back to article 3CX teases security-focused client update, plus password hashing

The CEO of VoIP software provider 3CX has teased the imminent release of a security-focused upgrade to the company’s progressive web application client. “Following our Security Incident we've decided to make an update focusing entirely on security,” CEO Nick Galea wrote on Monday. In case you missed it, that incident was a …

  1. Anonymous Coward
    Anonymous Coward

    Wow some password hashing that should have been there years ago and a bit of IP whitelisting. That hardly counts in my eyes as a serious review if that is all they are doing. Hope to see their security roadmap soon

  2. Anonymous Coward
    Childcatcher

    Phone bill expansion plan

    "If hacked these credentials can only be used to get calling access to the PBX."

    You'll still own your box but "they" will ransack your phone bill. Trebles all 'round.

    1. usbac

      Re: Phone bill expansion plan

      They are in the VOIP phone system business and have never heard of toll-call fraud? That is one of the main things anyone that admins a VOIP phone system needs to guard against.

      As mentioned above, they didn't hash passwords? They are still not hashing the SIP credentials?

      I would like to say unbelievable, but sadly I'm not surprised. A while back when I was looking into replacing the phone system, I looked at their product. It looked like total crap. I couldn't understand why anyone would buy the product. It was also one of the more expensive options. At the time, it only ran on Windows servers, so that pushed it down the list to begin with.

      It also only supported a limited list of IP phones, as was very difficult to make work with phones that were not on its very short list.

  3. Claptrap314 Silver badge

    It's the u$ model

    Security fails as a revenue source...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like