Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Security on CDMA for Banking Applications

Subject: Re: Security on CDMA for Banking Applications
Date: Wed, 30 Mar 2005 09:43:18 +0200
On Tuesday 29 March 2005 22:17, Nick Owen wrote:
I would add to this that each carrier has different network
configurations that can affect security.  

Yes, you're quite right. I assumed (unnecessarily) we were talking about a 
radio link directly managed by the bank with no carriers involved. This is 
not necessarily the case. If a carrier is supplying the link, they must be 
involved in the security setup. The best way is to ask for a transparent 
radio link, pure and simple linking. Whatever gets in on one side, gets out 
on the other (be it voice, data, IP, ATM, or a proprietary protocol).


Just to complicate things, one carrier wouldn't take our encrypted
messages unless we said it was a bitmap image ;).

;-) 

I wonder why they would do so. A carrier shoud be a ... carrier. If they stick 
their nose in what they carry from point A to point B, they might loose their 
status of "common carrier" (the same status airlines, post offices and the 
like enjoy all other the (free) world).  Just like the post office doesn't 
ask you what's inside the envelope you mail through them, as long it is of 
standard size,  I don't see a reason for a carrier (or even an ISP) to get 
into what is a (say) an IP packet as long it is correctly formatted.

In some EU member states they also try to resist the idea of encrypted traffic 
being fed into networks (the idea being that it would make it more difficult 
for police agencies to monitor (legally) such traffic). Yet, it's not really 
enforced.

-- 
Alessandro Bottonelli
Axis-Net (Privacy & InfoSec Consulting)
Tel. +39 02 93595859
Fax. +39 02 93590544
Web. http://www.axis-net.it

<Prev in Thread] Current Thread [Next in Thread>