<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech FAQ Blog &#187; VoIP Wiretap</title>
	<atom:link href="http://www.tech-faq.com/blog/category/voip-wiretap/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tech-faq.com/blog</link>
	<description>News and Views from The Tech FAQ Team</description>
	<lastBuildDate>Mon, 14 Sep 2009 03:42:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>VoIP wiretap rules attacked</title>
		<link>http://www.tech-faq.com/blog/voip-wiretap-rules-attacked.html</link>
		<comments>http://www.tech-faq.com/blog/voip-wiretap-rules-attacked.html#comments</comments>
		<pubDate>Tue, 13 Jun 2006 07:45:00 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[VoIP Regulation]]></category>
		<category><![CDATA[VoIP Wiretap]]></category>

		<guid isPermaLink="false">http://www.tech-faq.com/blog/voip-wiretap-rules-attacked.html</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>VoIP service technology <a href="http://news.com.com/Technologists+assail+federal+Net-tapping+rules/2100-1028_3-6083066.html" target="_blank">experts are not pleased</a>:</p>
<blockquote dir="ltr"><p><strong>Federal regulations saying that police must be able to tap into Internet phone conversations with ease are coming under renewed attack from academics, engineers and one of the Net&#8217;s founding fathers.</strong> </p>
<p>A 21-page study (<a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fitaa.org%2Fnews%2Fdocs%2FCALEAVOIPreport.pdf&amp;siteId=3&amp;oId=2100-1028-6083066&amp;ontId=1023&amp;lop=nl.ex" target="_blank"><span style="color: #0403ad;">click for PDF</span></a>) to be released Tuesday says it&#8217;s impossible for the government to expect all products that use voice over Internet protocol, or VoIP, to comply with the Federal Communications Commission&#8217;s September 2005 requirement mandating wiretapping backdoors for government surveillance. That requirement is backed by the Bush administration. </p>
<p>The study, organized by the Information Technology Association of America, says that because VoIP relies on a fundamentally different network architecture from that of traditional phone lines, such a mandate would pose &quot;enormous costs&quot; to the industry and could even introduce significant security risks. </p>
<p>The nine contributors included Vint Cerf, Google&#8217;s chief Internet evangelist and one of the Net&#8217;s founding fathers; Steven Bellovin and Matt Blaze, both prominent computer security professors who specialize in security; Clinton Brooks, a former National Security Agency official; and engineers from Sun Microsystems and Intel.</p>
</blockquote>
<p><newselement></newselement></p>
]]></content:encoded>
			<wfw:commentRss>http://www.tech-faq.com/blog/voip-wiretap-rules-attacked.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Vendors see profits in VoIP wiretap regulations</title>
		<link>http://www.tech-faq.com/blog/vendors-see-profits-in-voip-wiretap-regulations.html</link>
		<comments>http://www.tech-faq.com/blog/vendors-see-profits-in-voip-wiretap-regulations.html#comments</comments>
		<pubDate>Tue, 13 Jun 2006 06:42:00 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[VoIP Regulation]]></category>
		<category><![CDATA[VoIP Wiretap]]></category>

		<guid isPermaLink="false">http://www.tech-faq.com/blog/vendors-see-profits-in-voip-wiretap-regulations.html</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>It would appear that <a href="http://www.networkworld.com/news/2006/061306-vendors-sync-up-ip-wiretapping.html" target="_blank">not everybody in VoIP is complaining</a> about the FCC VoIP service wiretap requirements:</p>
<blockquote dir="ltr"><p class="first">Two software vendors have made their IP wiretapping tools for carriers and law-enforcement agencies work together.</p>
<p>Narus&#8217; NarusInsight Intercept Suite for carriers has been fully tested for interoperability with Pen-Link&#8217;s Lincoln 2 data collection and reporting software for law enforcement, the companies will announce Tuesday. </p>
<p>The transition on carrier networks from circuit-switched phone calls to IP packet data services has turned the world of wiretapping upside down. With new laws requiring carriers to hand over information about subscribers&#8217; e-mail and Web surfing, carriers and legal agencies need new tools that work with each other.</p>
<p>&#8230;The Narus and Pen-Link products are the first to comply with both the ETSI rules and the VoIP CALEA regulations as well as U.S. laws on collecting e-mail and Web data, the companies claim. Specifically, they fully comply with the CALEA T1.678 standard and the ETSI TS 102 232/233/234 standards. </p>
<p>The software is intended for probes, with warrants, of specific users&#8217; traffic during specific periods, Bannerman said.</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.tech-faq.com/blog/vendors-see-profits-in-voip-wiretap-regulations.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Court Upholds FCC on Broadband CALEA Compliance</title>
		<link>http://www.tech-faq.com/blog/court-upholds-fcc-on-broadband-calea-compliance.html</link>
		<comments>http://www.tech-faq.com/blog/court-upholds-fcc-on-broadband-calea-compliance.html#comments</comments>
		<pubDate>Sat, 10 Jun 2006 03:39:00 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[VoIP Regulation]]></category>
		<category><![CDATA[VoIP Wiretap]]></category>

		<guid isPermaLink="false">http://www.tech-faq.com/blog/court-upholds-fcc-on-broadband-calea-compliance.html</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>FCC <a href="http://www.wirelessweek.com/article/CA6342661.html" target="_blank">wins this round</a>:</p>
<blockquote dir="ltr"><p>A U.S. Court of Appeals ruling that upheld the FCC’s decision to apply digital wiretapping rules to VoIP providers probably won’t significantly affect wireless carriers’ broadband wiretap capabilities, according to a CTIA representative.</p>
<p>The U.S. Court of Appeals for the District of Columbia this afternoon upheld an FCC decision to require broadband VoIP providers to have wiretapping capabilities in place for law enforcement use. </p>
<p>The decision ostensibly would apply to wireless broadband services, says Mike Altschul, senior vice president and general counsel at CTIA, but wireless carriers already are covered by the Communications Assistance for Law Enforcement Act (CALEA). VoIP providers haven’t been classified as telecom carriers, so the rules are new to them.</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.tech-faq.com/blog/court-upholds-fcc-on-broadband-calea-compliance.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Judges challenge new U.S. Internet wiretap rules</title>
		<link>http://www.tech-faq.com/blog/judges-challenge-new-us-internet-wiretap-rules.html</link>
		<comments>http://www.tech-faq.com/blog/judges-challenge-new-us-internet-wiretap-rules.html#comments</comments>
		<pubDate>Sat, 06 May 2006 18:30:00 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[VoIP Regulation]]></category>
		<category><![CDATA[VoIP Wiretap]]></category>

		<guid isPermaLink="false">http://www.tech-faq.com/blog/judges-challenge-new-us-internet-wiretap-rules.html</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>Interesting article on the legal challenges to extending <a href="http://www.picayuneitem.com/articles/2006/05/07/news/23wiretaps.txt" target="_blank">CALEA to VoIP</a>:</p>
<blockquote dir="ltr"><p>A U.S. appeals panel sharply challenged the Bush administration Friday over new rules making it easier for police and the FBI to wiretap Internet phone calls. A judge said the government&#8217;s courtroom arguments were “gobbledygook.”</p>
<p>The skepticism expressed so openly toward the administration&#8217;s case encouraged civil liberties and education groups that argued that the U.S. is improperly applying telephone-era rules to a new generation of Internet services. </p>
<p class="content">“Your argument makes no sense,” U.S. Circuit Judge Harry T. Edwards told the lawyer for the Federal Communications Commission, Jacob Lewis. “When you go back to the office, have a big chuckle. I&#8217;m not missing this. This is ridiculous. Counsel!”</p>
<p>At another point in the hearing, Edwards told the FCC&#8217;s lawyer that his arguments were “gobbledygook” and “nonsense.” </p>
<p class="content">[...] In the current case, Edwards appeared especially skeptical over the FCC&#8217;s decision to require that providers of Internet phone service and broadband services must ensure their equipment can accommodate police wiretaps under the 1994 Communications Assistance for Law Enforcement Act, known as CALEA.</p>
<p>The new rules go into effect in May 2007. </p>
<p class="content">The 1994 law was originally aimed at ensuring court-ordered wiretaps could be placed on wireless phones.</p>
<p>The Justice Department, which has lobbied aggressively on the subject, warned in court papers that failure to expand the wiretap requirements to the fast-growing Internet phone industry “could effectively provide a surveillance safe haven for criminals and terrorists who make use of new communications services.”</p>
<p>Critics said the new FCC rules are too broad and inconsistent with the intent of Congress when it passed the 1994 surveillance law, which excluded categories of companies described as information services.</p>
<p>The FCC asserted that providers of high-speed Internet services should be covered under the 1994 law because their voice-transmission services can be considered separately from information services. “Congress intended to cover services (in the 1994 law) that were functionally equivalent” to traditional telephones, Lewis said during the hearing in U.S. Circuit Court for the District of Columbia.</p>
<p>“There&#8217;s nothing to suggest that in the statute,” Edwards replied. “Stating that doesn&#8217;t make it so.”</p>
<p>The panel appeared more inclined to support the FCC&#8217;s argument that Internet-phone services &#8211; which allow users to dial and receive calls from traditional phone numbers &#8211; may be covered under the 1994 law and required to accommodate court-ordered wiretaps. The technology, popularized by Holmdel, N.J.-based Vonage Holdings Corp., is known as “voice over Internet protocol,” or VOIP.</p>
<p>“Voice-over is a very different thing,” U.S. Circuit Judge David B. Sentelle said. He said it offered “precisely the same” functions as traditional telephone lines.</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.tech-faq.com/blog/judges-challenge-new-us-internet-wiretap-rules.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP service providers will have to comply with CALEA</title>
		<link>http://www.tech-faq.com/blog/voip-service-providers-will-have-to-comply-with-calea.html</link>
		<comments>http://www.tech-faq.com/blog/voip-service-providers-will-have-to-comply-with-calea.html#comments</comments>
		<pubDate>Fri, 05 May 2006 02:23:43 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[VoIP News]]></category>
		<category><![CDATA[VoIP Regulation]]></category>
		<category><![CDATA[VoIP Wiretap]]></category>

		<guid isPermaLink="false">http://www.tech-faq.com/blog/voip-service-providers-will-have-to-comply-with-calea.html</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>The FCC voted on May 4th to require VoIP service providers to comply with the 1994 Communications Assistance for Law Enforcement Act (CALEA) by making their services easily wiretappable.&nbsp; Broadband and VoIP providers will have until May 17, 2007 to comply with the law, and will have to foot the bill for any related costs, which could run into the hundreds of millions of dollars.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tech-faq.com/blog/voip-service-providers-will-have-to-comply-with-calea.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five WiFI VoIP security issues</title>
		<link>http://www.tech-faq.com/blog/five-wifi-voip-security-issues.html</link>
		<comments>http://www.tech-faq.com/blog/five-wifi-voip-security-issues.html#comments</comments>
		<pubDate>Fri, 17 Feb 2006 04:03:52 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[IP Telephony]]></category>
		<category><![CDATA[VoIP News]]></category>
		<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VoIP Service Providers]]></category>
		<category><![CDATA[VoIP Wiretap]]></category>

		<guid isPermaLink="false">http://www.tech-faq.com/blog/five-wifi-voip-security-issues.html</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p dir="ltr" style="MARGIN-RIGHT: 0px">Five WiFi VoIP sercurity issues <a href="http://www.unstrung.com/document.asp?doc_id=89180&amp;WT.svl=news2_2" target="_blank">from Unstrung</a>:</p>
<blockquote dir="ltr" style="MARGIN-RIGHT: 0px"><p>Here&#8217;s a Top 5 list of enterprise WiFi VOIP security issues, and some ways to guard against them:</p>
<p><strong>Widespread deployment equals a security headache:</strong><br />Because of the &quot;ubiquity of deployment&quot; in many enterprises, attacks can spread quickly and be targeted to take down multiple devices at once. IT managers should stay up to the minute with phone upgrades, and consider running phones over a separate physical or virtual LAN as a defense against these attacks.</p>
<p><strong>Many points of attack:</strong><br />As the phones get more sophisicated, so could the points of entry for malicious attacks increase. Bluetooth, email, client Web browsers, SMS, WiFi, media players, and image viewers could open back doors for hackers. Though users can use open-source and commercial tools to continually test their phones and networks, they&#8217;ll ultimately have to rely on vendors to do proactive testing on these devices. </p>
<p>&quot;Some vendors may engage in this testing while the majority will not,&quot; warns Merdinger.</p>
<p><strong>Targeting phones in public environments:</strong><br />For example, a Bluetooth scanner could be hidden at the entrance to a major airport or train station and be used to grab user data. It may be best to keep Bluetooth and other wireless features swicthed off when not needed.</p>
<p><strong>Rogue again:</strong><br />Meanwhile, at the office and on the road, users and IT departments will have to keep their guard up and scan for rogue access points. Hackers will set up access points to specifically target WiFi phones in the corporate space as well as at hotels, conferences, and other places business people like to congregate. Good device authentication and encryption can help provide protection here.</p>
<p><strong>Targeted attacks:</strong><br />Targeted attacks on specific voice-over-wireless networks could also be an issue, albeit one that the victims may try to downplay. &quot;There will be targeted attacks on VoIP networks [from hackers or competitors] that will be kept quiet if there is no legal requirement for disclosure or obvious public knowledge,&quot; Merdinger says.</p>
<p>Users, however, shouldn&#8217;t get in a snit about VOIP calls that are often unencrypted and therefore easier to listen in on. Unless attackers are targeting a specific user, it is much simpler to find useful information sent by the user or held on the phone than to listen in on calls, even if you&#8217;re the NSA.</p>
<p>&quot;Most attackers are going to go after text information &#8212; much easier to parse for the juicy information,&quot; says Merdinger.</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.tech-faq.com/blog/five-wifi-voip-security-issues.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP monitoring, Patriot Act expansion and the history of wiretaps</title>
		<link>http://www.tech-faq.com/blog/voip-monitoring-patriot-act-expansion-and-the-history-of-wiretaps.html</link>
		<comments>http://www.tech-faq.com/blog/voip-monitoring-patriot-act-expansion-and-the-history-of-wiretaps.html#comments</comments>
		<pubDate>Sat, 05 Nov 2005 05:53:21 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[VoIP News]]></category>
		<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VoIP Wiretap]]></category>

		<guid isPermaLink="false">http://www.tech-faq.com/blog/voip-monitoring-patriot-act-expansion-and-the-history-of-wiretaps.html</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s some more information on the developing VoIP wiretap story, with a lawsuit being filed and a proposed expansion of the Patriot Act under debate.&nbsp; At the end of the post we&#8217;ve also quoted some interesting background information on the history of wiretaps courtesy of CourtTV.</p>
<p>First, the <a href="http://www.technewsworld.com/story/47074.html" target="_blank">lawsuits</a>:</p>
<blockquote dir="ltr" style="MARGIN-RIGHT: 0px"><p>Last week, an alliance of Voice over Internet Protocol (VOIP) telephony providers and technology makers &#8212; including Sun Microsystems &#8212; filed a petition in federal court in Washington D.C. seeking to have the FCC&#8217;s rule requiring that all future Internet telephone systems be built to accommodate wiretapping technology.</p>
</blockquote>
<p dir="ltr" style="MARGIN-RIGHT: 0px"><a href="http://www.law.com/jsp/article.jsp?id=1130332860865" target="_blank">Also</a>:</p>
<blockquote dir="ltr" style="MARGIN-RIGHT: 0px"><p dir="ltr" style="MARGIN-RIGHT: 0px">Separately, the American Council on Education, which represents about 2,000 colleges and universities, filed an appeal of the rule on [October 24th] in federal court in Washington. </p>
<p>The education group said schools are willing to cooperate with the FBI, but that there are other ways to assist law enforcement rather than rewiring networks. </p>
<p>&quot;We fear that the FCC order will make every college and university replace every router and every switch in their systems,&quot; said council senior vice president Terry Hartle. &quot;The cost of doing that is substantial.&quot; </p>
</blockquote>
<p>Moving on, here&#8217;s a summary of the proposed expansions / extensions of the <a href="http://www.localtechwire.com/article.cfm?u=12637" target="_blank">Patriot Act</a>:</p>
<ul>
<li><strong>Roving wiretaps:</strong> Section 206 expands the 1978 Foreign Intelligence Surveillance Act to allow federal agents to wiretap several phone lines based on a single wiretap order, issued by the secret FISA court. The target of the roving wiretaps under 206 can be a “John Doe,” in contravention of previous court rulings that either the person or the place to be wiretapped must be “particularly described.”&nbsp; These wiretaps don’t require after-the-fact justification to the court, though pending reauthorization would change that.</p>
<p>Pre-PATRIOT wiretap law required that common carrier telecommunication firms that must provide wiretapping assistance be named in the warrant.&nbsp; But PATRIOT vitiates that requirement, allowing the issuance of generic orders by the court and leaving the wiretapping agents to direct telecommunications providers to provide access to their systems.</p>
<p>After stonewalling requests for information for a few years, the Department of Justice in March, with the sunset coming up, said this provision had been used 49 times. Competing PATRIOT reauthorization acts in the House and Senate would renew the provision for 10 and four years respectively.&nbsp; The Senate bill would require more information about the target beforehand and add extensive public reporting on the use of roving wiretaps.</li>
<p>
<li><strong>VoIP and Voicemail:</strong> Section 209 makes it easier for the FBI to search “stored communications” without a wiretap order or in some cases without a search warrant.&nbsp; Thought purportedly targeted at voicemail, this will apparently apply to VoIP (voice-over-Internet) calls that are cached in the process of travelling over networks.&nbsp; Section 209 is set to be made permanent as well.</li>
</ul>
<p><span id="more-895"></span></p>
<p>Also, here&#8217;s some interesting information from CourtTV on the <a href="http://www.courttv.com/news/2005/1104/technologylaw_ap.html" target="_blank">history of wiretaps</a>:</p>
<blockquote dir="ltr" style="MARGIN-RIGHT: 0px"><p>Wiretapping — so named because eavesdropping police placed metal clips on the analog wires that carried conversations — has a complex legal history.</p>
<p>A 1928 case, Olmstead v. United States, legitimized the practice, when the Supreme Court ruled it was acceptable for police to monitor the private calls of a suspected bootlegger.</p>
<p>Behind that 5-4 ruling, however, a seminal debate was raging. The dissenting opinion by Justice Louis Brandeis argued, among other things, that the government had no right to open someone&#8217;s mail, so why should a phone — or other technologies that might emerge — carry different expectations about privacy?</p>
<p>In 1967, as the dawn of the digital age was fulfilling Brandeis&#8217; fears that other forms of technological eavesdropping would become possible, the Supreme Court reversed Olmstead. After that, authorities had to get a search warrant before setting wiretaps, even on public payphones.</p>
<p>That apparently hasn&#8217;t been much of a hindrance.</p>
<p><strong>State and federal authorities have had 30,975 wiretap requests authorized since 1968, with only 30 rejections, according to the Electronic Privacy Information Center. Some 1,710 wiretaps were authorized last year, the most ever, with zero denied.</strong></p>
<p>Since 1980, authorities also have been able to set secret wiretaps with the approval of the Foreign Intelligence Surveillance Court, which privacy watchdogs say requires a lower standard of evidence than the general warrant process. For the first two decades FISA orders numbered less than 1,000 annually; 2003 and 2004 each saw more than 1,700. Only four FISA applications have been rejected, all in 2003.</p>
<p>But technology began to pose obstacles in the 1980s, as old-fashioned telephone networks were giving way to digital switching systems that could also transmit information. Suddenly some wiretaps had to become virtual, using &quot;packet sniffing&quot; programs that spy on the splintered packets of data that make up network traffic.</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.tech-faq.com/blog/voip-monitoring-patriot-act-expansion-and-the-history-of-wiretaps.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
