- 1
- 2
- 3
- < previous
- next >
What about security?
One reason for having the VOIP phones on a separate VLAN is we firewall it. It turns out all these phones have Web servers -- not browsers -- in them and one way to configure them is to talk directly to the phone. All you need is the phone admin password, which is the same one in every phone and it's in the manual, so we don't let Web connections get to the VOIP phones, so security is at that level. I would love it if the phones would encrypt the voice stream. They don't do that today and there's nothing I can do about it except indicate to the vendors that I really want that feature and hope we'll even get it. It's a concern. But so are cell phones. If there hadn't been cell phones I'd be much more worried. We don't want to go overboard on something that's not a real threat yet.
If I put my IETF hat back on, VOIP security in general has been a real disaster. Like everyone who does technology, the VOIP vendors don't want to think of security when they're designing, and they aren't convinced the bad guys are really out there just because they're not attacking yet (and of course they won't attack until you have 100 million handsets out there to make it worth their while). The other problem with VOIP is that there have been a lot of Bellheads involved and they have a security model that's completely whacked -- the "trust the network" model. In the Internet space you don't trust anybody, particularly the network. You better do end-to-end security if you care.
Then there's the whole damn government. I don't know this but I suspect if the Polycoms and Ciscos of the world had had these phones do end-to- end encryption on Day 1, then the U.S. government probably would have come in and tried to stop it. They want to maintain the ability to do surveillance even if we all have to walk around naked.
OK, on to project No. 2. What's MIT doing to become a regional optical network player?
Through an arrangement with Internet2 and their FiberCo arrangement we have a pair of fibres from Boston down through Rhode Island, Connecticut and eventually terminating at 32 Avenue of the Americas in New York City, and a redundant pair up the Hudson River and that cuts across Massachusetts. We got it at a price we could afford, so we went for it. We're lighting it up with optical gear that will give us 72 10G waves. This means in New York City we can peer with CERN and with a lot of the major players. The contract for our fibre wasn't 24 hours old when through the grapevine our researchers found out about it and were enthused about using it for high-speed access to various national and international assets.
MIT doesn't already have access to high-speed links for research through Internet2 or other networks?
Internet 2 backbone now is 10G I think, and links to this part of country are around 1G. Our researchers want 10G to CERN and now we can give them that. We also did this before Internet2 announced its new network [which had gone by the working name NewNet and boasts 10G lambdas].
I'm very annoyed about the competition that emerged between Internet2 and the National LambdaRail network people. It was a national embarrassment that literally got down to name calling. The networks were going to merge but turned out to be like water and oil, so now they're competing. A side effect was that the Internet2 people didn't talk to us before they announced one of their NewNet nodes would be in Boston, so now we're in the same facility as them. Even so, we're still getting a better deal on price to get to New York City. Meanwhile, we have a history of cooperation in the Boston area with other schools, such as Boston University and Harvard, such as through the Northern Crossroads facilities. Some asked why we didn't buy the new fiber under Northern Crossroads, but it was just a timing issue: We had the money and couldn't wait for approvals from the others.
This all sounds too easy ...
It wasn't. It's amazingly complicated. First the IRU [Indefeasible Right to Use] agreements, and it's Level 3 fibre, so we have to sign agreements with them. And it's not just the fibre, you have to get space in huts along the fiber path to put in regeneration and optical amplification equipment [Nortel installs most of the equipment]. It turns out there's paperwork to be done for each of those sites, plus lots of legal contracts. And we're a nonprofit organization, so we need to file paperwork in every single township along the way to demonstrate this.
- 1
- 2
- 3
- < previous
- next >
ScrumMaster offers tips on how to play in a winning dev team
How spyware nearly sent a teacher to prison
Open source identity: Asterisk founder and Digium CEO Mark Spencer
Fighting e-waste one mobile phone at a time
MIT's JoAnne Yates on information overload, 'CrackBerry' addicts and the 'always online' life
Read up on the latest ideas and technologies from companies that sell hardware, software and services. The state of Middleware
Delivering the Power of Choice with Microsoft Dynamics CRM
Everything you need to know about email and web security (but were afraid to ask)
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Best Practice in Building an Integrated Information Management Strategy
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Solve Exchange Mailbox Storage Issues Once and for All
Email Archiving Implementation: Five Costly Mistakes to Avoid
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
How to improve employee productivity in small and medium businesses
U.S. businesses lose 5.4 billion productive hours through employees searching for information annually. Avoid the same inefficiencies occurring in your business. Read on to discover the productivity issues facing SMBs and how the Oracle Application Express (APEX) can improve employee productivity and enhance development efficiencies.












