The Voice over IP security alliance (VoIPSA) has published a list of security problems that could derail IP telephony’s expansion.

These turn out to be remarkably similar to the hassles of using a conventional PSTN phone, but with added problems that come from running calls across the Internet.

Topping the industry body’s list are more familiar issues such as privacy and eavesdropping, harassment by phone, premium rate abuse, and hijacking of service, all of which remain to be tackled by the industry.

Customers used to the PSTN might not, however, be as acquainted with other threats that will arrive with the technology. These include VoIP spam, caller-ID impersonation, denial of service attacks, authentication and complex ID fraud.

As to denial of service attacks specifically, the report lists eight methods by which this can be initiated, which brings home the point that the VoIP world will have more in common with that of computing than that of the telephone networks people have become used to.

And these are only the top-level security issues. Calls can also be “black holed”, or terminated unexpectedly, rerouted, and degraded. As well as interfering with quality of service they will also make possible further security threats such as call impersonation.

"The overall goal of to help drive VoIP security awareness in the press, industry and public," say the reports authors, which comprised engineers from a range of VoIP industry vendors.

"While some early press accounts focused on potential VoIP spam and VoIP call hijacking, the consensus of learning from this project is that there are many other threats more prevalent risks including economic threats from deceptive practices, malware, and denial of service," the report states.