Live data from Hacker News

Bypassing Browser Security Warnings with Pseudo Password Fields

troyhunt.com

1–10 of 127 posts

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#2
If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data.

HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this wholly insecure connection? Who cares! Just don't let the auditor near our PBX.

Sadly, the HTTPS and IPv6 anti-vaxxer crowd is strong in the VOIP community, if it isn't severely painful to the VOIP company themselves, they aren't going to secure it. Not that they'd secure it properly anyway, even if their livelihoods depended on it...

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#3

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

What are VOIP systems used for these days? Private enthusiasts or some company call centers? I've no idea, as I haven't seen one for at least half a decade now -- even all conference calls are always over Skype or Hangouts.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#4

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

What are VOIP systems used for these days? Private enthusiasts or some company call centers? I've no idea, as I haven't seen one for at least half a decade now -- even all conference calls are always over Skype or Hangouts.

The largest VOIP companies in America today are the cable companies, ACN (pyramid scheme with a few million VOIP customers), Vonage (a first mover) then a few dozen minor players that are near the half million customer mark. IMO its a big (but unsurprising) marketing failure.

VOIP as a product never really made it into the home, despite all its features and enhancements. Instead, it is limited to the realm of businesses, where it is in most hospitals, medical facilities, chain stores, call centers, and so on.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#6
"I’ve been speaking with the owner about SSL before I invest in becoming a member, but she’s been told by the dev of the platform (it’s a franchise system called ShopCity.com) that SSL is more about Google’s monopolizing visibility of content, and less to do with security"

This is an interesting observation of how Google's technical crusades often align with its profit interests.

The main threat that HTTPS everywhere secures against is preventing your ISP from analyzing your traffic in order to build and sell an advertising profile on you.

Now, obviously that is something I don't want, so I am all for HTTPS everywhere, but Google already has that profile, so for them HTTPS everywhere is eliminating the competition.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#7

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

What are VOIP systems used for these days? Private enthusiasts or some company call centers? I've no idea, as I haven't seen one for at least half a decade now -- even all conference calls are always over Skype or Hangouts.

I'm assuming you're talking about consumer VoIP; in the corporate world, Cisco (and presumably others) do a crapload of VoIP office phones.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#8

Earlier quoted context omitted.

What are VOIP systems used for these days? Private enthusiasts or some company call centers? I've no idea, as I haven't seen one for at least half a decade now -- even all conference calls are always over Skype or Hangouts.

I'm assuming you're talking about consumer VoIP; in the corporate world, Cisco (and presumably others) do a crapload of VoIP office phones.

I also haven't seen an office phone in ages, it's just all mobiles around here.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#9

Earlier quoted context omitted.

What are VOIP systems used for these days? Private enthusiasts or some company call centers? I've no idea, as I haven't seen one for at least half a decade now -- even all conference calls are always over Skype or Hangouts.

The largest VOIP companies in America today are the cable companies, ACN (pyramid scheme with a few million VOIP customers), Vonage (a first mover) then a few dozen minor players that are near the half million customer mark. IMO its a big (but unsurprising) marketing failure. VOIP as a product never really made it into the home, despite all its features and enhancements. Instead, it is limited to the realm of busines…

All landline phone connections sold by Telekom in germany are VOIP, it's just mostly hidden from the subscriber. The technology is doing perfectly fine.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#10
post #9

Earlier quoted context omitted.

The largest VOIP companies in America today are the cable companies, ACN (pyramid scheme with a few million VOIP customers), Vonage (a first mover) then a few dozen minor players that are near the half million customer mark. IMO its a big (but unsurprising) marketing failure. VOIP as a product never really made it into the home, despite all its features and enhancements. Instead, it is limited to the realm of busines…

All landline phone connections sold by Telekom in germany are VOIP, it's just mostly hidden from the subscriber. The technology is doing perfectly fine.

VOIP and specifically SIP in its least secure form became the replacement for old tandem circuits. Sadly, rather than pushing SIP hardware out to the endpoints, most lamdline carriers chose to just provide twisted pair service.

VoLTE is as close as most consumers will get to proper VOIP service.

Post reply on HN