Slashdot Mirror


Compressed VoIP Calls Vulnerable To Bugging

holy_calamity writes "Security researchers at Johns Hopkins report that a variable bit-rate compression scheme being rolled out on VoIP systems leaves encrypted calls vulnerable to bugging. Simpler syllables are squeezed into smaller data packets, with more complex ones taking up more space; the researchers built software that uses this to spot phrases of interest in encrypted calls simply by measuring packet size."

19 of 140 comments (clear)

  1. Re:Do what my grandparents do by smitty97 · · Score: 5, Funny

    That or you could just learn Russian... I don't think they *have* any simple-syllable words in Russian :-) In Soviet Russia, VoIP bugs you!
    --
    mod me funny
  2. Evasive, ummm, technology by martyb · · Score: 4, Funny

    FTFA

    In tests on example conversations, the software correctly identified phrases with an average accuracy of about 50%. But that jumped to 90% for longer, more complicated words. Wright thinks these phrases may be the most important. "I think the attack is much more of a threat to calls with some sort of professional jargon where you have lots of big words that string together to make long, relatively predictable phrases," he says. "Informal conversational speech would be tougher because it's so much more random."

    So, ummm, what we should do to, umm, well, protect ourselves from, ummm, yaknow, eavesdroppers, heh-heh, is well, make sure there's enough, ummmmmmm, yaknow, like extra noise, like, mixed in, dude.

    1. Re:Evasive, ummm, technology by gstoddart · · Score: 4, Funny

      So, ummm, what we should do to, umm, well, protect ourselves from, ummm, yaknow, eavesdroppers, heh-heh, is well, make sure there's enough, ummmmmmm, yaknow, like extra noise, like, mixed in, dude.

      Oh my god, thats like, totally, like, a great idea, yaknow. I mean, like, they'll never figure out what we're, like, saying, yaknow?

      Oryoucouldspeakreallyfastwithoutpausesbetweenwords. Thatwaythey'llneverknowwhatyousaid =)

      Or. We. Could. All. Speak. Like. Shatner. Random. Long. Pauses. Genius.

      Cheers
      --
      Lost at C:>. Found at C.
    2. Re:Evasive, ummm, technology by Anonymous Coward · · Score: 2, Funny

      Or. We. Could. All. Speak.
      Like. Shatner. Random. Long.
      Pauses. Genius.


      You're missing one syllable in the middle line...


  3. Here's a thought by mhall119 · · Score: 1, Funny

    Encrypt the data first, then compress it.

    --
    http://www.mhall119.com
    1. Re:Here's a thought by Anonymous Coward · · Score: 1, Funny

      I just threw something together in Python that will compress encrypted data at a near 1:1 ratio.

    2. Re:Here's a thought by oodaloop · · Score: 3, Funny

      Voice data just CAN'T be securely encrypted. Really? I have a Top Secret phone on my desk, and I can assure you it's pretty secure. (And no, it's not a shoe.)
      --
      Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
    3. Re:Here's a thought by gstoddart · · Score: 2, Funny

      In case you can't figure it out: good encryption makes data look completely random. Do you know of any algorithms which compress PURELY RANDOM data? I sure as hell don't.

      Sure, drop every other byte. It'll be half as big. ;-)

      Cheers
      --
      Lost at C:>. Found at C.
  4. Re:Easy Solution: by Daimanta · · Score: 4, Funny

    ""Music in the background" is not a security solution. In fact, that's a freaking joke."

    Yes, but a joke you can dance on.

    --
    Knowledge is power. Knowledge shared is power lost.
  5. Re:Do what my grandparents do by markana · · Score: 4, Funny

    >That or you could just learn Russian... I don't think they *have* any simple-syllable words in Russian :-)

    Da!

  6. Re:Do what my grandparents do by mlwmohawk · · Score: 3, Funny

    Just speak arabic!! We already know the FBI and CIA don't have enough translators.

  7. Re:Do what my grandparents do by hummassa · · Score: 3, Funny

    That or you could just learn Russian... Which would give you an advantage, if you ever have to pilot a bleeding-edge mind-controlled Russian jet fighter.

    --
    It's better to be the foot on the boot than the face on the pavement. ~~ tkx Kadin2048
  8. Re:Easy Solution: by martin_henry · · Score: 3, Funny

    Awesome....a VOIP dance party.

    --
    www.purevolume.com/martyd
  9. Re:Do what my grandparents do by Anonymous Coward · · Score: 1, Funny

    Da!

  10. solution by obfuscation... heh. by Anonymous Coward · · Score: 1, Funny

    Merely utilize the stupendous wealth of complex language alternatives located in the voluminous expanse of your thesaurus to inflate your unimportant topics of conversation to prodigious lengths, and leave the vital ones to sound so simple they don't pay them any notice!

    Anyway, what's the use of this? "Oh wow, they must be talking about something interesting. Now if I only knew what they were saying..." The simple fact that the communication is being encrypted would allude to that.

  11. Re:Easy Solution: by gstoddart · · Score: 2, Funny

    Easy Solution. Music in the background.

    Oh, sure, give the RIAA reason to get involved in encrypted phone calls.

    They'll try to make sure you're not using unlicensed music to mask your conversations. We'll be seeing John Doe subpoenas to get access to what music you were playing. :-P

    I'm only half joking.

    Cheers
    --
    Lost at C:>. Found at C.
  12. ode-cay by fahrbot-bot · · Score: 3, Funny

    Ust-jay eak-spay in ode-cay.

    --
    It must have been something you assimilated. . . .
  13. Re:Do what my grandparents do by Samizdata · · Score: 2, Funny

    I worked for a set of commodity trader brothers back in the 80's. One of them, who worked as their corporate attorney, was in a Club Fed for tax issues.

    I saw more than one threat from the Bureau of Prisions warning them to stop using Latvian (their native tongue) during phone calls to the incarcerated.

    --
    It's not the years, honey, it's the mileage. - Colonel Henry Walton Jones, Jr., Ph.D.
  14. Re:This is compressed, encrypted VOIP by 6Yankee · · Score: 2, Funny

    the buggers in government

    Oooh. Well played, Sir, well played.