SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    VOIP signal transmission security - which is better?
Go
New
Find
Notify
Tools
Reply
  
VOIP signal transmission security - which is better? Login/Join 
Member
Picture of konata88
posted
I'm converting from POTS to AP-A (ATA) based VOIP next week. The AP-A unit supports both cellular and ethernet for signal transmission. Seems like I can use both (unit uses cellular unless signal strength is poor then used ethernet?) or one of them (disable cellular by removing the antenna? disable ethernet by not connecting the lan cable).

From a security / device, network hacking / privacy perspective, is one better than the other (use one and disable the other)? Or should I be relatively indifferent and just let it choose?

At my location, cell signal may be spotty unless it the unit uses 5G (I don't know the signal strength for that at my location; my cell phones are 5Ge or 4G LTE). But seems like my home network would be safer if the unit is not connected to LAN (I could put it on my "junk" home LAN to isolate from my other primary devices but that may make it more susceptible to hacking).

Ethernet would be more robust and consistent but I'm concerned about hacking - I don't think the unit is going to be very secure as a plug-n-play device without any administrative configuring.

Thoughts?




"Wrong does not cease to be wrong because the majority share in it." L.Tolstoy
"A government is just a body of people, usually, notably, ungoverned." Shepherd Book
 
Posts: 14930 | Location: In the gilded cage | Registered: December 09, 2007Reply With QuoteReport This Post
SIGForum Official Hand Model
Picture of ThankGod4Sig
posted Hide Post
If you’re worried about who is listening on your cell phone calls, well there bub you must be important.


"da evil Count Glockula."-Para
 
Posts: 8006 | Location: C-bus, Ohio | Registered: December 17, 2004Reply With QuoteReport This Post
Member
Picture of konata88
posted Hide Post
Thanks. While I wouldn't find that desirable either, I actually concerned about the AP-A unit as an IOT device being used as an entry point onto my home LAN to hack into my computers which are used to access my bank accounts, etc. Some IOT units (ie - some chicom company products) are known exposure points with malware built into them.




"Wrong does not cease to be wrong because the majority share in it." L.Tolstoy
"A government is just a body of people, usually, notably, ungoverned." Shepherd Book
 
Posts: 14930 | Location: In the gilded cage | Registered: December 09, 2007Reply With QuoteReport This Post
Optimistic Cynic
Picture of architect
posted Hide Post
quote:
Originally posted by konata88:
Thanks. While I wouldn't find that desirable either, I actually concerned about the AP-A unit as an IOT device being used as an entry point onto my home LAN to hack into my computers which are used to access my bank accounts, etc. Some IOT units (ie - some chicom company products) are known exposure points with malware built into them.
This is a very valid concern. Many brands of "routers" and other in-home network devices ship with widely-known vulnerabilities that can be remotely exploited. This is not limited to Chicom products.

If you select a VoIP provider that will give you a VPN tunnel to their "central office," and firewall any in-the-clear data to your internal device, you will be well ahead of the game.

A general-purpose upstream encrypted tunnel from your router to some remote egress point would perform a similar function for your entire LAN, you wouldn't need to do both (assuming that the AP-A does not offer this functionality).

By concealing the origin of your network traffic, you go a long way to preventing most direct attacks against your internal network devices. Of course, you may want to get into your LAN yourself, for monitoring webcams, alarm systems, etc. or just to gain access to your "stuff." This would open an attack surface that has to be secured, but it is possible to do.

Overall, it is a delicate balancing act, how much time and money do you want to spend securing your stuff vs. what it is worth to a potential compromise. Most people aren't worth the time to hack. As AI and improved compromise tools evolve, this bar will get lower over time. There are a lot more potentially vulnerable points of access than your voice communications equipment.

As far as radio vs. wired is concerned, IMO wired will always be "more secure" due to its not broadcasting its data transmissions to everyone in the world who owns an antenna.
 
Posts: 8057 | Location: NoVA | Registered: July 22, 2009Reply With QuoteReport This Post
Ammoholic
posted Hide Post
quote:
Originally posted by ThankGod4Sig:
If you’re worried about who is listening on your cell phone calls, well there bub you must be important.
I’ve got a similar reaction to konata88 - If some idiot wants to listen to what is is that my lovely bride wants me to pick up in town or whatever nonsense the kids are getting up to, who cares? If someone wants to hack into my home network, that I might care about…
 
Posts: 7841 | Location: Lost, but making time. | Registered: February 23, 2011Reply With QuoteReport This Post
Member
Picture of konata88
posted Hide Post
Architect: Thanks for your insights. Unfortunately, I'm not very technical and so I don't really know how to confirm whether my router or the AP-A is configured / capable of providing the protections you described. Or how to implement if not.

I don't generally access my LAN from outside; exception is the webcam but not sure if I'm accessing the device or the cloud. Perhaps the former but the opening in my LAN is done by the webcam device.

I have two routers attached to my modem. I'll perhaps the AP-A to my "junk / guest" router LAN; the primary house LAN w/ my computers and stuff can remain isolated, converging at the WAN modem.

I was torn between wired and cellular - I was thinking the wired may be harder to hack but it's shared w/ my important computers (but won't be if I put the AP-A on the junk LAN). Whereas the cellular and the AP-A aren't connected to my LAN at all if I don't connect the ethernet cable. But then the VOIP service may be spotty if the cell service is spotty / congested.

I'll setup the unit with wired (junk LAN) and cell and see which the unit prefers and test the VOIP QOS.

Since it sounds like I do have a valid concern, the AP-A will not be on the router shared with my computers; hopefully that adds another layer of security.

The possible positive - sounds like the AP-A unit is OEM'ed by a company in FL (American company).




"Wrong does not cease to be wrong because the majority share in it." L.Tolstoy
"A government is just a body of people, usually, notably, ungoverned." Shepherd Book
 
Posts: 14930 | Location: In the gilded cage | Registered: December 09, 2007Reply With QuoteReport This Post
  Powered by Social Strata  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    VOIP signal transmission security - which is better?

© SIGforum 2026