Desperate RIM Gives In And Lets Indian Gov't Spy On Blackberry Communications

from the impossible-doesn't-mean-what-it-used-to dept

Back in 2008, we wrote about how the Indian government was demanding that RIM let it snoop on encrypted messages from Blackberry users. RIM’s response was that it was simply impossible to snoop on its enterprise customers’ messages, since they set their own encryption keys. A few months later, the government claimed to have cracked RIM’s encryption, though the whole claim was sketchy. In 2010, the government again demanded the right to spy on Blackberry users (raising more questions about that encryption cracking claim). RIM apparently offered up a “solution” that the Indian government rejected, because it didn’t let them snoop enough (basically it allowed snooping on consumers, but not corporate accounts).

Now, however, there are reports that RIM has come up with a “solution” to let the Indian government spy on enterprise users as well:

RIM recently demonstrated a solution developed by a firm called Verint that can intercept messages and emails exchanged between BlackBerry handsets, and make these encrypted communications available in a readable format to Indian security agencies, according to an exchange of communications between the Canadian company and the Indian government.

If you’re a RIM Blackberry customer, and you bought into it because of the security features, now would be the point where you get pretty pissed off and start seeking alternatives. The report from the Economic Times suggests RIM did this because of the “importance” of the Indian market. RIM is clearly in trouble. Its failure to keep up on the innovation front means that the company is clearly struggling. But kowtowing to a government by allowing it to spy on users is hardly the sort of thing that’s likely to get you more customers. It seems like it should do exactly the opposite.

Filed Under: , , ,
Companies: rim

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Desperate RIM Gives In And Lets Indian Gov't Spy On Blackberry Communications”

Subscribe: RSS Leave a comment

The way things are going now the only way to make sure the government can’t spy on you is to ditch all cell phone equivalents, and other electronics you carry around with you, and make sure your computer has no Internet connection. Oh, and ditch your credit cards and bank accounts to.

That’s why RIM gave in, what safe alternate to protect you from government spying is there? Even Skype doesn’t seem to be safe anymore.


Re: Re:

Quite a bit. First of all, cell phones should require a warrant for a specific person or connection before you can ‘monitor’.

Same thing for internet connections.

Same thing for credit cards and bank account (in this case, that is actually how it goes).

Bottom line is that ‘criminals’ should not drive exceptions to our system of protections.


Interesting technical implications

I’m rather interested in the technical implications here, as this implies a major underlying flaw in the encryption RIM is using. It shouldn’t be a trivial thing to break the level of encryption RIM uses without the keys. If I were still administrator for any BESs I’d be in the process of implementing the optional PGP encryption (assuming it wasn’t on already) and setting the Blackberry Router on my devices to bypass SRP and connect directly to my BES, those steps should give users some protection, assuming of course that the actual attack resembles what is being described in news reports.


Re: Re: Re: Re: Interesting technical implications

Unlikely, an unencrypted feed would be trivial to detect and even a second encrypted feed should show up in deep packet analysis, though you wouldn’t be able to read it, you’d definitely know it was there. Given the design of the Blackberry network, this sounds like some sort of man in the middle attack, probably being run against the encrypted AES packets as they pass through the Blackberry network after SRP authentication before they’re passed back to the corporate BES. That would be the point that the packets would be most vulnerable to attack, but you’d still need to break the AES encryption, which must have a flaw that allows it to be broken that easily, what’s surprising is that such a flaw hasn’t been more widely reported.



in russia, they have already worked around this issue. The cellular provider owns the BES, and you provide them with an account that has access to your blackberry users’ mailboxes. Its super effective and your level of privacy is transparent. This isnt required for activesync connections, which makes me believe that activesync is already cracked.

gama rayssays:

You guys must realize that spying is for the national security. While I agree this can be abused, I also realize it is used generally for the country’s own good majority of the time.

Why do people feel the need to communicate with utter secrecy? If you feel the need to talk with that kind of privacy, better talk with them face to face or use encrypted mail.(unless you are doing anything illegal of course) Again i agree again that this can be abused just like any other technology(like 1%-10% of the time)[my numbers;not to be taken as fact]. The government must make sure it has the ability to intercept emails from possible terrorists that may get hold of this technology.

Just imagine terrorists using this technology to co-ordinate their attacks. It will become an utter nightmare. And imagine how will this becomes if government does not have the ability to stop them.

tl;dr privacy is compromised slightly for the greater good.


Re: Re:

I think you got your numbers backwards.

Real threats rarely happen, so most of the time this will be used to spy on others for other reasons.

Iran contras was not a fantasy and it highlights why spying in secrecy without any kind of oversight is bad.

Maybe you are to young to remember what that was, but some still remember it and know exactly why spying on our own people was forbidden.

gama rayssays:

Re: Re: Re: Re:

Iam not denying any of your points. At least we both agree real threats DO occur.

Terrorists are not dumb; they are not going to just strap a bomb and kill themselves all the time. They are constantly evolving and they try to use any means possible to make their job easy.

The reality is that if we want to feel safe anywhere we go, we need to tolerate the spying. Bad guys kills other people. It may be today, tomorrow or even after 10 years. Spying is only one of the tools many tools we have at our disposal to beat them. Because I am more than happy to compromise my privacy if that means it helps save a few people’s lives or mine for that matter.

John Fendersonsays:

Re: Re: Re: Re: Re: Re:

Because I am more than happy to compromise my privacy if that means it helps save a few people’s lives or mine for that matter.

And I am not.

Here’s the problem — the risk of abuse, even life-threatening abuse — in the name of security far outweighs the risk from terrorist acts. There are indeed circumstances where civil rights should be abridged for the greater good, but these must be truly exceptional in nature, and only for a limited time.

The threat posed by terrorists is neither of those things.

Let me put this in perspective: the odds that you will be killed driving on a freeway is many orders of magnitude greater than the odds of you being killed by a terrorist act. Are you arguing that we need to be stripped of civil rights to mitigate the freeway threat? If not, then why the difference?

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Report this ad??|??Hide Techdirt ads
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Older Stuff
12:25 Australian Privacy Commissioner Says 7-Eleven Broke Privacy Laws By Scanning Customers' Faces At Survey Kiosks (6)
10:50 Missouri Governor Doubles Down On 'View Source' Hacking Claim; PAC Now Fundraising Over This Bizarrely Stupid Claim (45)
10:45 Daily Deal: The All-in-One Microsoft, Cybersecurity, And Python Exam Prep Training Bundle (0)
09:43 Want To Understand Why U.S. Broadband Sucks? Look At Frontier Communications In Wisconsin, West Virginia (8)
05:36 Massachusetts College Decides Criticizing The Chinese Government Is Hate Speech, Suspends Conservative Student Group (71)
19:57 Le Tigre Sues Barry Mann To Stop Copyright Threats Over Song, Lights Barry Mann On Fire As Well (21)
16:07 Court Says City Of Baltimore's 'Heckler's Veto' Of An Anti-Catholic Rally Violates The First Amendment (15)
13:37 Two Years Later, Judge Finally Realizes That A CDN Provider Is Not Liable For Copyright Infringement On Websites (21)
12:19 Chicago Court Gets Its Prior Restraint On, Tells Police Union Head To STFU About City's Vaccine Mandate (158)
10:55 Verizon 'Visible' Wireless Accounts Hacked, Exploited To Buy New iPhones (8)
10:50 Daily Deal: The MacOS 11 Course (0)
07:55 Suing Social Media Sites Over Acts Of Terrorism Continues To Be A Losing Bet, As 11th Circuit Dumps Another Flawed Lawsuit (11)
02:51 Trump Announces His Own Social Network, 'Truth Social,' Which Says It Can Kick Off Users For Any Reason (And Already Is) (100)
19:51 Facebook AI Moderation Continues To Suck Because Moderation At Scale Is Impossible (26)
16:12 Content Moderation Case Studies: Snapchat Disables GIPHY Integration After Racist 'Sticker' Is Discovered (2018) (11)
13:54 Arlo Makes Live Customer Service A Luxury Option (8)
12:05 Delta Proudly Announces Its Participation In The DHS's Expanded Biometric Collection Program (5)
11:03 LinkedIn (Mostly) Exits China, Citing Escalating Demands For Censorship (14)
10:57 Daily Deal: The Python, Git, And YAML Bundle (0)
09:37 British Telecom Wants Netflix To Pay A Tax Simply Because Squid Game Is Popular (32)
06:41 Report: Client-Side Scanning Is An Insecure Nightmare Just Waiting To Be Exploited By Governments (35)
20:38 MLB In Talks To Offer Streaming For All Teams' Home Games In-Market Even Without A Cable Subscription (10)
15:55 Appeals Court Says Couple's Lawsuit Over Bogus Vehicle Forfeiture Can Continue (15)
13:30 Techdirt Podcast Episode 301: Scarcity, Abundance & NFTs (0)
12:03 Hollywood Is Betting On Filtering Mandates, But Working Copyright Algorithms Simply Don't Exist (66)
10:45 Introducing The Techdirt Insider Discord (4)
10:40 Daily Deal: The Dynamic 2021 DevOps Training Bundle (0)
09:29 Criminalizing Teens' Google Searches Is Just How The UK's Anti-Cybercrime Programs Roll (19)
06:29 Canon Sued For Disabling Printer Scanners When Devices Run Out Of Ink (41)
20:51 Copyright Law Discriminating Against The Blind Finally Struck Down By Court In South Africa (7)
More arrow