. By Paula Rooney Jun 02, 2023 7 mins Travel and Hospitality Industry Digital Transformation Artificial Intelligence case study Deoleo doubles down on sustainability through digital transformation The Spanish multinational olive oil processing company is immersed in a digital transformation journey to achieve operational efficiency and contribute to the company's sustainability strategy. By Nuria Cordon Jun 02, 2023 6 mins CIO Supply Chain Digital Transformation brandpost Resilient data backup and recovery is critical to enterprise success As global data volumes rise, business must prioritize their resiliency strategies. By Neal Weinberg Jun 01, 2023 4 mins Security brandpost Democratizing HPC with multicloud to accelerate engineering innovations Cloud for HPC is facilitating broader access to high performance computing and accelerating innovations and opportunities for all types of organizations. By Tanya O'Hara Jun 01, 2023 6 mins Multi Cloud Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe