The FBI Accidentally Drizzles on Digium's Parade

There has been some recent madness in the open source communications world and I thought I had to get involved to get the matter settled properly. Some media outlets reported on the fact that the FBI put out a vague statement via the IC3 regarding how Asterisk may be susceptible to vishing attacks or caller ID spoofing via VoIP.

Before commenting I waited to hear back from Digium's John Todd who explained that there were some methodology and editorial process issues in this alert - basically no one checked with Digium before going public. As it turns out, after checking with Digium, the FBI quickly revised their statement and everything is fine.

The details are that there was a bug which Digium found in March of 2008 and subsequently patched in version 1.2 and 1.4. Version 1.6 is not affected. Besides, according to Todd, the security issue would arise if system administrators basically disregarded logical security measures like using numerals in passwords.

For your reference you may want to check out the blog entry from Todd titled SIP Security and Asterisk as well as the updated IC3 warning from the FBI.

I am sure by the time Asterisk World rolls around in a few months in Miami, we will all be laughing about this incident and marveling at the opportunity that is open source communications.

The opinions and views expressed in comments, blogs, etc. are those of the authors alone and not necessarily those of TMC, TMCnet, or its editors. TMCnet reserves the right to edit, delete, or otherwise make changes to the content that appears on these pages at its own discretion and as it deems necessary.
| 0 Comments | 0 TrackBacks

Listed below are links to sites that reference The FBI Accidentally Drizzles on Digium's Parade:

The FBI Accidentally Drizzles on Digium's Parade TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/38406

Leave a comment

Recent Activity

Today

  • Rich Tehrani tweeted, "Droid Won't Kill the iPhone But Google Guide Might: For the record, Google Guide is not a product or service develope... http://bit.ly/idsyt"
  • Rich Tehrani posted Droid Won't Kill the iPhone But Google Guide Might

Saturday

Friday

More...

Recent Comments

  • cram: What's the Treco v. Kromka case about? (I don't have read more
  • chezhanson: (continued) The most interesting thing about it is that nothing read more
  • chezhanson: And to answer your other question Marc, the department I read more
  • Ethan: The lawsuit must be Treco v. Kromka: http://dockets.justia.com/docket/court-flsdce/case_no-1:2009cv22987/case_id-344282/ read more
  • chezhanson: "Ex-employees say Bobier is a genius Ex-employees say Bobier is read more
  • abdul jaleel.m: i got some problem in google talk becoz when i read more
  • anon: Hey Chez, Bart and Ugly, check this out! Ex-employees say read more
  • anon: What lawsuits, slanty? read more
  • Backbooner: xG has nothing and the the lawsuit just tells how read more
  • anon: Donger, that doesn´t make the cash any less green. Let´s read more

Subscribe to Blog

Blogroll

Recent Entry Images

  • itexpo-east-2009-exhibit-hall-aisle.jpg
  • tmc-halloween-2009-tom-keating.jpg
  • google-tricycle.jpg
  • benioff-apple-behind-the-cloud.jpg
  • happy-cell-phone.jpg

Archives

Around TMCnet Blogs

Latest Whitepapers

TMCnet Videos