Earlier quoted context omitted.
I'm assuming you're talking about consumer VoIP; in the corporate world, Cisco (and presumably others) do a crapload of VoIP office phones.
I also haven't seen an office phone in ages, it's just all mobiles around here.
Bypassing Browser Security Warnings with Pseudo Password Fields
11–20 of 127 posts
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#12Earlier quoted context omitted.
I'm assuming you're talking about consumer VoIP; in the corporate world, Cisco (and presumably others) do a crapload of VoIP office phones.
I also haven't seen an office phone in ages, it's just all mobiles around here.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#13If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…
I've literally seen a college have admin credentials hosted on a publicly addressable plaintext document just so that their new machines can netboot. And that's just one, quick, story out of dozens upon dozens I have.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#14What's preventing these types from doing so?
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#15Earlier quoted context omitted.
I also haven't seen an office phone in ages, it's just all mobiles around here.
It's because you don't do bulk calls. Sells, support, orders, etc. They all need office phones at a certain scale. Not that they couldn't do it with mobiles. But infrastructures for those kind of systems all assume a land line.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#16If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…
In my experience, the entire world runs on insecure systems (and will continue to do so until companies start getting sued into oblivion for leaking data). Secure systems are the exception--not the norm. It's just not a priority because companies only prioritize things that "add value". So until we attach a real cost to lack-of-security, it won't be valued. I've literally seen a college have admin credentials hosted…
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#17Earlier quoted context omitted.
I also haven't seen an office phone in ages, it's just all mobiles around here.
I've worked for pretty much every type of company except VC-funded Silicon Valley style start-ups since about 2008. Every desk I've ever sat at, including the one I'm at now, has had a VoIP phone sitting on it.
For added fun, the site looked like this at the time https://web.archive.org/web/20110207225932/http://nestlabs.c...
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#18Surely it would be easier to just get a cert. What's preventing these types from doing so?
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#19Surely it would be easier to just get a cert. What's preventing these types from doing so?