Security experts say voice mail systems vulnerable
Computerworld -
Security consultants aren't surprised that someone managed to take a voice mail Hewlett Packard Co. Chairwoman and CEO Carly Fiorina left for HP Chief Financial Officer Robert Wayman last month and transmit it to the world.
Voice-mail systems and phone rooms tend to have less security than other sensitive areas in companies, and the four-digit personal information numbers used to guard access to user's messages can be easily cracked.
"My guess is that this info was obtained simply by guessing [Wayman's] password," said Todd Tucker, director of security and architecture at Pentasafe Security Technologies Inc. in Houston.
The San Jose Mercury News said it received the voice-mail message, in which Fiorina told Wayman she was worried about the outcome of the March 19 proxy vote on the HP/Compaq Computer Corp. merger, from an anonymous caller. HP has had little to say about the incident except that the message was genuine and that it takes the dissemination of private company communications quite seriously (see story).
But Tucker and others think HP has learned a lesson that all companies should take to heart.
"I think the biggest thing is that we continue to have wake-up calls on how security and privacy needs to be addressed, and this is definitely a wake-up call," said Rick Shaw, president of CorpNet Security Inc. in Lincoln, Neb. "Companies do not always cover their voice-mail systems with the same critical level that they would with the networks. The bottom line is ever since we started digitizing, voice mail it is just another file sitting on a server."
As such, Shaw said that anyone who can access that server can listen to whatever voice-mail messages are there. He said it isn't "that difficult" to go looking around on voice-mail servers and poking into different files to see what's vulnerable.
If the intruder finds something interesting, then downloading that information and spreading it to the rest of the world is even easier, Shaw said.
Another way companies leave themselves vulnerable is that they use systems right out of the box without configuring them for added security, said David Losen, director of secure systems at Sergeant Laboratories Inc., in La Crosse, Wis.
"If you do it right out of the box and think you are good to go, then you probably aren't," Losen said. He noted that it also depends on what kind of system companies use for voice mail, as some systems are left "wide open" to attack.
There is also a human element at play, Tucker said. People
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

