Slashdot Mirror


Russian Software Company Says Its App Can Crack BlackBerry Security

AZA43 leaps into the ranks of accepted submitters, writing "Russian security software vendor Elcomsoft has released an app that it claims can determine BlackBerry handheld passwords. The software supposedly hacks the BlackBerry password via an advanced handheld security setting that's meant to encrypt data stored on a user's memory card. And a hacker doesn't even need to have the BlackBerry to determine a password, just the media card."

45 of 78 comments (clear)

  1. In Soviet Russia... by ksd1337 · · Score: 2

    ...software cracks YOU!

  2. Do Russians contribute anything useful? by Beelzebud · · Score: 2, Insightful

    It seems like the only time I read about anything Russians do with computer tech, it involves botnets, stealing passwords, and ripping off peoples bank accounts. Are there any Russians that contribute something positive to the world of software?

    1. Re:Do Russians contribute anything useful? by Threni · · Score: 1

      They provide entertaining plane/sub/ etc disasters. Oh, and putin does stuff like lying about finding ancient vases etc when he goes swimming. He's like that bearded Iranian twat. But without the beard.

    2. Re:Do Russians contribute anything useful? by thht · · Score: 2, Funny

      Kaspersky?

    3. Re:Do Russians contribute anything useful? by Anonymous Coward · · Score: 4, Funny

      Are there any Russians that contribute something positive to the world of software?

      Tetris alone puts them way ahead of most countries.

    4. Re:Do Russians contribute anything useful? by Osgeld · · Score: 2

      they have pinouts for everything!

      http://pinouts.ru/

    5. Re:Do Russians contribute anything useful? by ripdajacker · · Score: 3, Insightful

      One might view the testing and breaking of security as a valuable contribution. How else will companies like RIM learn?

    6. Re:Do Russians contribute anything useful? by davester666 · · Score: 1

      Unfortunately, RIM has two CEOs, and it appears it takes them twice as long as everybody else to learn things.

      --
      Sleep your way to a whiter smile...date a dentist!
    7. Re:Do Russians contribute anything useful? by roman_mir · · Score: 1

      I am former Soviet, Israeli, Canadian, currently in Europe building and selling/deploying software systems that analyze and integrate retail operations within store chain (integrate stores into a chain) and between stores and suppliers/manufacturers. It's hard business to compete with Oracle, SAP, MS in this field as well as with a number of smaller providers, including Russian 1C (1S), which is supported by Russian government, even their owner is a 'comptroller general' for a very large part of Russian Federation. OTOH I don't have Russian citizenship, so :) maybe not precisely what you are asking.

    8. Re:Do Russians contribute anything useful? by fuzzyfuzzyfungus · · Score: 4, Funny

      I'm told that they are currently hunting for a third, because they think that a Mismanage à trois would be totally hot...

    9. Re:Do Russians contribute anything useful? by Anonymous Coward · · Score: 1

      Have you seen that picture of him riding the shark though? A guy who could harness a wild shark and ride it around the sea, is probably badass enough to happen upon an ancient vase. Even more likely to do so because he would be traveling at shark speed through the water, rather than human speed.

    10. Re:Do Russians contribute anything useful? by Reservoir+Penguin · · Score: 2

      Parallels.

      --
      US-UK-Israel: The real Axis of Evil
    11. Re:Do Russians contribute anything useful? by X.25 · · Score: 1

      It seems like the only time I read about anything Russians do with computer tech, it involves botnets, stealing passwords, and ripping off peoples bank accounts. Are there any Russians that contribute something positive to the world of software?

      No, of course not, you stupid retard. All Russians are criminals, right?

      How are you not ashamed of publicly admitting that you don't read anything is beyond me, though.

    12. Re:Do Russians contribute anything useful? by melted · · Score: 1

      They do. There are a lot of Russian programmers working here in the US contributing quite heavily and positively to "the world of software". It's just that good news aren't as exciting.

      Engineer is really a third rate profession in an oil and gas rich country like Russia. Everyone wants to be a boss of some kind and to sit just a wee bit closer to the pipe. A few companies that manage to pull together good talent generally either work for the local market (because US is impossible to get into if you're not a US company), or offer outsourcing, or just keep low profile. Kaspersky writes antiviruses, but it was almost a decade before he figured out a viable strategy to enter the US market. Yandex works on the local market. Google, Cisco and Intel have dev offices there. I suspect many other large multinationals do, too.

    13. Re:Do Russians contribute anything useful? by TheRaven64 · · Score: 2, Informative

      How did this borderline racist shit get modded up? Two of the biggest open source projects that I work on (LLVM and FreeBSD) have a lot of Russian contributors. You are almost certainly using code (at least partially) written by Russians on a daily basis.

      --
      I am TheRaven on Soylent News
    14. Re:Do Russians contribute anything useful? by fatphil · · Score: 2

      Plenty working on Linux are from Russia too. The input layer subsystem is Dmitry Torokhov's ward, for example, and Artem Bityutskiy gave us UBI(FS). Not to mention a great number of footsoldiers contributing a whole host of drivers, features, fixes, etc. I've worked alongside a great many Russians, and they were highly skilled and rigorous engineers.

      --
      Also FatPhil on SoylentNews, id 863
    15. Re:Do Russians contribute anything useful? by tokul · · Score: 1

      Are there any Russians that contribute something positive to the world of software?

      rarlabs, akella, http://l10n.gnome.org/languages/ru/

    16. Re:Do Russians contribute anything useful? by Hentes · · Score: 2

      If they disclose the vulnerability instead of just exploiting it than it's useful. Also, Russians are very good at IT in general, you just only hear about the hackers as they are the ones to make the news.

    17. Re:Do Russians contribute anything useful? by gtall · · Score: 2

      Racist? Errrm...okay, I give up, how does casting aspersions on Russians constitute racism?

      The GP though should give the Russians a break. First the Tsars, then Stalin, and now Putin. Russkies do have a knack for finding the least capable people to run the country. Having a government which is the moral equivalent of La Cosa Nostra isn't a recipe for success. The Russkies should be hailed for still trying to succeed in spite of their leaders.

    18. Re:Do Russians contribute anything useful? by Unequivocal · · Score: 1

      Yeah good points. I'll add Nginx to the list. Jeez - that webserver software has been killing it in terms of capabilities (and market growth) for about 4 years. All thanks to a solid Russian OSS developer named Igor Sysoev.

      And if you want to dig a little deeper, the GiST index system for Postgres which enables GIS, spherical projections (for astronomy) and all kinds of other amazing solutions in Postgres - thanks to two great (and amazingly smart) guys also in Russia. http://www.sai.msu.su/~megera/postgres/gist/ (note the ".su" badass domain still). :)

    19. Re:Do Russians contribute anything useful? by hutsell · · Score: 1

      Isaac Asimov's Three Laws of Robotics. Initially, I found the simplistic algorithm to be strangely fascinating; in hindsight,
      I realized the exposure was my first experience with the idea of programming--something I still find strangely fascinating.

      From: ...Are there any Russians that contribute something positive to the world of software?

      --
      "God, please stop me before I code again."

      --
      Yesterday's Weirdness is Tomorrow's Reason Why
    20. Re:Do Russians contribute anything useful? by Eponymous+Hero · · Score: 1

      they trade us awesome hockey players. lawyered

      --
      insensitive clod overlords obligatory xkcd car analogy russian reversals whoosh pedant fanbois ftfy in 3...2...1..PROFIT
  3. Not reliable... by hawkbat05 · · Score: 5, Interesting

    If you actually read this one you'll realize it's useless if the card isn't encrypted (ironically) or the user chose one of the other 3 options. Plus this option is designed to be less secure so you can put the card in another device and decrypt it with just a password. I also wonder what character set is included in their claim of cracking a 7 character password in just hours. http://xkcd.com/936/

    1. Re:Not reliable... by Anonymous Coward · · Score: 1

      I don't think so. The Troubador password may have 5,748,511,570,879,116,626,495 possible requirements if brute forced, but it does not require pure brute forcing. A modified dictionary attack would quickly crack a one word password like that because people use certain patterns. For example, the capital letter usually only appears at the first position and numbers and symbols are appended to the end of the word. Additionally, "troubador" is likely to appear on some expanded word lists (in fact the comic seems to think it would appear on a list of 65,536 words on it). Put that all together, John the Ripper would likely get that fairly quick using some of their more basic rules.

      Conversely, the four words example appears to assume they would appear on a list shorter list of 2,048 possible words (to reduce uncertainty to 1 and guarantee a hit). Then, then you get 2048^4 (possible selections^number of selections) or 17,592,186,044,416 possible permutations to get the right words in the right order through brute forcing.

    2. Re:Not reliable... by Ja'Achan · · Score: 1

      That's assuming the average person will have 2048 words to choose from, rather than, say, 64.

    3. Re:Not reliable... by fatphil · · Score: 1

      And that he won't lock himself out by repeatedly trying "pony right cell staple", or similar.

      --
      Also FatPhil on SoylentNews, id 863
  4. Re:I wonder how they managed that... by hawkbat05 · · Score: 2

    They're brute forcing it

  5. Re:someone cracks blackberry security by PsychoSlashDot · · Score: 5, Informative

    news at 11...big freaking deal...

    You act like this is either unimportant or not news. I'm not sure which.

    Fact is while there's a lot of FUD floating around regarding things like RIM "caving in" and dropping BIS servers in questionable countries, there haven't actually been very many actual real-life exploits for the phones or their communications. Blackberry phone remains the only ones on the market that encrypt all data traffic by default and that encryption can't be disabled. If you're on BIS or if you're on BES, your unencrypted web traffic, e-mail traffic (even POP3) is encrypted at the device. That's still worlds ahead of the other devices.

    There's reports that one exploit exists that can decrypt Password Keeper data from a phone backup on a PC. There's this report that discusses recovery of phone unlock passwords. There's the widely discussed and misunderstood reports about RIM dropping BIS MDS servers in unfriendly countries and what that allows (hint: it has zero to do with Blackberries not in those countries).

    RIM's stuff is by and large still very, very secure by any comparison and their phones are unique in that regard. So the way I see it, this is both news (being a genuine security hack) and relevant (these phones being the best on the market).

    So stuff your ignorant sarcasm.

    --
    "Oh no... he found the .sig setting."
  6. Puzzling by amightywind · · Score: 1

    Russians are good at cracking software. It is a puzzle that they are so bad at creating it.

    --
    an ill wind that blows no good
  7. Re:I wonder how they managed that... by Sqr(twg) · · Score: 3, Informative

    The password is not stored in any form, of course. But if there's encrypted data on the card, and that data can be decrypted using only the password, then you can just try every possible password until you find one that doesn't result in gibberish. This is called a known-plaintext attack.

  8. Mod parent up. by RulerOf · · Score: 1

    Kaspersky?

    Talk about getting pwned.

    --
    Boot Windows, Linux, and ESX over the network for free.
  9. Re:someone cracks blackberry security by wiedzmin · · Score: 1

    Very well said. Though, I really hope this gets addressed, because I don't feel comfortable with having to make a choice between potentially exposing my device password or contents of my SD card..

    --
    Bow before me, for I am root.
  10. In other news by G3ckoG33k · · Score: 4, Funny

    In other news "Other Russians Say They Cracked BlackBerry Years Ago" but kept mum about, for "financial and business reasons". ;)

  11. Re:Why does this matter? by jkflying · · Score: 2

    Dunno. Here in South Africa, everybody has a BB. In an average week I probably see 3 people posting their new BBM number on facebook. Just because the US all went iPhone doesn't mean the rest of the world particularly agrees.

    --
    Help I am stuck in a signature factory!
  12. Same key? by russotto · · Score: 1, Interesting

    Pure speculation here:

    Since this only works with media encryption enabled, I'm guessing this is an alternative cipher attack. They can't directly obtain the Blackberry device password, but they can break the media encryption (perhaps because it is a much weaker cipher). The media encryption key is likely the same as or derived from the device password, allowing an expedited attack on that.

    Moral of the story: If you derive a key for a weak cipher from a key used for a strong one, make sure you use an irreversible function to do so.

  13. Re:someone cracks blackberry security by PsychoSlashDot · · Score: 1

    would you even care?

    Yes.

    just trying to inform the likes of ya.

    Inform away. So far you've got zero information content in either of your posts. Mine summarizes the known exploits and security topics. Yours don't. Feel free to drop the newsburger edgestuff at 11 nonsense and communicate with us. Drop down to the lesser language of English and educate me.

    --
    "Oh no... he found the .sig setting."
  14. Re:someone cracks blackberry security by ColdWetDog · · Score: 1

    Pics. Or it didn't happen.

    Slapping your epenis around with ol Psycho isn't terribly entertaining. You know something? Tell us.

    --
    Faster! Faster! Faster would be better!
  15. Re:someone cracks blackberry security by Bert64 · · Score: 3, Interesting

    RIM stuff is largely security by obscurity at this point however, very few people have seemingly tried to pull their stuff apart, and the few that have didn't find good things, see the pwn2own contest from this year for one such example.

    Android, iphone and even windows mobile devices are much easier to target because they are largely based on existing systems which are well understood... RIM are using a totally obscure black box that requires significant investment of time to reverse engineer. This doesn't mean it's secure, it just means that hackers will need to spend more time to find holes in it. On the other hand, it means that whitehats will also require more time to reverse engineer the system, whereas its highly possible that blackhats have already stolen the sourcecode.

    Most devices provide the option to run a VPN between the handset and a server under your control, only RIM require that there be a server under their control sitting in between.

    Most devices (RIM included) can also boot up and start talking to the network without requiring any user input, therefore the keys used for this encryption must be stored on the device somewhere, just waiting for someone appropriately skilled and motivated to work out how to extract them...

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  16. Sergey Brin? by circletimessquare · · Score: 2
    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
    1. Re:Sergey Brin? by Pseudonym+Authority · · Score: 1

      Yeah, but what has he done for me lately?

  17. I wonder what would happen by circletimessquare · · Score: 1

    if Putin crossed paths with Chuck Norris

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
  18. Blast to the past: Dmitry Skylarov by metallic · · Score: 4, Informative

    Let's try not posting this as an Anonymous Coward by mistake.

    This is the same company that employed Dmitry Skylarov, one of the first people to be arrested under the DMCA for breaking the encryption on Adobe's eBook format.

    http://en.wikipedia.org/wiki/Dmitry_Sklyarov

    --
    Karma: Positive. Mostly effected by cowbell.
  19. Re:someone cracks blackberry security by Fnord666 · · Score: 1

    RIM's stuff is by and large still very, very secure by any comparison and their phones are unique in that regard. So the way I see it, this is both news (being a genuine security hack) and relevant (these phones being the best on the market).

    This seems to be misunderstood as either a crack or a break in the security of the BB. It is neither. Elcomsoft is using a crib that they have found to attempt dictionary and/or brute force attacks, nothing more. See this blog post for the specific details about the file they are using. Unless there is something else that they haven't mentioned, this is a garden variety known plaintext attack.

    --
    'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  20. Notthing to see here... by Prune · · Score: 2

    This is simply brute-forcing the password, relying on a short user password. It is only viable if the user has set up the phone security options in a weak way: selected to encrypt media card with user password only, rather than user password plus device key. So really there is nothing surprising in this attack. If you want good security on a Blackberry, it's a matter of setting it up in the options.

    --
    "Politicians and diapers must be changed often, and for the same reason."
  21. Re:someone cracks blackberry security by Eponymous+Hero · · Score: 1

    fuck rule 10, i'm more interested in rule 34. where's the porn of these security vulnerabilities?

    --
    insensitive clod overlords obligatory xkcd car analogy russian reversals whoosh pedant fanbois ftfy in 3...2...1..PROFIT