Spyware In BlackBerry Updates For Users in the UAE
mulaz writes with this excerpt from The Register: "An update pushed out to BlackBerry users on the Etisalat network in the United Arab Emirates appears to contain remotely-triggered spyware that allows the interception of messages and emails, as well as crippling battery life. Sent out as a WAP Push message, the update installs a Java file that one curious customer decided to take a closer look at, only to discover an application intended to intercept both email and text messages, sending a copy to an Etisalat server without the user being aware of anything beyond a slightly excessive battery drain."
Panties Stink!
They really, really stink!
Sometimes they're red, sometimes they're green,
Sometimes they're white or black or pink
Sometimes they're satin, sometimes they're lace
Sometimes they're cotton and soak up stains
But at the end of the day, it really makes you think
Wooooooo-wheeeee! Panties stink!
Sometimes they're on the bathroom floor
Your girlfriend- what a whore!
Sometimes they're warm and wet and raw
From beneath the skirt of your mother-in-law
Brownish stains from daily wear
A gusset full of pubic hair
Just make sure your nose is ready
For the tang of a sweat-soaked wedgie
In your hand a pair of drawers
With a funky feminine discharge
Give your nose a rest, fix yourself a drink
cause wooooooo-wheeeeeee! panties stink!
c'mon real time backup, can't beat that.
Mod me down. Now!
" as well as crippling battery life." is not the same as "a slightly excessive battery drain."
Steve Jobs and I are gay lovers (I was the one who gave him HIV). I gotta say he gives good head and has one of the tightest anuses around considering the constant flow of dicks in his ass.
As far as non-north-american countries go - the UAE is very progressive. But a former client of mine who spent 8 yrs there working in administration pointed out - "in North America we are an odd country and culture - we simply take it as the norm that nobody will listen to us. That level of privacy is not the norm, it's unusual" He was in a senior healthcare position and essentially knew as a foreigner in a position of influence that he would be monitored regularly if not constantly.
slightly excessive battery drain
As a crackberry user myself, I can tell you that sometimes a change in battery life isn't even something I would worry much about. Considering the number of applications that many of us have on our 'berries, the number we have in the background at any given time, and the amount we use the applications in the foreground, a noticeable shift in battery life between Tuesday and Wednesday might not be considered abnormal. I know there are people who just charge every night religiously because they always want to start with a full battery in the morning; if they ended at 45% instead of 55% they might not think anything of it as long as their charge made it to the end of the day.
On the other hand if they normally end at 45% and now they don't make it through the day, they would likely notice that.
Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
my guess is the UAE wanted to come inline with U.S. American standards of communications.
Why would the carrier need to route messages and data coming through their systems *back* to their systems to read them? They are, after all, the carrier of all this data in the first place. Why can't they just sniff around in it in the middle?
Something smells fishy.
Porquoi?
So I am paying for my bandwidth twice, first to receive the message and a second time for it to be forwarded to TPTB. Talk about being fsckd!
the register has a followup (including some code) here.
Apparently etisalat claims the spyware is for troubleshooting during the 2g to 3g upgrade.
The Register article stated:
It pointed to this link: http://supportforums.blackberry.com/rim/board/message?board.id=BlackBerryDeviceSoftware&thread.id=5504&view=by_date_ascending&page=2
But if you follow it you get:
Interesting.
Doug
I'm not very familiar with RIM's network architecture, so it wasn't clear to me whether the UAE needed RIM's help in distributing the spyware or whether it was entirely the doing of the local phone carrier in the UAE.
Would the UAE had to have had RIM's help or did they simply buy the services of the third-party spyware vendor?
-Sean
If so, then you're already paying to be spied on to the government anyway.
I am assuming it only installed on Blackberry's that were customers of Etisalat's network - or if I was traveling there at the time of the push, would it have installed on my blackberry as well?
It's just a typo in the link, and for some reason the 404 page says "deleted" instead of just "not found". If you read the elreg comments page, you can find the corrected URL and the thread is still live:
http://supportforums.blackberry.com/rim/board/message?board.id=BlackBerryDeviceSoftware&thread.id=5632&view=by_date_ascending&page=1
I thought the messages between blackberries were encrypted. How is a man in the middle attack even possible?
rose@askauntrose.com
Here is the full compiled code as well as the decompiled source
http://www.zshare.net/download/6271263910e5cbec/
Death Penalty, no we dont have it for any crime, this is the touchstone for the difference between civilised countries and others. Only uncivilised countries have the death penalty.
Socail security- You dont have a proper social security system compared with other countries.
Health Care-The US does not have universal health care but spends more than countries that do, quite an achievement.
The Gun- As much a religion to some in the US as the bible, we got rid of most of the guns in our society and we have no regrets.
YAnks just dont know what socialism is do they?
"No basic healthcare"? Sorry, fucktard, anyone who's sick can go to the ER and get treated. There is basic health care. "The gun and the bible". I understand that this whole "freedom of religion" thing pisses you off, as you'd like to force everyone to be an atheist. That's really fucking progressive. Perhaps you forgot the point of the gun. The gun is so that the government doesn't become like the European governments they left 250 years ago. So the government doesn't become like Hitler's Germany or Stalin's Russia. For an acid test, how about you get a Nazi flag, march up and down a sidewalk in the US, and then try the same thing in Germany.
By the way, I know how healthcare works in Europe. "Oh, you have insurance, come ahead now." Maybe Greece and Italy aren't part of Europe, but your universal healthcare seems to be a case of some pigs are more equal.
By the way, retards. I'm in the Emirates right now, and it's the most progressive country I've seen outside of North America, if by progressive you mean "progressing towards human rights." And yes, I've spent quite a while in quite a few european and African countries.
Maybe they/we need a crypto-twitter app?
Does something like this exist?
The article mentioned in the original post linked to a BlackBerry support forums post explaining the spyware and how to remove it.
Post was quickly deleted by forum admins.
Copy mostly still available through Google cache, and has been reposted. Let's see how long it stays up.
I can't believe my country would try something like this. For the love of god we are not Homeland or the FBI or even the CIA!!! My ISP have made a name for them self's as the biggest idiots I have ever known. I hope this will tech them a lesson."Performance enhancement patch"
There is one non-Islamic country in the Middle East. It kind of breaks your interesting list of general features, which only seems to have included Islamic Middle Eastern countries.
And actually, the Palestinian Authority doesn't seem to fit into your general classification, either.
Now.. the President owns a Blackberry. Does he know about this? Foreigners could be spying on our President's texting. That would not be helpful in treaty negotiation.
Can you be Even More Awesome?!
Veracode has provided an analysis of the spyware source code. The spyware apparently is designed to encrypt messages it grabs from a BlackBerry before it sends them back to the server so that anyone intercepting the data en-route would not be able to read it.
Just open talk to cell phone discussion