Ask the Expert

Can an attacker gain mobile device data through a peer-to-peer (P2P) network?

Can an attacker gain important and private information from my phone through a peer-to-peer network?

    Requires Free Membership to View

Peer-to-peer telephone services, such as Skype, Free World Dialup (FWD) and Ooma, offer users a way to save significant money on telephone services. By leveraging peer-to-peer networks to route calls around the world, every call becomes a local one.

While this is an interesting technology, I would not recommend that it be used for any private communications. Peer-to-peer services allow telephone calls to be routed through the privately owned equipment of one or more unknown individuals. This raises a number of confidentiality, integrity and availability concerns, and little information is available about what, if any, security controls these services have put in place to protect your telephone calls.

Would you be upset if an unknown third party was able to eavesdrop on your call? What if they were able to reroute it to a different destination? Or if they were able to disrupt your service? If the answer to all three of these questions is "no," then by all means give peer-to-peer telephone a shot. Otherwise, until the security implications are addressed, you probably want to think twice about adopting this emerging technology.

For more information on peer-to-peer VoIP security, read Skype: Its dangers and how to protect against them elsewhere on this site.

More information:

  • In a Security Wire Weekly podcast, Andrew Christensen of FortConsult explains how the Tor peer-to-peer network can be hacked.
  • A SearchSecurity.com reader recently asked Mike Chapple, "What warning signs will indicate the presence of a P2P botnet?"
  • This was first published in January 2009

    There are Comments. Add yours.

     
    TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

    REGISTER or login:

    Forgot Password?
    By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
    Sort by: OldestNewest

    Forgot Password?

    No problem! Submit your e-mail address below. We'll send you an email containing your password.

    Your password has been sent to: