<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Security and authentication on the telephone</title>
	<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone/</link>
	<description>Comments on Ask MetaFilter post Security and authentication on the telephone</description>
	<pubDate>Mon, 10 May 2010 13:35:56 -0800</pubDate>
	<lastBuildDate>Mon, 10 May 2010 13:35:56 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Security and authentication on the telephone</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone</link>	
		<description>Two prominent, famous or &apos;important&apos; people talk on the telephone. How does either the caller or recipient know they&apos;re actually speaking to the real person ? &lt;br /&gt;&lt;br /&gt; For instance: Suppose the Prime Minister of Greece needs to speak to the Chancellor of Germany urgently. How would it be ensured that the person finally picking up the phone was really the Chancellor ? How could the Chancellor know it&apos;s really the Prime Minister on the other end ?&lt;br&gt;
&lt;br&gt;
Would there be code words used between their personal assistants when the call is placed and received ? How would the authentication be done ?&lt;br&gt;
&lt;br&gt;
Substitute those two with different people who may have had even less of a connection previously: maybe the CEO of BP taking a call from the Governor of one of the areas threatened by the recent oil spill ? Or Warren Buffett and the director of a company he&apos;s been rumoured to be considering buying a stake in ?&lt;br&gt;
&lt;br&gt;
Impersonating someone&apos;s voice (especially someone in the public eye), rerouting landline phone numbers, stealing someone&apos;s mobile phone (or at least the sim) etc. don&apos;t seem insurmountable hurdles if someone was determined.&lt;br&gt;
&lt;br&gt;
Obviously as a prank it might just be a waste of a few minutes, but in delicate discussions it could be much more than that.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2010:site.153501</guid>
		<pubDate>Mon, 10 May 2010 13:30:52 -0800</pubDate>
		<dc:creator>selton</dc:creator>
		
			<category>telephone</category>
		
			<category>security</category>
		
			<category>authentication</category>
		
			<category>prank</category>
		
			<category>resolved</category>
		
	</item> <item>
		<title>By: dfriedman</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200294</link>	
		<description>I have worked in the past with people who worked for an A-list name.  Basically, these people answered all of his calls and screened the calls for him.&lt;br&gt;
&lt;br&gt;
When another A-lister wanted to get in touch with this A-lister, my understanding was that the second A-lister&apos;s personal assistant/secretary would contact the first A-lister&apos;s personal assistant/secretary and say, essentially, &quot;A-lister #2 is on the line for A-lister #1.&quot;&lt;br&gt;
&lt;br&gt;
Etc.&lt;br&gt;
&lt;br&gt;
This was in the business/political world.  It may be different in the celebrity world.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200294</guid>
		<pubDate>Mon, 10 May 2010 13:35:56 -0800</pubDate>
		<dc:creator>dfriedman</dc:creator>
	</item><item>
		<title>By: Cool Papa Bell</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200296</link>	
		<description>There have been a few cases where pranks have occurred. &lt;a href=&quot;http://www.msnbc.msn.com/id/27489929/&quot;&gt;Sarah Palin took a prank call.&lt;/a&gt; I think George Bush was a victim once, too...?&lt;br&gt;
&lt;br&gt;
In reality, calls like these are arranged by subordinates on both sides, who can authenticate by pre-arranged ID systems, like Caller ID on steroids. There could also be &lt;a href=&quot;http://en.wikipedia.org/wiki/Moscow%E2%80%93Washington_hotline&quot;&gt;dedicated lines&lt;/a&gt; involved.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200296</guid>
		<pubDate>Mon, 10 May 2010 13:37:15 -0800</pubDate>
		<dc:creator>Cool Papa Bell</dc:creator>
	</item><item>
		<title>By: phrontist</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200455</link>	
		<description>&lt;em&gt;who can authenticate by pre-arranged ID systems, like Caller ID on steroids.&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
This is what the OP is asking about, I think. Can you elaborate?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200455</guid>
		<pubDate>Mon, 10 May 2010 15:24:58 -0800</pubDate>
		<dc:creator>phrontist</dc:creator>
	</item><item>
		<title>By: Civil_Disobedient</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200459</link>	
		<description>At some point it will boil down to a public listing of some sort, like the toll-free telephone number to the corporate headquarters that&apos;s then transferred from secretaries up the chain of command.&lt;br&gt;
&lt;br&gt;
Kind-of like, I call your public number and tell you my public number&apos;s CEO wants to talk to your public number&apos;s Governor.  Would you please call me back at my publicly-listed number to confirm?  It is an interesting question of distributed trust.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200459</guid>
		<pubDate>Mon, 10 May 2010 15:28:34 -0800</pubDate>
		<dc:creator>Civil_Disobedient</dc:creator>
	</item><item>
		<title>By: Xalf</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200461</link>	
		<description>&lt;a href=&quot;http://www.slate.com/id/2204245&quot;&gt;Slate&apos;s Explainer explains&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200461</guid>
		<pubDate>Mon, 10 May 2010 15:31:36 -0800</pubDate>
		<dc:creator>Xalf</dc:creator>
	</item><item>
		<title>By: rokusan</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200483</link>	
		<description>&lt;i&gt;It is an interesting question of distributed trust.&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
It&apos;s boggling how many large, reputable organizations don&apos;t have this basic security hole figured out. I have brushed off calls that, I suppose, &lt;i&gt;might have been&lt;/i&gt; from my bank or credit card company because they phoned me and then asked me to verify my identity.&lt;br&gt;
&lt;br&gt;
&quot;Ma&apos;am, you called me. I don&apos;t know who you are. I&apos;m not giving you personal information.&quot;&lt;br&gt;
&lt;br&gt;
As Civil says, public numbers are very useful in fixing this trust problem, and are certainly used as a single-party piece of the solution. The fact caller ID is so easily spoofed still makes this inadequate for &lt;i&gt;both&lt;/i&gt; parties, though, which is why the call me back at this other public/verifiable number is the easiest route.&lt;br&gt;
&lt;br&gt;
See also, seriously, &lt;a href=&quot;http://www.youtube.com/watch?v=Gy_cLJ19HMg&quot;&gt;Kevin Smith calls Prince&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200483</guid>
		<pubDate>Mon, 10 May 2010 15:52:26 -0800</pubDate>
		<dc:creator>rokusan</dc:creator>
	</item><item>
		<title>By: ocherdraco</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200585</link>	
		<description>Certain people are instantly recognizable on the phone.  Once, Dan Rather called my direct line (trying to reach someone else; I don&apos;t know why he called me) and it was ABUNDANTLY CLEAR that it was actually Dan Rather.  There was just no mistaking his voice, and an imitator couldn&apos;t have gotten that close.  I think there are probably several public figures like that.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200585</guid>
		<pubDate>Mon, 10 May 2010 17:19:16 -0800</pubDate>
		<dc:creator>ocherdraco</dc:creator>
	</item><item>
		<title>By: Oriole Adams</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200745</link>	
		<description>&lt;a href=&quot;http://www.laurasnyctales.com/current/chris-rock.html&quot;&gt;This person got Chris Rock&apos;s old cell phone number&lt;/a&gt;. Spike Lee and Adam Sandler called her directly; Jerry Seinfeld and Jack Nicholson had assistants do the dialing.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200745</guid>
		<pubDate>Mon, 10 May 2010 20:07:24 -0800</pubDate>
		<dc:creator>Oriole Adams</dc:creator>
	</item><item>
		<title>By: aqsakal</title>
		<link>http://ask.metafilter.com/153501/Security-and-authentication-on-the-telephone#2200887</link>	
		<description>Been there, done that.  The subordinates (PAs, Principal Private Secretaries, etc.) of A-class people already know each other, at least by phone if not personally, and will chat briefly for a moment before passing the call &quot;up&quot; to the boss.  If they&apos;re calling someone to whom they have no personal contact (say, a newly-elected prime minister), they&apos;ll first go to somebody they know personally, who will pass the call on with a confirmation that it&apos;s kosher.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2010:site.153501-2200887</guid>
		<pubDate>Tue, 11 May 2010 01:14:33 -0800</pubDate>
		<dc:creator>aqsakal</dc:creator>
	</item>
	</channel>
</rss>
