How I built the best-selling BlackBerry app
neilwithdata.com
neilwithdata.com
I have a number of fun stories about RIM (I was one of the BB product managers at a telco), and this post reminded me that it might be a good time to record them for posterity... :)
It was initially played as an exclusive (not many telcos wanted to devote APNs to manufacturers or set up the tunnelling to the BES), which helped cement that worldview.
From an IT perspective again, you also had pretty decent device management (activation/restriction/lockout/wipe) features.
Customers, on the other hand, loved having usable e-mail and calendaring on their pockets (and later IM, but that's part to RIM's failed attempt at going mainstream, and I do thing I will write that post soon...).
Oh, and they also loved week long battery life. Sad that is now a thing of the distant past.
I'm presuming it's this direct integration that allowed BlackBerry to push a message straight out to a device, no firewalls in the way?
Later (for consumer services) RIM became essentially a large virtual corporate customer, with traffic routed via the Internet.
While true, the initial versions of iOS and Android represented a step down in security. (BlackBerry at least encrypted the phone, by default - maybe even required?)
I was always baffled that the tech media would never mention how insecure Android or iOS were.
In order to operate in some countries, all Blackberry traffic had to be routed through that country's government servers.
It's been a long while, but I'm pretty sure that India was one such country. And at least one Middle Eastern country.
> In order to operate in some countries, all Blackberry traffic had to be routed through that country's government servers.
> It's been a long while, but I'm pretty sure that India was one such country. And at least one Middle Eastern country.
This was only related to the BlackBerry Messenger (BBM), and even then only on the standard consumer phones. The corporate servers had their own keys, IIRC. Plus, it was only for messages traversing Indian or Pakistani networks, and my memory was that BlackBerry did not hand the keys over, just answered all of their requests.
Even at that, this level of encrypted communications was not otherwise widely available for consumers. The actual migration from BBM to whatever iPhone and Android were offering were downgrades.
I'm not aware that BlackBerry devices were ever rooted, and they were default encrypted with 128-bit AES. The OS required users to grant permission for apps to access resources, such as GPS. This took something close to a decade to be installed and enabled by default in iOS and Android.
There was a big story where 3rd-party apps installed by providers contained malware. It was a huge story run everywhere and headlines made it sound as if every single phone had this vulnerability. However, they didn't mention the vulnerability could not affect BlackBerry devices because BlackBerry had a contract with all providers that the provider could not install any software to the device.
Not security-related, but a big complaint from devs at the time was that BlackBerry had so many different devices that it was very expensive to develop for. Apple, for sure, and maybe Android promised this would never happen on their platforms. Only the truly naive could believe this.
My takeaway was that BlackBerry somehow pissed-off all of the tech journos and suffered appropriately. That's why they got nothing but bad press.
The other thing they suffered from was this "co-CEO" nonsense. For whatever reason, it seems nearly universal that if more than one person is in charge, nobody is accountable.
Edit:
And something even I forget about is that prior to the Snowden releases, concerns over government snooping were only for the tin-foil hat donned black-helicopter dodging conspiracy theorists. It just wasn't on the public's radar.
They handed over their "global encryption key" to the RCMP, see https://www.techdirt.com/articles/20160414/10482434186/canad...
They jumped from "most secure" to "least secure" effectively immediately once they did that.
> They handed over their "global encryption key" to the RCMP, see https://www.techdirt.com/articles/20160414/10482434186/canad....
> They jumped from "most secure" to "least secure" effectively immediately once they did that.
That article is an absolutely fantastic example of how the press treated BlackBerry (average consumers might come away thinking that BlackBerry devices are insecure).
It is after BlackBerry was dead from a market share perspective, so this isn't really applicable to the period I am referring to, which was from iPhone launch to maybe as late as 2012, when BlackBerry went from hero to zero.
Well, maybe see my comment below for more, but backdoor implies a backdoor was required. With no encryption, as was the case with iOS and Android, no backdoor was required for communication intercepts or device, and you're only referring to BlackBerry Messenger. Users could install their own messaging apps and larger customers could opt for BES.
Give people extensibility and they can do things you'd never imagine: just take a look at the early jailbreaking community, who had neither APIs nor support from Apple but were able to do quite a bit just by being able to inject code into system applications to augment them. (I like to think that a faint echo lives on today in Mail plugins for macOS.) Sadly, we seem to be moving away from this for reasons that are touted to be for security…
DOS is the other example -- it was amazingly extensible to the point multitasking operating environments like DESQview[1] was available for it, but was also very susceptible to malware.
In the case of email on any given platform, it should be possible for an application to add functionality to email, but also to ensure (to use the author's example) that it cannot peek into your bank app.
I suspect given email's not as popular as it once was, and so email plugins are too much trouble for first-party mail clients, given their attack surface. Platforms like Slack and Teams do offer extensibility though.
It’s also not working too well to keep Android devices secure.
The analog to UAC on Android is permissions, which work pretty similarly to ios. You could argue that the user gets used to just clicking agree and that not much is gained for the average user.
Sideloading apps and unlocking the bootloader is much different. It requires the user to actively go through the settings to enable the options, which would only happen if the user knew what they were doing in the first place. And after you try to enable the settings, you are bombarded with warnings before the settings actually apply.
An app can't trick you into flipping these switches. Most of them are actually hidden in developer mode anyway.
I challenge you to prove these have ever been a vector for attack. It's just not practical.
The security lost is zero, and the freedom gained is immense.
https://www.cnet.com/news/fortnites-battle-royale-with-andro...
There is no evidence that malware is utilizing these vectors to any measurable degree.
If you don't want to control your device, that's fine, but don't spread FUD that carefully design6 user-controllable devices are less secure than closed devices, when the opposite is true in practice. See XCodeghost and others.
Sorry if I come across as confrontational, I'm just after clarity, but that's what a plain reading of your reply actually says.
Hence Win32 and UWP containers, Android black listing of NDK and SDK APIs, with hardware sandboxes, plugins removal on browsers, moving stuff back into multi-processes with IPC,...
Drama, yes there is a lot I guess. But I've been an active developer since 2012 and I think it is easy to not involve yourself in it.
A buzz in the pocket, email symbol on the screen, main button to open the email, right-click button to forward, physical scroll to a recent colleague and select, lock & back in pocket.
All that before 3G. Easy, quick and no fuss, muscle memory took care of most of it.
I often still wish phones had physical keyboards.
That was my first smartphone and I loved the dual use with the sliding keyboard in landscape mode.
Should be possible to make something like this with all the improvements we had along the way... Anyone listening here? Please make it happen! :-)
Portrait style ones are the BB Key2 or Unihertz Titan
Landscape keyboard is the Fxtec Pro1
The only times it was required to "reply when I get back to my computer" was when document editing was required.
Plus replaceable batteries and especially high capacity batteries meant pretty much never worrying about charging while out and about.
i never had to use one for work but blackberry was my first smart phone, it came with a truly unlimited plan from verizon.
here are some fond memories of it:
- i got notification that new OS was available, i did an over the air update and it wiped 90% of my contacts. i came from dumbphones and remember i had to re-enter 100 or so contacts by hand, i don't think i ever upgraded the SW on it again.
- went out to HH with some friends and getting ready to go home i thought of using the internet on my fancy BB to look up the bus schedule, i pulled up the cttransit website and it would not open the .pdf with the bus time natively, it pointed me to buying some pdf viewer for something like $25. at the same time, my co-workers iphone 3G or whatever it was, opened the pdf without any additional apps.
so much for a "computer" in your pocket and being all about "business and not play", the stereotypical mantra of old crackberry.com. i think the next year on valentines verizon got the iphone 4 and that was the end of blackberry for me.
i can't believe people have nostalgia for this garbage phone.
- Don't implement a feature
- Don't rely on a hack that could change
... in the end, it worked for him. Great write up indeed.
This obviously requires contextualization and I naturally assume it was stated with that context implicit, but I'm not entirely sure what the connotation is. Don't implement OS-level features, so when the OS (re)does them (potentially better, notwithstanding incompetence) you die?
I look back on BB with alot of nostalgia, you really had to work to make things look good. If you didn't want your Views (widgets) black, white and blue then you were making them from scratch.
I worked at a startup that built a BlackBerry app in 2007. I wrote up my experience here: https://schlu.org/2014/05/29/Things-Are-Better.html
Interesting how one small piece of technical knowledge changed someone's life
There's the sales part, but there's also the "got a job at blackberry" part which might or might not have happened without the app.
And by the sounds of it, a good job as well!
Sometimes some companies just deserve to fail. The current duopoly formed because the competition just couldn't keep up, and that's on them
There was tons of pressure to stay with Blackberry (it WAS the monopoly incumbent - almost every major IT department had invested in it - telcos loved it for the $$$).
Seriously - someone like Obama or Trump would be told they could only use a blackberry because it was more "secure" supposedly. Users told the same thing.
From top to bottom after folks got to try out the iphone from apple (no telco lock in at start at all - I bought the iphone 1 full price in cash when sold) just would not go back to blackberry.
It actually worked out for a while. people carried two phones. The blackberry required by their work and an iphone.
The crazy thing is blackberry just kept on falling behind in huge leaps backwards. It was nuts.
Apple's execution was really pretty good given the ramp they had.
Windows Phone 7 was incompatible with Windows Mobile 6, so developers had to start over. Windows phone 8 had a new prefered app framework, so developers needed to support two apps. Windows mobile 10 had a new prefered app framework that was ironically called universal; but windows mobile 10 was released without any of the polish of previous windows phone releases and without any low end phones, so it never had more users than windows phone 8 or 7.
If windows mobile 10 had a well organized release, it might still be a thing. The only company to blame for that is Microsoft.