Russian Software Company Says Its App Can Crack BlackBerry Security
AZA43 leaps into the ranks of accepted submitters, writing "Russian security software vendor Elcomsoft has released an app that it claims can determine BlackBerry handheld passwords. The software supposedly hacks the BlackBerry password via an advanced handheld security setting that's meant to encrypt data stored on a user's memory card. And a hacker doesn't even need to have the BlackBerry to determine a password, just the media card."
news at 11...big freaking deal...
What this world is coming to - is for you and me to decide.
...software cracks YOU!
This turns your Blackberry literally into a Crackberry.
It seems like the only time I read about anything Russians do with computer tech, it involves botnets, stealing passwords, and ripping off peoples bank accounts. Are there any Russians that contribute something positive to the world of software?
If you actually read this one you'll realize it's useless if the card isn't encrypted (ironically) or the user chose one of the other 3 options. Plus this option is designed to be less secure so you can put the card in another device and decrypt it with just a password. I also wonder what character set is included in their claim of cracking a 7 character password in just hours. http://xkcd.com/936/
Why would the password be stored, in any form recoverable by means that aren't computationally intractable brute forcing, anywhere in the device or storage expansion cards?
Isn't this the sort of thing that hashing is supposed to solve?
Russians are good at cracking software. It is a puzzle that they are so bad at creating it.
an ill wind that blows no good
Kaspersky?
Talk about getting pwned.
Boot Windows, Linux, and ESX over the network for free.
RIM will not even exists within a year or so. I'ts only a matter of time before they get completely slaughtered and file for bankrupcy etc..
In other news "Other Russians Say They Cracked BlackBerry Years Ago" but kept mum about, for "financial and business reasons". ;)
Pure speculation here:
Since this only works with media encryption enabled, I'm guessing this is an alternative cipher attack. They can't directly obtain the Blackberry device password, but they can break the media encryption (perhaps because it is a much weaker cipher). The media encryption key is likely the same as or derived from the device password, allowing an expedited attack on that.
Moral of the story: If you derive a key for a weak cipher from a key used for a strong one, make sure you use an irreversible function to do so.
Not sure about "useful", but Tetris sprints to mind as something positive
http://en.wikipedia.org/wiki/Sergey_Brin
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
if Putin crossed paths with Chuck Norris
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
Many times over the past 2 decades. E.G.-> I was an avid Borland Delphi dev. circa 1995-2002, & a good % of those that contributed VCL were Russian coders.
(VCL prebuilt objects/libs, albeit, with added or better functionality than std. ones Borland gave you)
I'm SURE that the same goes for C/C++ over time & probably Assembly work before that, etc./et al...
* Then again, I am inclined to go with you on some grounds, online security ones, because I have been populating a custom HOSTS file vs. malware infested sites, botnet C&C servers, known bogus hosts-domain names, & adbanners too, & where do a LARGE %-age of them come out of? You guessed it: The U.S.S.R./Soviet Union/Russia...
"Are there any Russians that contribute something positive to the world of software?" - by Beelzebud (1361137) on Sunday October 02, @12:38PM (#37583738)
Per what I wrote above, you have a SMALL fraction of a possible answer...
(It's the same anywhere though - you've got your "normal folks" & you've got your "criminal elements" too...)
APK
P.S.=> As to what I opened with - Pretty much any custom VCL site can show folks this, & once there? Take a peek around @ the VCL authors' names: You'll see what I mean...
Then also, you've got the guys in the FREEWARE 64 bit world who did UltraDefrag64:
http://it.slashdot.org/comments.pl?sid=2435272&cid=37443252
(Which is 1 of INFOWORLD's "top picks" recently for good freeware)
They're russians too.
Honestly - I'm not even BEGINNING to scratch the surface here either, not really!
Face it - Every culture has "good" & "bad" folks (some are bad due to bad decisions forcing their hands too I'd imagine as well, so, i.e.-> They're not really "evil", just more desperate)...
... apk
"nigger" - by Anonymous Coward ANOTHER "ne'er-do-well" /. OFF-TOPIC TROLL on Sunday October 02, @05:43PM (#37585392)
"???"
Uhm... Could we get a translation of that off-topic "troll-speak/trolllanguage" of yours, please?
---
* And, you're an off-topic troll - no questions asked...SEE MY SUBJECT LINE ABOVE!
APK
P.S.=> Yes, it must have just have been another off-topic done nothing of significance with his life troll spewing his off-topic b.s. again & not contributing to the ongoing conversations. Oh well - No biggie!
("ReVeRsE-PsYcHoLoGy", for trolls - Courtesy of this code by "yours truly" in less than 1 second flat):
---
#TrollTalkComReversePsychologyKiller.py (Ver #2 by APK)
def reverse(s):
try:
trollstring = ""
for apksays in s:
trollstring = apksays + trollstring
except:
print("error/abend in reverse function")
return trollstring
s = ""
print reverse(s)
try:
s = "Insert whatever 'trollspeak/trolllanguage' gibberish occurs here..."
s = reverse(s)
print(s)
except Exception as e:
print(e)
---
... apk
"reggin" - by Anonymous Coward ANOTHER "ne'er-do-well" /. OFF-TOPIC TROLL on by Anonymous Coward on Sunday October 02, @05:43PM (#37585392)
"???"
Uhm... Could we get a translation of that off-topic "troll-speak/trolllanguage" of yours, please?
* And, you're an off-topic troll - no questions asked...SEE MY SUBJECT LINE ABOVE!
APK
P.S.=> Yes, it must have just have been another off-topic done nothing of significance with his life troll spewing his off-topic b.s. again & not contributing to the ongoing conversations. Oh well - No biggie!
("ReVeRsE-PsYcHoLoGy", for trolls - Courtesy of this code by "yours truly" in less than 1 second flat):
---
#TrollTalkComReversePsychologyKiller.py (Ver #2 by APK)
def reverse(s):
try:
trollstring = ""
for apksays in s:
trollstring = apksays + trollstring
except:
print("error/abend in reverse function")
return trollstring
s = ""
print reverse(s)
try:
s = "Insert whatever 'trollspeak/trolllanguage' gibberish occurs here..."
s = reverse(s)
print(s)
except Exception as e:
print(e)
---
... apk
This is the same company that employed Dmitry Skylarov, one of the first people to be arrested under the DMCA for breaking the encryption on Adobe's eBook format.
http://en.wikipedia.org/wiki/Dmitry_Sklyarov
Let's try not posting this as an Anonymous Coward by mistake.
This is the same company that employed Dmitry Skylarov, one of the first people to be arrested under the DMCA for breaking the encryption on Adobe's eBook format.
http://en.wikipedia.org/wiki/Dmitry_Sklyarov
Karma: Positive. Mostly effected by cowbell.
It seems like the only time I read about anything an American wrote, it involves ignorance, bad generalizations, and a us versus them mentality. Are there any Americans that contribute something positive to the world?
This is simply brute-forcing the password, relying on a short user password. It is only viable if the user has set up the phone security options in a weak way: selected to encrypt media card with user password only, rather than user password plus device key. So really there is nothing surprising in this attack. If you want good security on a Blackberry, it's a matter of setting it up in the options.
"Politicians and diapers must be changed often, and for the same reason."
If you understand what a known-plaintext attack is you have explained it very badly. It may well be that a known plaintext attack is possible because you expect certain files or file structure to be in place but known plaintext means that you know specific parts of the plaintext not just that you are looking for anything that isn't gibberish.
Posted anonymously so that I can mod you down.