Slashdot Mirror


Hiding Packets in VoIP Chat

holy_calamity writes "Two Polish researchers say they have developed a system to hide secret steganographic messages in the packets of a VOIP connection. It exploits the fact that VoIP uses UDP, not TCP; it is designed to tolerate some packets going missing -- so hijacking a few to transmit a hidden message is not a problem." You may also be interested in reading the original paper.

90 comments

  1. Too late by oodaloop · · Score: 4, Informative

    Didn't /. just post an article a few months ago about how the NSA figured out a way to block steganographic messages in VOIP?

    --
    Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
    1. Re:Too late by Zymergy · · Score: 5, Informative

      Sort of... "Blocking Steganosonic Data In Phone Calls" http://it.slashdot.org/article.pl?sid=08/04/02/0133212
      There is this too... http://it.slashdot.org/article.pl?sid=04/01/10/2358247

    2. Re:Too late by Anonymous Coward · · Score: 0

      Troll? Seriously? Who gave the angry guy mod points?

    3. Re:Too late by oodaloop · · Score: 1

      Wouldn't the same technique work for VOIP as well? And since when is referring to previous relevant /. articles being a troll?

      --
      Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
    4. Re:Too late by bickerdyke · · Score: 5, Informative

      Only as long as you'd try to hide your secret data in the Audio stream. If you inject your secret data directly into the network "connection" (read: the sequence of UDP Packets sent) it bypasses manipulated background noise.

      --
      bickerdyke
    5. Re:Too late by redxxx · · Score: 3, Interesting

      The first link would not work because they can't just add noise. They would have to inspect and remove packets from the data stream. It works totally differently and would not be applicable.

      The second is just looking for out of band communication in data streams. It could be configured to look for it in Voip traffic, but most of it is encrypted. It wouldn't be easy, particularly doing it in something like real time, but not impossible.

    6. Re:Too late by GuldKalle · · Score: 4, Funny

      And since when is referring to previous relevant /. articles being a troll? Probably just someone trying to post a steganographic message using the /. mod-system.
      --
      What?
  2. Pay for 388 words? by CogDissident · · Score: 5, Insightful

    To continue reading this article, subscribe to New Scientist. Get 4 issues of New Scientist magazine and instant access to all online content for only USD $5.95

    Thanks Slashdot, because I really want to go to Slashdot to get links to a story that I have to pay to read.

    1. Re:Pay for 388 words? by Beat+The+Odds · · Score: 5, Funny

      Thanks Slashdot, because I really want to go to Slashdot to get links to a story that I have to pay to read.

      You're welcome?

    2. Re:Pay for 388 words? by chunk08 · · Score: 4, Funny

      Wait, someone who reads articles? On slashdot?

      You must be new here.

      --
      Do away with our corrupt tax code. Support the Fair Tax
    3. Re:Pay for 388 words? by witherstaff · · Score: 1

      It's sometimes confusing to remember the rules. When talking about Playboy / Maxim / etc, you get it 'just for the articles'.

      And then you go to /. and since there's no eye candy (Unless you get rickrolled or goatse'd) and you actually read the stuff, but have to hide that you do. Confusing!

  3. Complete article by TripMaster+Monkey · · Score: 5, Informative

    The complete article, accessible without NewScientist subscription, may be found here.

    --
    ____

    ~ |rip/\/\aster /\/\onkey

  4. Well... by Vectronic · · Score: 3, Insightful

    It's not a sectret anymore now is it?

    1. Re:Well... by Vectronic · · Score: 4, Funny

      Nor a secret for that matter.

    2. Re:Well... by fracai · · Score: 4, Funny

      I assumed the misspelling was one part of a larger steganographic message. Let it be known that I am now browsing over your comment history looking for further "mistakes".

      I'm on to you.

      --
      -- i am jack's amusing sig file
    3. Re:Well... by Vectronic · · Score: 2, Insightful

      You are abolutely right, however, you forgot that I may have multiple accounts, and may be sending messages across more than just Slashdot.

      You would have to know all my accounts, on all forums, plus know the method to decipher the data.

      Muahaha.

    4. Re:Well... by flaming+error · · Score: 1

      it Never was a secret. yOu could alSo hide messages In ceReal boxes and floral arrangements.

    5. Re:Well... by lanswitch · · Score: 3, Funny

      Twitter, is that you?

    6. Re:Well... by Vectronic · · Score: 1

      Ouch, low blow.

    7. Re:Well... by lanswitch · · Score: 1

      Multiple accounts, may be sending from more than one address. It just seemed logical to me...

    8. Re:Well... by SpaceLifeForm · · Score: 0, Offtopic

      Missing a comma after 'anymore'.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
    9. Re:Well... by Vectronic · · Score: 3, Funny

      By that logic, we might both be Twitter, considering his nack for replying to himself.

    10. Re:Well... by Anonymous Coward · · Score: 2, Funny

      Well played "everyone"...

    11. Re:Well... by morgan_greywolf · · Score: 2, Funny

      You are abolutely right, however, you forgot that I may have multiple accounts, and may be sending messages across more than just Slashdot.


      Okay, so the code has MISSING as well as added letters. Extra 'T', missing 'S' -- ah ha! Terrorist State! Wait'll the NSA finds out, it'll be Gitmo for y....

      No, no! I was just decoding the message for you guys! Hey! I'm not the recip....

      *klank!*
    12. Re:Well... by Anonymous Coward · · Score: 0

      Let's just hope they don't do a remake of Spartacus.

      I am twitter.
      No, I am twitter.
      We are all twitter!

      (shudder)

    13. Re:Well... by h4ck7h3p14n37 · · Score: 5, Interesting

      That reminds me of a neat story.

      A few years ago at a tech conference I met someone who worked for the data storage division at Dell. Some of the technical manuals that the engineer needed for their work were classified as secret (product hadn't gone to market yet) and the engineer had to sign various NDAs with the company to get access to the documents.

      Said engineer compared their copy of a manual with another engineer's copy and discovered that each manual had a different set of spelling errors. Apparently Dell was generating documents with unique sets of typos in order to be able to track down the identify of the person who leaked a document.

    14. Re:Well... by Vectronic · · Score: 1

      If I had mod points. (it wouldnt do any good since envoled in the conversation) +1 Interesting, anyways.

      Although Dell wasnt the first to do so, it is still generally a good idea, because serial numbers, and other tags, can easily be swapped/removed.

      But it's not perfect, given that if someone manually typed out the document, and removed all spelling mistakes, or even created new ones, the system fails, likewise, if someone was "in the know" about the scheme, they could essentially impersonate another (rival) employee, and it would be very hard to prove they weren't the ones who leaked it.

    15. Re:Well... by QRDeNameland · · Score: 1

      Look at the bright side...at least you have free GTMO health care now.

      --
      Momentarily, the need for the construction of new light will no longer exist.
    16. Re:Well... by argent · · Score: 1

      Peer and Kate read, "Leopold Bloom wandered through Dublin."

    17. Re:Well... by AioKits · · Score: 2, Funny

      Apparently Dell was generating documents with unique sets of typos in order to be able to track down the identify of the person who leaked a document. Either that, or Dell has taken the 'million monkeys at a million keyboards' approach to producing technical manuals!
      --
      "Quote me as saying I was mis-quoted." -Groucho Marx
    18. Re:Well... by ISoldat53 · · Score: 1

      Dell learned something from having an ex-NSA Director and Deputy CIA Director on their Board of Directors.

    19. Re:Well... by Anonymous Coward · · Score: 0

      It's called a Canary Trap - http://en.wikipedia.org/wiki/Canary_trap
      Which just goes to show - if you're going to leak company info, pinch the PHB's copy.

    20. Re:Well... by twatt3r · · Score: 0

      I never reply to myself, and I have no sockpuppets.

      And am I supposed to get a separate IP address for every split personality...?!

    21. Re:Well... by Anonymous Coward · · Score: 1, Insightful

      Said engineer compared their copy of a manual with another engineer's copy and discovered that each manual had a different set of spelling errors. Apparently Dell was generating documents with unique sets of typos in order to be able to track down the identify of the person who leaked a document.

      That's crude. There are other schemes that encode the identity of a document in the microspacing between the letters.


    22. Re:Well... by lanswitch · · Score: 1

      I never reply to myself

      this must be the exception.

  5. No way by William+Robinson · · Score: 4, Funny

    secret steganographic messages in the packets of a VOIP connection

    Stop this research. No way I am going to say GoodBye to my Secretary. She knows a lot more than just stenography;)

    1. Re:No way by RandoX · · Score: 1

      All I can figure is that he assumed steganographic was a typo. Maybe I missed the joke too.

    2. Re:No way by laddiebuck · · Score: 1

      A joke on stenography, i.e. taking dictation or notes via shorthand.

  6. UDP Only... by mchawi · · Score: 4, Interesting

    Based on the RFCs for VOIP they are supposed to support UDP and TCP per the new specs. Most companies are moving to support both so you can choose, but some of the large companies are going to TCP because this is what all of the 'Unified Communications' packages go with (such as Microsoft Office/Live/Communicator, etc).

    One of the reasons they are leaning this way is security. Go figure.

    Besides that, I don't really see the point. What does this solve that just encrypting sensitive data wouldn't?

    1. Re:UDP Only... by k_187 · · Score: 3, Insightful

      If somebody's looking for something encrypted data is something. With this method, there isn't anything to find, unless I'm totally misunderstanding it.

      --
      11 was a racehorse
      12 was 12
      1111 Race
      12112
    2. Re:UDP Only... by zappepcs · · Score: 4, Interesting

      Well, it might ensure that the NSA et al are not infecting your VoIP equipment with tracing software while you are talking, and those pesky terrorists might not be able to send text data about the next planes to hijack while having a bad conversation quality exchange about prayer times and how to find Mecca while in Chicago.

      When a security hole is found, it needs to be plugged because the threats it poses are not always explicitly understood at first glance.

      In fact, in computing in general, there are multiple ways to sneak a couple of packets through here and there if you're willing to be patient. I'd mention a few of them, but that would probably get me on a fucked up watch list. The fact remains that this is but one way to do so. Monitoring the network packet for packet won't uncover them all either, nor will it out any terrorists who don't want anyone watching their communications. Why, even my music on hold can contain data for transmission to the right person with the right audio equipment. Never mind a blog post, or email. In fact... woooootttt! I could use the NSA's website as the key for an encryption routine that they would never decode in several decades of trying. sigh, but that won't stop them from telling us that it's all for our protection.

      Just encrypting it would not stop the possibility of rogue data if your application can withstand a few missing packets. VoIP is not the only protocol which is susceptible.

    3. Re:UDP Only... by Vectronic · · Score: 2, Insightful

      Yeah thats what I got from it aswell.

      If someone is using an encrypted connection/transfer, then its obvious they are doing something, and also trying to keep it hidden, whereas, if they were to carry out a normal transmition, but have the "secret" part of it hidden in this, someone looking, would see a normal interaction and possibly skip over the noise.

      You could also have an encrypted message, that also requires data from the steganographic 'noise' and vice versa to become usable data, that way if one is "caught" its still useless data unless both are "caught"...

    4. Re:UDP Only... by PhuCknuT · · Score: 4, Informative

      The idea behind steganography is not just to encrypt the data, but to hide the fact that you're sending it in the first place.

    5. Re:UDP Only... by Kr3m3Puff · · Score: 5, Informative

      First, Stenographic or Stenophonetic solutions are supposed to disguise that you are actually communicating encrypted information, which is 1/2 the battle. If you know two parties are transmitting encrypted information that is sometimes enough (especially in this day and age) to either attack via brute force, or even worse, make them legally hand over their decryption keys, where then you need plausible denability. When the third party doesn't even know you are transmitting information, you are in a much better situation.

      First, wide adoption of RTP transmission via TCP is highly unlikely, due to the nature of streaming media in general which UDP is designed for and TCP is not. Fixed datagrams and packet ordering protocol are a major pain in the a$$ for streaming media.

      Where as the call control protocol (SIP, H.323, MGCP, etc) via TCP is probablly more likely and most standards support transmission under either, though the vast majority is still UDP based.

      You are right from a security perspective with TCP you know if information is gone missing, where as UDP you never really know.

      --
      D.O.U.O.S.V.A.V.V.M.
    6. Re:UDP Only... by papna · · Score: 2, Informative

      With this method, there isn't anything to find, unless I'm totally misunderstanding it. Or rather, there's nothing to notice.

      Plain cryptography is something like having a locked safe sitting in a room. It might not be easy to get into, but you know it when you see it. This is like having a safe behind a painting. You don't notice that there is anything being kept away from you.
    7. Re:UDP Only... by Anonymous Coward · · Score: 1, Informative

      Besides that, I don't really see the point. What does this solve that just encrypting sensitive data wouldn't?
      A lot. Remember when W. told OBL that we were listening in on their sat phones? Well, between that incident and the time that reagan gave up info about the KAL incident told a lot about our intel world (the 2 should have been swung, or gone on a hunting trip with cheney, for those actions of being traitors; it took several years for pilots to talk again and a number of interesting channels were shutdown in 2003). One of the things about the terrorists is that they are not just romantics. They are extremely bright (PhD's and MD all over). OBL went underground and pushed for hiding info. Of course, the issue is what package to look at. Well, when a small portion are encrypted, then it is trivial to find. of course that brings up the issue of whether the NSA can decrypt it? So, AQ has figured out that answer and needed another way to communicate. So they switched up to steg. Why? Because now, we have to hunt for these, figure out which packets to reassemble, which ORDER to assemble them, and then decrypt. That is DAMN difficult.

    8. Re:UDP Only... by mattwarden · · Score: 1

      Geekier.

    9. Re:UDP Only... by Anonymous Coward · · Score: 0

      Plain cryptography is something like having a locked safe sitting in a room. It might not be easy to get into, but you know it when you see it. This is like having a safe behind a painting. You don't notice that there is anything being kept away from you. I'm sorry. You lost me. Could you rephrase that as a car analogy instead?
    10. Re:UDP Only... by morgan_greywolf · · Score: 1

      I'm sorry. You lost me. Could you rephrase that as a car analogy instead?
      Sure. Plain cryptography is like hiding your illegally-modified Covette engine with hood locks -- steganography is like putting your illegally-modified Corvette engine into a Hyundai Elantra.
    11. Re:UDP Only... by Tanktalus · · Score: 5, Funny

      Plain cryptography is something like having a locked car sitting in a room. It might not be easy to get into, but you know it when you see it. This is like having a car behind a painting. You don't notice that there is anything being kept away from you. Well, other than that big-assed painting.

      No? How about this...

      Plain cryptography is something like having a locked car sitting in a room. It might not be easy to get into, but you know it when you see it. This is like having the locks of the car behind paintings. You don't notice the keyholes. Well, other than those out-of-place paintings hanging off the door handles.

      No? How about this...

      Plain cryptography is something like driving your car across the border while trying to keep from having to show your passport to the border patrol (by showing them fake ID). This is like doing the same while having the trunk full of cocaine when you do so.

      Bah, nevermind.

    12. Re:UDP Only... by Zadaz · · Score: 1

      And yet everyone says security by obscurity isn't security at all.

    13. Re:UDP Only... by shadow349 · · Score: 2, Funny

      Well, other than that big-assed painting.
      Excuse me, but I believe the proper term is rubenesque.
    14. Re:UDP Only... by ushering05401 · · Score: 1

      "And yet everyone says security by obscurity isn't security at all."

      Obscurity is not security, but can be complementary. In the VoIP example the security would be the encryption of your signal, the obscurity would be the addition of meaningful UDP packets.

      Obscurity is helpful when dealing with cursory inspections, but doesn't actually increase security because being secure requires more than being non-obvious.

      Think of contraband transportation. Driving around with illegal contraband in plain sight - say sitting on your passenger seat of your car - is just as insecure as putting the contraband in your glove compartment... any investigation into what you are doing and the jig is up. Putting the contraband in your glove compartment simply reduces the chance that questions about what you are doing will arise which is helpful, but not secure.

    15. Re:UDP Only... by Sancho · · Score: 1

      The term Security Through Obscurity is overused and poorly understood. The key is that most Security Through Obscurity has cryptography in plain sight with an "obscure" encryption mechanism. It's the "we created our own cryptography implementation, but we can't tell you what it is because it would compromise the security of the algorithm" that causes the problem. It's usually quite possible to reverse-engineer such algorithms, so if the system relies on secrecy which can be discovered (as opposed to the secrecy of passwords or keys which, in strong systems, cannot be recovered without interacting with the owner of said password), then the system is weak.

      With steganography, you're not only hiding the algorithm used, you're hiding the fact that there's any message at all. Ideally, you'd also encrypt any steganographic message, meaning that even if someone discovers that a message is there, they won't be able to read the message. In this way, you're protecting yourself from, say Carnivore-like systems, but even if your data-hiding fails, no one can read the content anyway.

    16. Re:UDP Only... by Em+Adespoton · · Score: 1

      Ever seen that TV commercial from a few years back where the guy walks up to what looks like an old beater parked in an alley, and then proceeds to pull the dust cover off his fancy sports car?

      Well, that's nothing like steganography ;)

    17. Re:UDP Only... by sr180 · · Score: 1

      Who are you? BadAnalagyGuy?

      --
      In Soviet Russia the insensitive clod is YOU!
    18. Re:UDP Only... by mpe · · Score: 1

      The idea behind steganography is not just to encrypt the data, but to hide the fact that you're sending it in the first place.

      Even though specific applications may use steganography in conjunction with encryption it does not imply that encryption is involved.

  7. Make noises by tristian_was_here · · Score: 5, Funny

    If you want to hide packets over VoIP I suggest making "beeping" noises.

  8. Re:Complete article, without ads by Animats · · Score: 5, Informative

    Here is the actual paper as a clean PDF. This is the good version.

    The linked Technology Marketing Corporation page mentioned in the parent post has only the beginning of the article. It also has 24/7 Media ads in the middle of the article, Google ads on the right, TMC ads at the top, bottom, and in boxes within the article, buttons for more promoted services at the left, a Flash banner at the top, ads from OAS at the lower right, a Digg button, and an email signup box. Oh, and the page refreshes itself every two minutes to change the ads.

  9. authors by Anonymous Coward · · Score: 1, Funny

    Article by Wojciech Mazurczyk and Krzysztof Szczypiorski... wow ... Did they encrypt and hide their original names ?

    1. Re:authors by Anonymous Coward · · Score: 3, Funny

      Ha...

      A Polish guy goes in for his yearly eye examination.
      The eye doctor says, "OK, read the smallest line down on the chart that you can."
      The guy reads out, "W... Z... P... X... Y... I... Z... Y... K...".
      The doctor says, "Wow, that's great, you can read the bottom line?"
      The Polish guy says, "Read it? Hell, I know the man!"

    2. Re:authors by Anonymous Coward · · Score: 0

      I laughed

  10. Original paper? by Kyont · · Score: 4, Funny

    You may also be interested in reading the original paper. CmdrTaco, you must be new here.
    --
    You shall see a cow on the roof of a cotton house.
  11. More info by Anonymous Coward · · Score: 0

    This has been looked at elsewhere:

    http://voipcc.gtisc.gatech.edu/

  12. there goes my work privacy again... by pha7boy · · Score: 1

    as more and more companies move their voice system over to VOIP, this creates an interesting dilemma: how do you prevent information leaks from secure sites when your telephone system can act as the carrier? Which probably means that we'll have more company snooping around and more "by using this system you agree that your privacy will be raped daily" forms we all have to sign when we get hired.

    --
    -- All this knowledge is giving me a raging brainer.
    1. Re:there goes my work privacy again... by Antique+Geekmeister · · Score: 1

      Telephone systems have been possible carriers for far longer than digital telephony has been around. While analog phones do not operate well below 100 cycles, they carried enough information to incorporate inaudible data at well below 20 cycles and imperciptible to your casual listener. The quality isn't good, but it doesn't have to be to bury a trigger message.

  13. Amazing! by 192939495969798999 · · Score: 4, Funny

    I didn't even know we knew what a Stegosaurus sounded like, and these guys hid its messages in VoIP traffic!

    --
    stuff |
  14. So... let me get this straight.... by Anonymous Coward · · Score: 2, Funny

    ...if you're using steganography in your VoIP data stream to imbed pr0n images, then you've invented a clever new form of digital phone sex, right?

    1. Re:So... let me get this straight.... by kcbanner · · Score: 1

      No, you didn't.

      --
      Obligatory blog plug: http://www.caseybanner.ca/
  15. VoIP doesn't just use UDP by Quattro+Vezina · · Score: 1

    While VoIP certainly can use UDP, it's also quite possible (and even common) for VoIP calls to use TCP as the transport. Hell, the original paper even mentions steganography over TCP.

    Saying "VOIP uses UDP, not TCP" is overly simplistic. RTP can run over either UDP or TCP, while SRTP runs over TLS-over-TCP.

    --
    I support the Center for Consumer Freedom
    1. Re:VoIP doesn't just use UDP by profplump · · Score: 2, Interesting

      I know people are still confused by the magic of IPSec, but seriously, UDP over IPSec is a vastly superior way to secure RTP in any situation where packets might be dropped or re-ordered. SSL+TCP+RTP might work on a LAN with lots of bandwidth to spare, but it just doesn't work across the Internet.

      I used to have an IPSec bridge to the office, with RTP running over UDP on that bridge. Everything worked great. Now my company has turned off end-user IPSec, and requires use of the Cisco SSL/TCP-based VPN client. I'm now forced to forward all calls to my cell, because phone calls over the new VPN stutter like nobody's business about 40% of the time.

  16. Typical stenographic VoIP conversation by Bovius · · Score: 1

    "Hey."
    "Hey."
    "I'm sending you a stenographically encrypted file through this call."
    "Oh, okay." ...
    "Uh, hello?"
    "Sorry, I gotta give it enough talk time to transmit."
    "Oh, gotcha." ...
    "So, how's the family?"

  17. Re:Complete article, without ads by Colin+Smith · · Score: 4, Funny

    So. You're the one paying for my internet surfing.

    Sounds like you need adblock.

    --
    Deleted
  18. Skype by Anonymous Coward · · Score: 0

    Doesn't skype use it's entire userbase to broadcast packets from the sender to the reciever? Wouldn't this allow people to communicate practically anonymously?

  19. "VoIP" is not exclusively UDP by Alarash · · Score: 2, Insightful

    VoIP doesn't "use UDP instead of TCP". VoIP (which is usually SIP+RTP, but there are other protocols out there used to carry voice over IP networks) can use UDP over TCP, and that configuration is the most common one. But not the only one possible as the article suggests.

    Also, the article in the /. article kind of suggests that VoIP (which is a concept, not a protocol) can use only UDP, which is not true. It's like saying Internet is used only for HTTP.

  20. Isn't VOIP illegal where data-hiding is needed? by Simonetta · · Score: 1

    Isn't VOIP illegal in most of the countries where data hiding needed to protect yourself from the political police?
    Telephone service is usually a government monopoly in the developing world. VOIP bypasses the government telecommunications monopoly. And since that monopoly is so profitable, the government authorities in these places violently suppress anyone that they catch using VOIP.

        What kind of information would be hidden in VOIP transmissions? General political tracts and religious books are too large for the limited space available. Specific information about meetings, such as, "Go to this address at this time and ask for Raul if you want to receive absolution from an ordained priest" in places where Christianity is illegal? Or criminal activity information, like "go to this address at this time and ask for Abdul. He'll have the bomb that you need to blow up the infidel day-care center"? Or, in the USA, drug deal information like "We received your PayPal transaction, Thank you very much. Eight grams of dynamite skunk weed for you is located in a crushed Mountain Dew can in the gutter exactly sixteen feet south east of the bus stop sign at the corner of First and Main. We will pick it up if you don't do so by 3:30pm Tuesday"? I've always wondered why simple dope dealers don't use Internet technology for anonymous untraceable transactions? Could it be because most dope dealers are stupid, or just old-fashioned?

        Why would someone want to hide information in a VOIP transmission when they could use an encrypted e-mail for the same purpose? This isn't a rhetorical question. I'd like to know your opinion. I don't have VOIP, so you'll have to take a chance and post it here.

    1. Re:Isn't VOIP illegal where data-hiding is needed? by Vegeta99 · · Score: 1

      "We received your PayPal transaction, Thank you very much. Eight grams of dynamite skunk weed for you is located in a crushed Mountain Dew can in the gutter exactly sixteen feet south east of the bus stop sign at the corner of First and Main. We will pick it up if you don't do so by 3:30pm Tuesday"? I've always wondered why simple dope dealers don't use Internet technology for anonymous untraceable transactions? Could it be because most dope dealers are stupid, or just old-fashioned?


      PayPal is anonymous?? Coulda fooled me!
    2. Re:Isn't VOIP illegal where data-hiding is needed? by sunderland56 · · Score: 2, Interesting

      You can purchase a Vonage/etc. adapter in the USA, and then plug it in anywhere in the world. This works in a lot of places that VOIP is officially "not available" - exactly where depends on the settings of that country's firewall.

  21. Patterns in the noise by StreetStealth · · Score: 3, Interesting

    It does get one thinking, though... So many things on the internet appear to be governed purely by entropy; how many of them could conceivably be used for steganographic purposes?

    Imagine a series of /. accounts set up for bots to automatically comment on stories, with an algorithm somewhere to scrape and concatenate certain characters based on a key consisting of times and offsets...

    Come to think of it, there's no reason why this necessarily couldn't be the case with some of the vast volumes of blog comment spam out there. Spread out wide enough and with a resilient enough algorithm, there could be more than enough signal to cover for the noise of spam-killed comments...

    --
    Your mind is clear / The things that you fear / Will fade with how much you / Believe what you hear
  22. Viruses will be the next safe transmitters by suitepotato · · Score: 3, Insightful

    I think the future will see the use of trojan/virus techniques to send data. It's already been fairly well proven that stopping botnets is next to impossible given current technologies, attitudes and ideas on the part of administrators and engineers, and most importantly that AI bears not a candle compared to Natural Stupidity.

    Forget just VoIP. In the future we'll hide communications networks under multiple layers of encryption inside trojan'd everything that is awfully hard to tell innocent user data from something else. We'll probably also host websites and files that way in a coalescence and then expansion of BT/P2P and anonymous remailer methods but not so much with identifiable clients but instead viral ware that people choose to allow on their machines so as to prevent privacy invasion by government and business.

    --
    If my grammar and spelling are off, I am [distracted/tired/careless] (take your pick)
  23. My VoIP is one big hidden message by gelfling · · Score: 1

    It must be cuz it sure as shit don't work right. I could reach more people sticking my head out the window and yelling than with AT&T.

  24. Serial numbers in ARP packets by karl.auerbach · · Score: 2, Interesting

    There are sometimes other places to hide data:

    I can't remember whether it was FTP Software of NetManage, but one of those used to hide the serial number of the software in the bits between the end of broadcast ARP requests and the end of the Ethernet frame.

    That way they could check for duplicate license keys on the same net without bothering anybody. Only worked across the broadcast domain, but that was adequate for that purpose.

    There's lots of other places too.

    RTP packets have optional extension headers that can be used, DNS can hold extra information in parts of the query and response packets - I once encountered someone tunneling music feed via buggered DNS packets. (It became very visible when it caused a Cisco firewall to go haywire.)

  25. Video gives more bandwidth, and DRM is an issue by hankk · · Score: 1

    Voice is one place for stego, but Video over IP can use a lot more bandwidth, and gives you more places to hide info--you can do more with the codecs, and can "hide" information in the picture itself (hey, the bad guys could use sign language.) :)

    One interesting thing about the paper is that it implies that some types of DRM mimic stego. Is this a reason to outlaw DRM?

  26. ATTACK!!! by sznupi · · Score: 2, Funny

    Say this:

    W Szczebrzeszynie chrzszcz brzmi w trzcinie.

    (note: your head may explode)

    (PS. and don't look at my nickname ;P )

    --
    One that hath name thou can not otter
  27. Great paper... to wipe your butt with by LostMyBeaver · · Score: 1

    Just read the paper. While their research is entirely sound (no pun intended), the value of their research is pretty limited.

    In circumstances like Skype (not RTP), it is possible to talk and text chat at the same time. All of it is encrypted.

    The application of this type of stegonographic message is for stored data. But for that, the data would have to be stored. There's just not point in storing a voice conversation as RTP packets on the users' system. In fact, it would be almost ridiculous to store audio in a network session specific payloaded form.

    Typically, it would be better to just store the audio as a .wav encapsulated G.711 or G.722.1 file. That would lose the RTP packets altogether while leaving the audio playable. But doing so would probably delete the hidden message.

    So far as I can tell, there's no application for using this in the real time context and if you're trying to hide your data, storing it in RTP encapsulated audio packets on disk is pretty silly since it isn't a standard file format.

    If you want to hide something, find a way to hide it in a jpeg. png, etc...

  28. Too Late by Anonymous Coward · · Score: 0

    In fact, in computing in general, there are multiple ways to sneak a couple of packets through here and there if you're willing to be patient. I'd mention a few of them, but that would probably get me on a fucked up watch list The comment above indicates that you have knowledge that may be used for espionage purposes. We're watching you...

    - Sincerely yours, the DHS.
  29. oops... by sznupi · · Score: 1

    /. comment system cut out one letter with diacritic...so, I'll just use closest thing from the roman alphabet:

    chrzaszcz

    There, should be much easier to you ;)

    --
    One that hath name thou can not otter