I noticed you have been doing some provisioning work recently, eg the RPS integration and it made me recall an idea I have had for some time that I think enhances security further.
I know that the would be hackers are constantly trying to obtain thos config files.
In a job I had a few years ago we used a third party company for provisioning. One day, I factory reset a phone and it did not come back up. I contacted said third party company and they explained that after 14 days thry removed any credentials from the config files that were sent.
What a brilliant idea, now, even if the hacker gets hold of any config files they will be useless to them for a sip hack using credentials.
I've wanted to implement something like this in fusionpbx for years but never gotten around to it.
Something along the lines of, after a device has been added, send the credentials with the first provision then set some sort of flag that indicates credentials were sent and then omit them from further provisioning. This allows you to make any other changes whilst not sending the credentials.
If there has been a password change or they are going to do a factory reset then go into the device and click a box labelled something like 'Send credntials on next provision', that could be the default fro a newly created device, that way after a factory reset, they get the credntials again.
Anyway, just an idea
I know that the would be hackers are constantly trying to obtain thos config files.
In a job I had a few years ago we used a third party company for provisioning. One day, I factory reset a phone and it did not come back up. I contacted said third party company and they explained that after 14 days thry removed any credentials from the config files that were sent.
What a brilliant idea, now, even if the hacker gets hold of any config files they will be useless to them for a sip hack using credentials.
I've wanted to implement something like this in fusionpbx for years but never gotten around to it.
Something along the lines of, after a device has been added, send the credentials with the first provision then set some sort of flag that indicates credentials were sent and then omit them from further provisioning. This allows you to make any other changes whilst not sending the credentials.
If there has been a password change or they are going to do a factory reset then go into the device and click a box labelled something like 'Send credntials on next provision', that could be the default fro a newly created device, that way after a factory reset, they get the credntials again.
Anyway, just an idea