MEMORIAL DAY SALE: Save 15% on ALL BlackBerry Accessories! Use Coupon Code MEM12.
Join Our 3 MILLION+ Members Today! Register Here | Login
Go Back   BlackBerry Forums at CrackBerry.com > BlackBerry Professionals > Business Users

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
    Thread Author   #1  
Old 01-06-2011, 10:27 PM
CrackBerry Newbie
 
Join Date: Jan 2011
Posts: 4
Likes Received: 0
Thanked 0 Times in 0 Posts
Default BBM Encryption compromised. What now?

A person in my office received an anonymous email that contained a copy of all bbm chats the person had with another person in the office. How is this possible? I thought bbm was encrypted point to point. Neither one of the two people ever downloaded their bbm chats. Does this mean the BES at the company keeps logs of bbm chats and they were compromised? Does the government have access to bbm chats? What is the best solution for this? Is there off the shelf software that can be installed on the blackberry to have true client based encryption? Help....thanks
Reply With Quote Tip this Post
    Thread Author   #2  
Old 01-07-2011, 08:33 PM
CrackBerry Newbie
 
Join Date: Jan 2011
Posts: 4
Likes Received: 0
Thanked 0 Times in 0 Posts
Default

More update: the person's email in outlook is automatically generating an email that has a subject that reads: BlackBerry Messenger Usage Report and it has a detailed minute by minute log of EVERYTHING that has happened on the BBM, status updates, messages sent and received with the PIN number and time for each entry. I need to figure out what to do. Any help would be greatly appreciated.
Reply With Quote Tip this Post
  #3  
Old 01-07-2011, 09:11 PM
CrackBerry Abuser
Device(s): 9630 (Tour), Galaxy Nexus
Carrier: Verizon
Pin: What's a PIN?
 
Join Date: Jan 2009
Posts: 251
Likes Received: 0
Thanked 7 Times in 6 Posts
Default

If you're on a BES, your employer can log all your BBM messages.

Posted from my CrackBerry at wapforums.crackberry.com
Reply With Quote Tip this Post
    Thread Author   #4  
Old 01-07-2011, 10:40 PM
CrackBerry Newbie
 
Join Date: Jan 2011
Posts: 4
Likes Received: 0
Thanked 0 Times in 0 Posts
Default

Wow I had no idea that with a BES all the BBM messages were being logged. I thought BBM was encrypted from each device point to point. So if the BES can log everything then that is where the interception is taking place. However, here the problem is that the log is being sent by email to a yahoo email from each user's outlook without the user sending it. So that would mean that someone with access to the BES could then have the log sent to an email of their choosing from the person's outlook? How would a person with access to the BES program for the log to be sent out from each user's account? The sent emails DO NOT appear on the BlackBerry but they are in the outlook Sent Items folder.
Thanks for your help
Reply With Quote Tip this Post
    Thread Author   #5  
Old 01-07-2011, 10:51 PM
CrackBerry Newbie
 
Join Date: Jan 2011
Posts: 4
Likes Received: 0
Thanked 0 Times in 0 Posts
Default

This is what the email that is being sent out looks like with a very long list of each entry on the BBM including status updates, etc (I replaced the last two digits of the PIN with and X and the text with "TEXT"):

Subject: BlackBerry Messenger Usage Report Jan 6, 2011 14:05 - Jan 7, 2011 14:05

19:05 < (247886XX) TEXTTEXTTEXTTEXT
19:05 < (247886XX) TEXTTEXTTEXTTEXT
Reply With Quote Tip this Post
  #6  
Old 01-08-2011, 06:25 AM
CrackBerry User
Device(s): Storm 9500
Carrier: Optus
Pin: PM me
 
Location: Rockhampton
Join Date: Nov 2010
Posts: 73
Likes Received: 0
Thanked 3 Times in 3 Posts
Default

Maybe it was sent from a sysadmin as a warning for inappropriate use of company resources. Report it to management and have it investigated. The IT department needs to know there is a security breach in the organisation.
__________________
Blackberry Torch 9800 - OS 6.0.0.546
Reply With Quote Tip this Post
Reply
BlackBerry Forums at CrackBerry.com > > BlackBerry Professionals > Business Users   BBM Encryption compromised. What now?

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes