I still haven't posted the full long explanation, but here's the quick version.
We've tried to find a way to balance things so that softphones/BYOD could fit into the mix. Even though we had stopped offering BYOD service, there was no clean way to deal with softphones without doing a proprietary one since people would just take the credentials and try to use them in something else. There is massive fraud with BYOD/Softphones but there are some legit uses for it as well, so it was a constant battle to stay on top of it without just banning it.
What we ended up doing was setting up a special server that is more locked down security wise and it's being dedicated to only BYOD. When a user activates the Softphone/BYOD option in their vPanel, it creates SIP credentials on the new BYOD server that they can use. When it's "disabled", the credentials are removed from that server and regenerated the next time it's enabled.
It is isolated from the rest of our network so it's not going to impact our core servers or primary SIP servers if someone does something bad on it. It's also significanlty more locked down and supports domestic calling to US/Canada ONLY. 99.9999% of fraud is with international calling. Since our primary service is delivered using the ATA and the BYOD/Softphone option is not meant for someone's primary use, international not being available on it should be fine. If a BYOD user makes a lot of international calls, chances are they will be savvy enough to route them through another provider anyway. Our international rates are competitive with traditional VoIP services, but if they're extremely savvy they'll find cheaper rates with some other BYOD providers.
Some older users have credentials for our primary SIP servers. If you already have these, they will continue to work, but we're not giving any out at all from this point on. The only credentials for any purpose that will be released are the seperate BYOD/Softphone ones found in vPanel.
The BYOD credentials will ONLY work on the BYOD server. The main credentials will only work on our core servers.
The system was implemented in a way that will allow you to register to both without issues. So if you have an ATA connected/provisioned at home and you connect with a softphone to the BYOD system, that's fine. Incoming calls would ring both and the first to answer would get the call.
Ultimately we think this will let us become a little more BYOD friendly while at the same time keeping things secure and contiuing to focus on our provisioned service as the main element.
Let me know if there are any questions.
Bookmarks