Thursday, October 28, 2004

Do you trust caller ID? 

It's long been an open secret in the security world that a bad or just plain mischievous person can make whatever they want appear on your caller ID display when they call you. The last few years, it's been getting even easier than it used to be.

Today it's really easy. Anyone can fake their caller ID information now for a small fee. There's a website (excuse me if I don't give you the address) where an attacker can type in the phone number he wants to call, the number he wants to pretend the call is from, his real phone number and some payment information. When he submits the data, his phone rings and when he picks up he'll hear the bogus call going through.

The moral is that all caller ID is good for is deciding whether to pick up the phone. You can't make important decisions based on what caller ID tells you.

|

This page is powered by Blogger. Isn't yours?