20 Years of SIP – A Retrospective
jdrosen.net
jdrosen.net
In practice the fundamentals of WebRTC rely on things like ICE, STUN, and TURN for media so they're not going to be compatible with almost all existing SIP implementations - many of which can't even do interop with bog-standard vanilla SIP over UDP with standard codecs properly.
As is often the case with SIP you're back to using some Session Border Controller or equivalent architectural component to make interop actually work reliably.
I am also really excited about WHIP[1]
Consider government, large corp, etc purchase requirements. "Oh SIP is the standard. Cisco do you support SIP?" Cisco says "Of course!". Check the box and buy.
Meanwhile at the time their ecosystem is 99% Skinny (their proprietary protocol) and SIP is an afterthought for anything other than extremely basic call functionality, trunking, etc. Even when pushed to release SIP firmware for their (at the time) $500 hardware phones the SIP firmware was so feature crippled you're literally throwing money away by using it.
So everyone installs Call Manager to be done with it and have something that actually works. Even when Cisco got around to essentially being SIP native getting 30 year old features like hold, transfer, busy lamp fields, provisioning, etc working between vendors was nearly impossible.
Repeat for just about every implementation in existence.
The only reason you're not given access to it is because carriers are doing their best to protect their obsolete business model, and despite the appearances, Apple is fully complicit as well.
It's buried in the settings for the Phone app (the dialer) and AFAIK is often removed from OEM ROMs because of course it is.
As a VoIP engineer, it's a terrible soft client. It works, barely, and has basically no features beyond bare minimum calling. I've tried to use it repeatedly over the years but always ended up on commercial softphones like Bria or GS Wave.
But the call quality will never be as good as the native phone app as that gets QCI prioritization.
While it's true that SMS 2FA is flawed, that still isn't an excuse for letting customers' phone numbers being taken over by very unsophisticated attacks, sometimes even if notes are added to the account (or a PIN) that explicitly warn against such attacks.
Also, I'm not sure how much of "decades ago" is hyperbole but back in the day ISP/telco support was a great career path and would allow you to learn and move up the ranks towards a more technical position. Nowadays "support" in any customer-grade ISP/telco is a dead-end position that's there to be exploited as much as possible (in fact it's often outsourced to a boiler room abroad, probably right next to the tech-support scammers) and replaced by a new sucker as soon as you burn out. Obviously this kind of treatment doesn't attract the right talent nor inspire goodwill in said talent.
I ported my number out to VoIP.ms, and it included a four day waiting period... for no particular reason except to probably allow for some human to check a box.
For the cost of a data-only SIM ($15/mo), I can call, text, and surf. I only need to be wary of the 3gb cap.
For those in EU/Asia, can you believe that here, that is considered an amazing deal? It's still unfathomable outside of North America, but imagine that everybody else pays at least 4-5x more than I do.
It makes economic sense - it is hard to monetize running SIP servers for independent network (and one cannot use ads like with e-mail as SIP clients are not web apps), but you can monetize selling access to PSTN.
Today, with WebRTC, one can build web client for SIP, but WebRTC VoIP services are still just silos.
Don't broadcast radio and TV have ads too, despite being independent of any client implementation?
(I hate ads as much as anyone, but it's possible to run pre/inter-call ads on a free call too.)
So, just be aware of this and do your homework on specific brands/models before purchasing to ensure you'll get something that will work for you.
You could also get an ATA (https://www.amazon.com/Grandstream-HT801-Single-Port-Telepho...) and plug a traditional phone into it. I used one of these at home for a long time. Just realized it's still plugged in an running and I threw out my last analog phone over a year ago!!!
Also found the /r/VOIP subreddit [1] which has plenty of reading.
Can you remotely update firmware on modems?
Some devices can be updated remotely as these helpful guides explain. https://www.draytek.co.uk/support/guides/fw-remote https://www.ewon.biz/technical-support/pages/firmware/modem-...
So can a specially crafted string from the phone line be used to update firmware on ATA's? If they can handle v23 protocols for Caller ID, this indicates some modem capabilities does it not? So can the device differentiate which interfaces the commands are coming in on?
Why do people implicitly trust the telco's? Here in the UK, if you can get fast broadband, basically anything above ADSL2+, you'll be connected to a Broadcom cabinet. Broadcom have their bugs as well, you can find them on their website, but its a less common attack vector because its not public facing as such, unlike calling a business on their freephone number and then getting a second dial tone like in the old days of phone phreaking.
TLDR is just look at these devices as circuit boards, convention can be used to hide attack vectors and whilst the circuit design can help make a device secure, the easier or more convenient it is to update a device, the easier it is to hack, its not like taking a EEPROM out to blank under UV light and re flash it, is it?
That said, PABXs I worked with have built-in software modems (both POTS and ISDN, needs to be explicitely enabled) with remote management capability and there is also dedicated web portal for management even if device is behind NAT (paid feature). Whether you want to trust hardware/software you have no control of - that's another story. For "big" PABXs partnership between manufacturer and installers usually lasts for years.
A cisco 7940 is rock solid and go for around 10 dollars, the only caveat is you will need a poe switch for 48 volt power and a custom cable as they use nonstandard voltage pinout.
I'd like to port my phone numbers from google, as I'm afraid the migration of the free domain may cost me my phone number in case of shenanigans (like google voice being considered separate of google mail etc)
If you're actively managing a large number of users and devices, I had great luck with OnSIP. They're not the cheapest game in town, but their management interface is top notch. They were always innovating and the architecture they disclosed was impressive; very focused on HA and performance.
I followed the first 10 chapters or so of the O'Reilly Asterisk book making a few changes here and there to suit my preferences (different Linux flavor, different DB). I run a $10/month Digital Ocean droplet that hosts the Asterisk server. If you can deal with config files, you can have a rock-solid PBX with Enterprise-grade features for the cost of the server + Twilio's SIP trunking features. It ends up costing about $25 every 1.5 months or so. I barely ever think about it, except when I need to tweak a greeting for holiday hours or something.
CUCM: https://twilio-cms-prod.s3.amazonaws.com/documents/InteropGu...
ISR: https://www.twilio.com/docs/sip-trunking/sample-configuratio...
They also have a porting process you can use to migrate your numbers from GV/Bandwidth (or you can just buy a Twilio number for $1).