Early this year, reports revealed that Yealink had suffered from a critical security gap in the provisioning technology for their IP phones. This gap left countless businesses wondering how they could once again secure their voice conversations and prevent criminals and outside parties from gaining access to their sensitive information.
NFON AG, leading pan-European cloud PBX provider, was informed by the IT security company VTRUST about the security gaps in the auto-provisioning process of the VoIP phone manufacturer Yealink. Chief Technology Officer of NFON AG, Jan-Peter Koopman, talked to me about the new two-factor authentication solution that is now available with Yealink's SIP phones.
How Did This Solution Come About?
[caption id="attachment_27366" align="alignright" width="200"]
Jan-Peter Koopmann[/caption]
The NFON technology available for Yealink delivers a two-factor authentication method for authentication and security within the IP environment. Jan-Peter Koopman, who has been with NFON since 2009, told me that NFON had been monitoring the security of the Yealink platform for a few months before the new two-factor authentication (2FA) solution was delivered.
“In August of last year, there was a security breach on VoIP-phones from many manufacturers including Yealink. We’ve been alert to the potential of a security issue since then. In September, we were approached with the much more serious security problem regarding safe provisioning. VTRUST approached us and we immediately took this seriously because it’s in our DNA to make sure that the cloud services that we deliver are as secure as possible.”
NFON operates on the principle of safety first, carrying out regular audits of their platform and working continuously on further opportunities for improvement. Based on analyses, NFON was able to further develop the authentication of Yealink devices to meet the highest standards for the future and guarantee a better level of security for customers.
Describe the Potential Impact on the End-User
According to Koopman, the basic challenge with most IP devices is figuring out how to make them work in a fashion that’s easy for end-users, while simultaneously making sure that information doesn’t get into the wrong hands. The first thing that businesses need to do is ensure that everything is secure and encrypted. The next stage is making sure that the authentication is there.
“We need to make sure that the request that reaches us is coming from wherever it’s supposed to be coming from. The presumption before now has been that this security is provided by the phone manufacturer. However, this isn’t always the case."
"Attackers can authenticate themselves to provisioning services and claim that they’re using a Yealink phone. You wouldn’t necessarily be able to tell the difference”
If a caller can authenticate themselves to the provisioning service, then they can potentially access a lot of sensitive information, spoof an IP system and compromise an entire platform. Yealink has already seen this issue, but something that can happen to a great company like Yealink is likely to happen to others as well.
What Are You Doing to Counter This Issue?
NFON has invested a substantial amount of development resources into the creation of the right two-factor authentication tools to close the security gap encountered by Yealink. Rather than just relying on the authentication messages sent by a device to the provisioning service, this means that NFON is introducing a second layer of security.




