SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Voice, Data, and IP

BlackBerry, other smart phone users easy spy targets

BlackBerry, other smart phone users easy spy targets

By:  Dan Nystedt  On: 07 Oct 2009 For: IDG News Service (Taipei Bureau) Creator

BlackBerry apps should go through the same scrutiny as software writeen for the iPhone, a security researcher says

KUALA LUMPUR — IPhone lovers and other smart phone users should take heed: A security researcher showed ways to spy on a BlackBerry user during a presentation Wednesday, including listening to phone conversations, stealing contact lists, reading text messages, taking and viewing photos and figuring out the handset's location via GPS.

And ironically, said Sheran Gunasekera, head of research and development at ZenConsult, Waterloo, Ont.-based Research In Motion Ltd.'s BlackBerry is one of the most secure smartphones available, in some ways better than Apple Inc.'s iPhone.

"There is no technical way of hacking a BlackBerry, it's impossible," said Gunasekera, during a presentation at the Hack In The Box security conference in Kuala Lumpur. "It's just too secure for that. So we have to rely on social engineering."

For hackers, social engineering is the art of tricking someone into loading spyware onto a device or finding some other way to install it, such as borrowing the device and downloading malware from the Internet or a MicroSD card, for example.

One way to entice a BlackBerry user to download spyware onto their smartphone is by offering a free application that appears to be a game or some other harmless software, but in fact carries a dangerous payload. Enticing slideshows are even easier to get users to accept, Gunasekera said.

"I will have the slideshow running on top and the spyware doing its nastiness on the bottom," he said.

What kind of nastiness?

A small piece of software able to conceal itself by not appearing on the BlackBerry's application menu, nor taking up much memory space nor using much processing power, can allow a hacker to do all kinds of things.

"People tend to put a lot of personal data on a BlackBerry," he said, but it's not just the data on the phone that's at risk.

Spyware on a BlackBerry could intercept a phone call and let the hacker listen in, or even let the hacker listen to a meeting the victim is sitting in on. By silently answering the victim's phone, then turning on the speakerphone, the spyware could allow the hacker to overhear the meeting. It could also forward incoming and outgoing text messages to the hacker, and even enable the hacker to write messages from the victim's BlackBerry, or run up the victim's phone bill by making international calls.

The hacker could also program the spyware to have the handset's camera take pictures every 10 seconds, for example, to find out the victim's location.

One recent example shows a massive installation of spyware on BlackBerry phones in the United Arab Emirates.

Regional mobile phone service provider Etisalat last June told its 145,000 BlackBerry subscribers to download a software upgrade that turned out to be spyware. Once users downloaded the "upgrade," it forwarded the phone's e-mails to a central server, Gunasekera said. The ploy was discovered because the software drained BlackBerry batteries at an excessive rate, in as fast as 30 minutes after a full recharge.

Etisalat maintains the software was an upgrade.

BlackBerry manufacturer Research In Motion (RIM), however, took matters into its own hands and provided a fix to affected users.

"Independent sources have concluded that Etisalat's 'Registration' software application is not actually designed to improve performance of a BlackBerry Handheld, but rather to send received messages back to a central server," RIM said on its Web site.

Gunasekera offered a range of advice to help people keep their BlackBerries secure, advice useful to most smart phone users.

"Don't install random pieces of software," he said, "and be sure of what you're installing, and limit the amount of software on your BlackBerry."

It's also not a good idea to let anyone else use your smartphone, he said, but if you do hand over your phone, keep an eye on it. He also implored people to learn and set default application permissions on their BlackBerry smart phones, a feature that increases safety. And always enable a device password. "This is the least you can do in case your device is lost or stolen," he said.

He also suggested that RIM start regulating apps made for BlackBerries.

"People complain about Apple and their application process for the App Store, but it's good for security because you have people actually looking at the code," he said. RIM needs to put third-party apps aimed at BlackBerry devices under the same scrutiny, he said.

A RIM security researcher sent to the Hack In The Box conference to view the presentation declined to comment, but said the company planned to issue a statement later in the day.

Sign up for our Newsletters












Print |  Views: 1754   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




dan nystedt Dan Nystedt is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

RIM opens BlackBerry App World
RIM opens BlackBerry App World Apple's iPhone App Store get some company as Research in Motion opens App World, RIM's online mobile application store
Eight free security tools
Eight free security tools Here are eight free downloads and services that will help you beat back the bad guys with antivirus, personal firewalls and even a program that tells you if your Web site is under attack
Advocacy groups step up battle against spyware
Advocacy groups step up battle against spyware With the Anti-Spyware Coalition's (ASC) final definitions of spyware in place, public interest advocacy groups have wasted no time in their quest to put malicious spyware distributors out of business. Two advocacy groups in Canada and the US have been particularly active in this struggle against spyware.
Hacking for Good
is there such a thing as a good hacker? isn’t “ethical hacking” an oxymoron? let me challenge your beliefs and the prevailing media message. hackers are not evil; in fact, they generally want things to be safer and better for all. at this point, you’re probably ready to either label me as a lunatic, or give me a lesson about “hacker” vs. “cracker”. let’s skip the historic definitions. th
Phishing for IT expertise
as soon as i got the e-mail from bmo financial group, i knew it couldn’t really be from bmo financial group.first of all, although i have accounts with that particular financial institution, and even do a lot of online banking there, i am certain they would not use e-mail as their primary channel for contacting me. to that extent, the message was no big deal. a phishing scheme is a phis
iPhone lessons from the BlackBerry Pearl
i don’t think apple ever officially called the iphone a blackberry killer, but even steve jobs probably didn’t see its device as a blackberry b
blog comments powered by Disqus