[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Secure RTP -- end user experience





Peter, I'm very curios to get an idea how people view the right way to deploy this - i assume we are talking about your firewall like product - do you plan to run ZRTP in the "bump in the wire mode" or does the box modify the SIP signaling and use ZRTP in the signaling associated mode? Most the ZRTP supports seem to prefer the bump in wire mode and I'm just trying to get a handle on some of the discussion about if the signaling associated mode is viewed as a good optional thing to ZRTP or something that should be mandatory to implement and use?


On Mar 13, 2007, at 7:20 PM, Peter Cox wrote:


Other than a posting by Craig Southeren there has been little discussion on the end-user environment in which secure RTP will be deployed. VoIP systems are deployed in environments where the end-users expect them to "just work", users are far less tolerant of what in their mind are intruding details than users of web and email systems, even when those users are the same people. A lifetime's experience with the PSTN means that VoIP users just want to pick
up the phone, dial and get connected.

The majority of those calls will be about non confidential matters, but when more sensitive issues are discussed users want a simple check that their conversation is secured end-to-end, the ZRTP SAS provides this in a form that is easy for the average end-user to understand. For the end- user the SAS is the analogue of the light on the phones used in cold-war spy movies,
the light flashed when the line was secure.

To declare an interest, Borderware is implementing ZRTP using Phil's
toolkit. This protocol was chosen because of its ease of use and because it
provides exactly what is needed to encrypt a VoIP call, ephemeral keys
negotiated without the overhead and complexity of certificate management.

While not minimising the importance of getting the protocol details right, factors like end-user acceptance, ease of use and ease of implementation are
also important. From this point of view ZRTP gets my vote.

------------------------------------------------------------------
Peter Cox                                  Phone: +44 20 8759 1999
CTO International                            Fax: +44 20 8757 1998
Borderware Technologies Inc              http://www.borderware.com