- 01-31-2013, 05:17 PM
Thread Author #1
So is BB10 still as secure as the previous BB's now that it's not going through BIS? And other Q's
Hi all,
I tried searching for this but couldn't find anything directly related (even when it recommended 'similar threads' as I created this post). If there is then kindly point me to that post.
I'm just trying to understand the implications of BB10 not going through BIS anymore (as it seems to be the case).
1. Wasn't it BIS that made Blackberry's communication so encrypted and secure (outside of BES)? What happens now?
2. Wasn't it BIS that compressed the data used so that we were able to get more data use out of our phone plans than the rest? This was a big selling point for people that travelled and roamed using data a lot. What happens now? Is it compressed at all?any more or less than iphone/samsung?
3. Is BBM the only thing going through BIS on BB10, or is all of our data going through BIS on BB10, or is none of it? One of the reasons I enjoy doing mobile banking on my 9900 is because I know it's a secure connection through the BIS--as I understood. Is this no longer the case?
4. If BIS is out of the picture, what is Blackberry going to use it for (outside of BB7 devices)?
Thanks - 01-31-2013, 05:25 PM
Thread Author #2
- 01-31-2013, 05:53 PM #3
1. Most mail servers will used SSL/TLS to encrypted data that it sends to the phone. This was not the case many years ago. SSL certificates were very expensive.
2. You found your answer I see.
3. BBM messages would still use the Blackberry's BIS/NOC. No difference there. I am guessing you are using the 9900's web browser. The bank's website will encrypt the data to and from the phone.
4. They will us it for BBM Video Chat and many other services
I hope this helps. - 02-08-2013, 08:44 AM #6
I honestly would not worry too much about security (or lack thereof). Of the millions and millions of Android phones sold, the actual documented security breaches where people have had data compromised is ridiculously small...infinitesimal actually. It's just the new buzzword that Android haters use now that they rule the mobile phone world...similar to people calling the iPhone stale or calling their devoted fans "fanboys".
There is no way to tell what apps are android within Blackberry World by the way.
Sent from my SAMSUNG-SGH-I317 using Tapatalk 2 - 02-08-2013, 09:03 AM #7
Not true. I wouldn't dare do any business on my SG3 which is why I still used a bold 9900. You have no idea how many actual security breaches are simply not documented. I know one company that had BYOD and then had a major security breach . You think they ran out to tell the world about it? It's amazing how the masses are in the dark.
- 02-08-2013, 09:40 AM #8
-
CrackBerry Genius
- Posts
- 3,257 Posts
- Global Posts
- 3,275 Global Posts
- PIN
- Proud contributer to The Human Fund
02-08-2013, 09:44 AM #9"Hard work spotlights the character of people: some turn up their sleeves, some turn up their noses, and some don't turn up at all." -Sam Ewing
Rollin' on Twitter
- 02-08-2013, 09:49 AM #10
I think the fips security on BB's has always been more on BES environment than the BIS environment. The one thing about bb is that it can't be rooted like the other systems. That doesn't mean that a browser attack can't happen either though, it just won't get to the OS.
Sent from me using my fingers. Be pantless in 5K. Febreze - for more than smells.
the 50K CrackBerry challenge - 05-03-2013, 11:18 AM #11
This Powerful Spy Software Is Being Abused By Governments Around The World
Read more: Countries With FinFisher Spying Software - Business InsiderLast edited by naviwilliams; 05-03-2013 at 12:39 PM. Reason: one link was removed
- 05-03-2013, 11:33 AM #12
Last edited by kbz1960; 05-03-2013 at 11:56 AM.
Sent from me using my fingers. Be pantless in 5K. Febreze - for more than smells.
the 50K CrackBerry challenge - 05-03-2013, 11:55 AM #14Sent from me using my fingers. Be pantless in 5K. Febreze - for more than smells.
the 50K CrackBerry challenge - 05-03-2013, 12:03 PM #15Thanked by:
Julius Leee (05-03-2013)
- 05-03-2013, 12:16 PM #16Sent from me using my fingers. Be pantless in 5K. Febreze - for more than smells.
the 50K CrackBerry challenge - 05-03-2013, 12:27 PM #17
I understand that completely.
But like I said, I'm just informing people of what's out there. I too value my security and privacy as much as anyone else when it comes to mobile phones, whether it be Blackberry, Android or IOS.
I'm not forcing you or anyone to check the links. That is totally up you. - 05-03-2013, 12:40 PM #18
I removed the Spy Files link(s). This article is so old, and I think we've probably moved on technology wise and security wise, too, since 2011...
- 05-03-2013, 12:47 PM #19
True...it's probably built into the BB10 software by now.
This has more up to date info.
There is an entire section of the report that covers FinSpy mobile, with technical details: https://citizenlab.org/storage/finfi...ireyesonly.pdfLast edited by jackdagripper; 05-03-2013 at 01:07 PM.
- 05-03-2013, 08:50 PM #20
BES is the product that made BlackBerry secure for business and government users.. BIS also used encryption, but it was "consumer grade", and not intended for high security (there is facility for law enforcement access in BIS that does not exist in BES).
Getting rid of BIS actually increases security in some instances: if your email service supports SSL/TLS, you're actually potentially more secure than with BIS transport..
There's actually lots of information about the security measures on the BlackBerry Web site..
Posted via CB10 - 05-03-2013, 10:35 PM #21
Answer:
Dear BES admins, I need some help...
Posted via CB10Future cross-platform BBM ad: "Your government not knowing that you are sexting? 0,01367123287671 cents a day." - 05-04-2013, 02:25 AM #22www.blackberryphoto.com coming soon
- 05-04-2013, 03:06 AM #23
8300>>8520>>9900>> Z10
Playbook 32GB
Believe
- 05-04-2013, 03:30 AM #24
Unfortunately this thread wanders a bit. Specifically, if you want to see if you are on BIS, turn off your wifi. The enter IP Address Geolocation to Identify Website Visitor's Geographical Location on the browser. It should identify you being on a rim server. In my case on my 9780, it shows me in Farmington Michigan.
On my phone, when I am on wifi, BIS is bypassed on the browser. My own ISP shows up.
If you load a 3rd party browser other than Opera, you should see the network of your carrier. I used to have Bolt on my phone, and in my case it would show me being in Los Angeles. In realty, I'm in neither location.
There is something to be said for signing up for a VPN and just being secure no matter where you are.
proXPN VPN | Get your FREE proXPN VPN account now!
has been advertising on TWIT. The price drops to a bit over $5 if you use TWIT when you sign up. Note I have no first hand experience with this provider, but the price is right. ;-) You need a fast VPN for streaming.
BTW, I noticed there is a free open source Android implementation of openVPN from code.google.com. On my TODO list is to take the APK and do a BAR conversion. I can test it on my playbook. - 05-04-2013, 05:27 AM #25
With BIS, the email relationship is essentially proxied and you do NOT get both encryptions.. BIS talks to the various mail servers on your behalf, and this portion of the connection is protected using SSL/TLS where applicable, but then it has to transmit the emails to your phone, and this connection is protected via a weak mechanism, that BlackBerry themselves advise you to only consider as "scrambled".. You are also trusting the carrier/ BlackBerry with your email credentials so that the BIS can get your emails for you.. BIS was enjoyed because the proxy relationship allowed the BIS and BlackBerry infrastructure to do the heavy lifting and give you very fast push email, data compression and things like quick PDF rendering (the BIS would intercept the attachment, run it through Acrobat and extract the content on the fly and send down text or a compressed version), but this essentially meant that BlackBerry servers were "reading" your emails before delivering..
In the new BB10 model, there is no BIS "scrambling": your handset talks SSL/TLS directly with your email server.. Your credentials and passwords remain only on your device and are not shared with anyone.. This is a much more secure model but the email server must support push, and because BlackBerry cannot see past the encryption, they can no longer provide compression and attachment processing..
On BES though, you do get the extra BES encryption as well as SSL/TLS, but this is enterprise grade.
And I never said anything about BIS being hacked.. That system is monitored 24/7 by BlackBerry, but just because they're never been hacked doesn't mean that the protocols that they've chosen are secure..
Posted via CB10Thanked by:MarsupilamiX (05-04-2013)
Similar Threads
-
Any way to get google maps to use the native carrier network, not go through BIS?
By pmcilvaine in forum General BlackBerry DiscussionReplies: 10Last Post: 11-17-2009, 09:22 AM -
Why is att still referred to as cingular?
By knicksfan1025 in forum AT&TReplies: 15Last Post: 08-05-2009, 09:51 AM -
Why is att still referred to as cingular?
By knicksfan1025 in forum BlackBerry Bold 9000Replies: 4Last Post: 08-02-2009, 03:11 PM -
So Is All This Shaking Good For The BB Storm ???
By Mike-D in forum BlackBerry StormReplies: 23Last Post: 03-08-2009, 12:25 PM -
So is McCain still using his BlackBerry?
By Dave88LX in forum General BlackBerry DiscussionReplies: 6Last Post: 01-21-2009, 06:34 PM

Reply

?












