Live data from Hacker News

Schneier on UAE to Ban BlackBerrys

schneier.com

21–27 of 27 posts

Re: Schneier on UAE to Ban BlackBerrys

#21
post #14

Schneier and WSJ seem to put an emphasis on the concept of government interest in monitoring its citizens (or subjects in the U.A.E. I guess). The internal motivations for this action may be different. For example, maybe the U.A.E. sees BB as a bit of critical infrastructure that they don't want other countries to be able to monitor. First article: "The U.A.E. acted after RIM refused to set up a proxy server in the c…

It can also have other legal implications. We (a non-US company) just got informed by legal that we shouldn't email copies of our patents internally because our email supplier is in the US - and any of our patents could be regarded as US property.

So a contract sent on a Blackberry between two UAE parties - could come under Canadian law.

Re: Schneier on UAE to Ban BlackBerrys

#22
post #18
post #6

>RIM makes a big deal about how secure its users' data is, but I don't know how much of that to believe: It sounds like RIM is describing normal public key encryption. I'm not sure why Schneier thinks they have the plaintext, though admittedly "customer data" could refer to anything.

Since you're presumably entering the data (i.e., email text) using a BlackBerry device, running an RIM-developed operating system, device drivers and so on, RIM most likely "have" your data. At least that was how I interpreted it, and it makes sense to me.

That's not how computers work.

Re: Schneier on UAE to Ban BlackBerrys

#23
post #18
post #6

>RIM makes a big deal about how secure its users' data is, but I don't know how much of that to believe: It sounds like RIM is describing normal public key encryption. I'm not sure why Schneier thinks they have the plaintext, though admittedly "customer data" could refer to anything.

Since you're presumably entering the data (i.e., email text) using a BlackBerry device, running an RIM-developed operating system, device drivers and so on, RIM most likely "have" your data. At least that was how I interpreted it, and it makes sense to me.

Especially considering on the other end your email comes out as plain text (it's not a requirement to send to other BB devices). Perhaps their messager service works completely encrypted, but as far as emails go that's surely not the case.

Re: Schneier on UAE to Ban BlackBerrys

#24
post #18
post #6

>RIM makes a big deal about how secure its users' data is, but I don't know how much of that to believe: It sounds like RIM is describing normal public key encryption. I'm not sure why Schneier thinks they have the plaintext, though admittedly "customer data" could refer to anything.

Since you're presumably entering the data (i.e., email text) using a BlackBerry device, running an RIM-developed operating system, device drivers and so on, RIM most likely "have" your data. At least that was how I interpreted it, and it makes sense to me.

That's like saying Mozilla has emails you sent through Gmail, because you know they made Firefox. It doesn't work that way.

Re: Schneier on UAE to Ban BlackBerrys

#25
post #6

>RIM makes a big deal about how secure its users' data is, but I don't know how much of that to believe: It sounds like RIM is describing normal public key encryption. I'm not sure why Schneier thinks they have the plaintext, though admittedly "customer data" could refer to anything.

This is from the BES Security Technical Overview [1 p.30] [pdf]:

    Before the BlackBerry device sends a message, it 
    compresses and encrypts the message using the device 
    transport key. When the BlackBerry Enterprise Server 
    receives a message from the BlackBerry device, the 
    BlackBerry Dispatcher decrypts the message using the 
    device transport key, and then decompresses the message.
Doesn't that mean that BES has the plaintext?

[1] http://docs.blackberry.com/en/admin/deliverables/16650/Black...

Re: Schneier on UAE to Ban BlackBerrys

#26
post #6

>RIM makes a big deal about how secure its users' data is, but I don't know how much of that to believe: It sounds like RIM is describing normal public key encryption. I'm not sure why Schneier thinks they have the plaintext, though admittedly "customer data" could refer to anything.

This is from the BES Security Technical Overview [1 p.30] [pdf]: Before the BlackBerry device sends a message, it compresses and encrypts the message using the device transport key. When the BlackBerry Enterprise Server receives a message from the BlackBerry device, the BlackBerry Dispatcher decrypts the message using the device transport key, and then decompresses the message. Doesn't that mean that BES has the plai…

BES has the plaintext, but where is BES located?

Re: Schneier on UAE to Ban BlackBerrys

#27
RIM should sit tight and do nothing, IMO. Those 500,000 users are likely to be the most important movers and sheik'ers in the Saudi kingdom. When their Blackberry service goes dark, the government absolutely will be held accountable.
Post reply on HN