Latest news
Most of the problems identified in the area of VoIP have to do with the complexities of interconnecting VoIP switches and other hardware components in an enterprise configuration. In addition to this, there have been persistent arguments that VoIP is insecure because the vast majority of VoIP systems do not provide any level of encryption by default for their users.
Efforts in the VoIP industry to use encryption more pervasively, to reduce the risk of equipment configuration errors, and to reduce the amount of infrastructure components needed to deploy the service will help. Skype has a distinct advantage in this area because its peer-to-peer design eschews hardware switches, thereby eliminating the risk of misconfiguration, and uses only encrypted communications links.
What is your general strategy for making Skype more secure?
Keeping Skype simple to use and retaining a public key infrastructure-based (PKI) authentication system are the keys to ensuring continued security for Skype.
In the old days it was all about phreaking, nowadays the term of VoIPhreaking is making its way into the news. Have you had any experience with it or is it just media hype?
The term "phone phreaking" predates "malicious hacking" and the myriad of Internet-age terms that have come to represent the analogue of phone phreaking in the modern age. By their very nature, all security systems pose a challenge to those who perceive themselves as being on the outside of the barrier.
What I think is the biggest sea change in telecommunications security is in the area of motivation. Phone phreakers were, by and large, interested in the security of telecommunications systems per se; it was viewed by the phreakers as a mostly intellectual pursuit.
Today, however, we see a bifurcation of objectives: while some continue their pursuit – rightly or wrongly – for purely intellectual challenge, the commercial benefits in the areas of unsolicited commercial calling (spam messaging) and in industrial espionage are perceived to be so great that very well-financed and sophisticated attacks are appearing at an alarming rate on the Internet. This is not just a risk for VoIP, but for the general computing milieu of which VoIP is merely one part.
What challenges do you face in the marketplace? What do you see as your advantages?
While Skype is a leader in the area of peer-to-peer communications and in converged messaging, there is always the possibility of becoming obsolete due to competition. The challenge we face is partly organisational – making sure we use our resources effectively and remain lean – and partly technological, ensuring that our developments are relevant, innovative and easy-to-use.
I suppose that the challenges we face in the marketplace are the same as any other new company: gaining customer acceptance and focusing on delighting our users every single day.
Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





