Live data from Hacker News

Schneier on UAE to Ban BlackBerrys

schneier.com

1–10 of 27 posts

Re: Schneier on UAE to Ban BlackBerrys

#5
post #4

How would a startup go about selling monitoring services to the UAE government?

Considering that the traffic is encrypted between the devices and RIM's servers, you'd have to try to 1) break the encryption or 2) gain access to RIM's internal network, and 3) check your morals at the door. Good luck.

Re: Schneier on UAE to Ban BlackBerrys

#6
>RIM makes a big deal about how secure its users' data is, but I don't know how much of that to believe:

It sounds like RIM is describing normal public key encryption. I'm not sure why Schneier thinks they have the plaintext, though admittedly "customer data" could refer to anything.

Re: Schneier on UAE to Ban BlackBerrys

#8
post #5
post #4

How would a startup go about selling monitoring services to the UAE government?

Considering that the traffic is encrypted between the devices and RIM's servers, you'd have to try to 1) break the encryption or 2) gain access to RIM's internal network, and 3) check your morals at the door. Good luck.

they already have the monitoring capability. where they don't they just block the site/service (ie. Blackberry, Skype or any VoIP service really)

You might make a fortune selling VPN etc solution access to expats there though.

Re: Schneier on UAE to Ban BlackBerrys

#9
post #7

He makes an excellent point about that nonsense 'even we at RIM don't see the unencrypted data' which RIM seems to think convinces people. How can makers of the software doing the encryption not know the plaintext?

By not having control over the endpoints where the data is encrypted and decrypted, and being trustworthy.

Microsoft don't have the plaintext of Windows user's SSL encrypted web browsing, but they could if they changed their software to send them the plaintext too.

Re: Schneier on UAE to Ban BlackBerrys

#10
post #7

He makes an excellent point about that nonsense 'even we at RIM don't see the unencrypted data' which RIM seems to think convinces people. How can makers of the software doing the encryption not know the plaintext?

They don't have to do the encryption on their computers, they can do it on the devices.
Post reply on HN