The FBI Accidentally Drizzles on Digium's Parade

There has been some recent madness in the open source communications world and I thought I had to get involved to get the matter settled properly. Some media outlets reported on the fact that the FBI put out a vague statement via the IC3 regarding how Asterisk may be susceptible to vishing attacks or caller ID spoofing via VoIP.

Before commenting I waited to hear back from Digium's John Todd who explained that there were some methodology and editorial process issues in this alert - basically no one checked with Digium before going public. As it turns out, after checking with Digium, the FBI quickly revised their statement and everything is fine.

The details are that there was a bug which Digium found in March of 2008 and subsequently patched in version 1.2 and 1.4. Version 1.6 is not affected. Besides, according to Todd, the security issue would arise if system administrators basically disregarded logical security measures like using numerals in passwords.

For your reference you may want to check out the blog entry from Todd titled SIP Security and Asterisk as well as the updated IC3 warning from the FBI.

I am sure by the time Asterisk World rolls around in a few months in Miami, we will all be laughing about this incident and marveling at the opportunity that is open source communications.

The opinions and views expressed in comments, blogs, etc. are those of the authors alone and not necessarily those of TMC, TMCnet, or its editors. TMCnet reserves the right to edit, delete, or otherwise make changes to the content that appears on these pages at its own discretion and as it deems necessary.
| 0 Comments | 0 TrackBacks

Listed below are links to sites that reference The FBI Accidentally Drizzles on Digium's Parade:

The FBI Accidentally Drizzles on Digium's Parade TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/38406

Leave a comment

Recent Activity

Saturday

Friday

More...

Recent Comments

  • Scott: My name is Scott Hardin. I am the son of read more
  • Scott: My name is Scott Hardin. I am the son of read more
  • Backbooner: The answer to that is the same as how "someone" read more
  • Bart: "It's remarkable xG has managed to shut Marc up. I read more
  • Backbooner: It's remarkable xG has managed to shut Marc up. I read more
  • prefabrik: How can be a cycle set up and controlled? Is read more
  • Sheeri: IPTV, is where DSL was back in early 90s. We read more
  • zayıflama: Your could ask someone from Gimp for Mac community read more
  • Peter Koz: Rich, I am interested in your comments regarding Proxim's new read more
  • Catherine: As a Brit, I have noticed a growth of royal read more

Subscribe to Blog

Blogroll

Recent Entry Images

  • sagem-interstar-xmediusfax-outbound.png
  • tmcnet-feature-plaer-jquery-javascript.jpg
  • monopoly.jpg
  • itexpo-east-2009-exhibit-hall-aisle.jpg

Archives

Around TMCnet Blogs

Latest Whitepapers

TMCnet Videos