Canadian Police Obtained BlackBerry’s Global Decryption Key
news.vice.com
news.vice.com
sms, not encrypted.
pin messages/BBM, "scrambled"
BBM protect, encrypted
BES (corporate device), encrypted with a key that BlackBerry is not suppose to be able to access.
Originally bb devices could send messages to other bb if you knew their pin. The data was compressed and encrypted, but a moot point since all bb devices had the same key. Pin messages,BBM and their bis infrastructure was never really considered secured, their main offering was BES with offered end to end security.
I used the term scrambled since that was the term everyone was using years ago since people get confused between encrypted, vs encrypted with shared key, vs not encrypted, etc. It quickly becomes a pointless conversation.
As far as I'm concerned, This isn't really surprising if you think about it. BlackBerry's only claim to security was BES for end to end communication.
Another way into BES is of course via stupidity, such as Nicola Nero the crime boss police caught a few years ago in Ontario who had written his password on a memo and left it beside his BlackBerry phone because he kept forgetting it. They busted a global mafia ring from that one mistake.
Quote: "In fact, one of the world’s most powerful tech companies recently refused a lawful access request in an investigation of a known drug dealer because doing so would “substantially tarnish the brand” of the company. We are indeed in a dark place when companies put their reputations above the greater good."
I guess it depends on your definition of "the greater good".
http://blogs.blackberry.com/2015/12/the-encryption-debate-a-...
"Rouleau even admitted to the judge, during one ex parte hearing, that his own phone would be vulnerable to the type of intrusion the RCMP used on the targets of the investigation.
"I'm a dead chicken. That's the reality of it, that's what we don't want the general public to know," Rouleau said."
> There have been a number of news articles over the past few months speculating that BlackBerry technology may have been deployed in a non-approved manner, placing sensitive government information at risk. While I cannot comment or speculate on those news stories, or the extent to which any vulnerable non-BlackBerry components may have been involved, I do want to reiterate the security technologies that BlackBerry provides to millions of government and enterprise customers around the world.
New BlackBerries are based on Android now. I'd venture that 95% of a new BlackBerry is made of non-BlackBerry components. I find it interesting that he carefully disclaims any vulnerabilities that might have been found and exploited in that 95%.
I don't have anything particularly against BlackBerry. I wish they'd get their act together and do well so we can have more competition and innovation in the cell phone market. However, I wish we'd put that whole "BlackBerry is secure" trope to rest because that doesn't ring remotely true to my ears.
Darn happy with my Passport though.
As long as all that's true, their stuff is secure. That's not confidence inspiring.
I remember one experience very clearly from when the Priv first entered the market. I looked through the related web pages, curious about where Blackberry was going. I found plenty of marketing around tools that would notify you if various things went wrong in terms of privacy and security. However, I found literally nothing to state that the phone would actively prevent those things from going wrong or check with the user before performing actions they apparently considered significant enough to warn about. It was one of the most marketing-heavy, content-light, non-committal product sites I've seen in a long time.
Until today I don't think I've been there again. After reading the initial marketing, I just assumed the phone wasn't actually going to be significantly more secure or private than anyone else's or they'd have told us how it was instead of skirting around it repeatedly for the entire site. In fact, if memory serves, it was at the time based on a version of Android that predates some significant improvements in terms of app permissions and locking down what they can do, suggesting that contemporary models from competitors that used a later version of Android would actually have been much better than the Priv in at least some areas of security and privacy.
> Canadian government warns BBM PIN-to-PIN messaging is ‘most vulnerable method of communicating on a BlackBerry’
http://bgr.com/2013/02/27/blackberry-messenger-security-vuln...
> Canadian government agency Public Safety Canada, which is tasked with overseeing cyber-security across all federal departments, has issued a memo warning government workers that communicating using BlackBerry Messenger PIN-to-PIN messaging is “the most vulnerable method of communicating on a BlackBerry.” ... According to the memo, PIN-to-PIN messages sent via BlackBerry Messenger could be intercepted and read by any BlackBerry user anywhere in the world. ... “Although PIN-to-PIN messages are encrypted, they key used is a global cryptographic ‘key’ that is common to every BlackBerry device all over the world,” Public Safety Canada official stated in the memo. “Any BlackBerry device can potentially decrypt all PIN-to-PIN messages sent by any other BlackBerry device.”
Why is there any surprise then that the RCMP has capability to decrypt it?
Who is going to trust Blackberry now? Even as a BB Enterprise customer, I'd be scrambling right now to change my system immediately. This is exactly what I expect will happen to the whole industry if idiotic bills like the one currently proposed by Senator Feinstein make it through. No sane, security-minded person will want to use any of these products. And there certainly is no shortage of foreign competition. But it's all worth it to calm down the cowardly masses who are afraid of terrorism or whatever the fear of the day might be, right?
EDIT: Of course, I also mean the closed possession of private keys.
If it were open, one could check and ensure private keys were never under the possesion of a third-party.
> BlackBerry (formerly RIM) encrypts all messages sent between consumer phones, known as PIN-to-PIN or BBM messages, using a single “global encryption key” that’s loaded onto every handset during manufacturing. With this one key, any and all messages sent between consumer BlackBerry phones can be decrypted and read. In contrast, Business Enterprise Servers allow corporations to use their own encryption key, which not even BlackBerry can access.
[0]: http://motherboard.vice.com/read/rcmp-blackberry-project-cle...
It really sounds terribly insecure to me.
The company I work for is still using their key-fobs for VPN access.
It's called backwards compatibility... though that's not really an excuse.
Check out the bottom of page 7, and the diagrams on page 8.
http://security.stackexchange.com/questions/5985
Security is not exactly their forte.
From: https://www.canlii.org/en/ns/nssc/doc/2016/2016nssc7/2016nss...
" On June 24, 2014 the RCMP advised in writing that their crime lab required another two to three months to crack the BlackBerry."
&
"The Crown could not disclose the contents of the BlackBerry until they were able to crack it. Once cracked, there was no relevant evidence on it to disclose."