和谐英语

您现在的位置是:首页 > 英语听力 > 英语听力材料

正文

使用电话银行存在的风险

2010-02-10来源:和谐英语

'Welcome to the Internet banking support service. To reset your security details please press 1. For all other enquiries press 2.'

Banking by telephone is hardly new. But it's not so much old-fashioned phones that have caused the banks problems as computers. They've allowed criminals to do from home what they used to do with a mask and a sawn-off shotgun. So now that telephony is moving onto the net should we be worried?

The real problem with VOIP is that it means that the telephone system is now going to be as secure as the Internet.

In other words yes, very worried. The Grug as he styles himself is a leading security expert specialising in Internet telephony or VOIP as it is often called.

What I expect we are going to be seeing in a few months, and what's already technically possible, is for an attacker to gain access to a call centre.

Because Internet telephony is software based it's vulnerable to hacking and it offers a way in for attackers with potentially serious consequences.

An attacker would be able to break into the call centre. He could then set up a server which would monitor all of the traffic and during the hold music it would be possible for an attacker to inject content such as, 'in order for us to better serve you please enter your account number and pin code.'

When I caught up with the Grug he was in Malaysia for the Hack In The Box Security Conference where he both gave a key note speech and held training sessions for security professionals.

In my training class I actually have several guys from banks who are freaking out because they had showed up hoping to learn how to secure VOIP and deploy VOIP internally within their own infrastructures. And they have learned that but they have also found out that that's not going to be enough. They need to make sure that everywhere, everyone who has a VOIP system that is connected to the Internet is secure. Otherwise the entire system falls apart. It's basically a house of cards.