1. Daniel.Black's Avatar


    Have you ever been surfing to a website on your BlackBerry using the default browser and a certificate error pops up? Well if this happens be sure to pay close attention before clicking continue.



    Valid Certificate (Name and Domain match)

    According to a Research in Motion (RIM) security warning [Click Here] on some BlackBerry Operating Systems (OS) the system allows web sites to pass domain names with null characters in them. This gives the illusion that the domain and certificate are valid when in fact they are not.



    Fake Certificate (Name and Domain do not match)

    RIM recommends that all users running handheld OS 4.5 or higher, check to be sure they are running the latest OS version for their handheld.

    Major Carrier BlackBerry Download Pages

    * Altel: Alltel Downloads
    * AT&T: https://www.blackberry.com/Downloads/entry.do
    * Sprint: https://www.blackberry.com/Downloads/entry.do
    * T-Mobile: T-Mobile BlackBerry Downlods
    * Verizon: BlackBerry® Software Updates
    * Official Research in Motion Downloads Page: BlackBerry - Update your Device Software

    Current Software Version

    * BlackBerry Device Software v4.5.0.x NEED v4.5.0.173 or later
    * BlackBerry Device Software v4.6.0.x NEED v4.6.0.303 or later
    * BlackBerry Device Software v4.6.1.x NEED v4.6.1.309 or later
    * BlackBerry Device Software v4.7.0.x NEED v4.7.0.179 or later
    * BlackBerry Device Software v4.7.1.x NEED v4.7.1.57 or later

    Unfortunately after doing a quick check of AT&T and Verizon’s BlackBerry download pages, the recommended OS versions were not readily available.

    In the mean time, if you are unable to upgrade to the recommended OS level then I highly recommend you do not accept certificates from any site you do not fully trust.

    [source: BlackBerry Security]

    MobiMadness Article: Security Warning: BlackBerry Browser Allows Phishing Attacks | MobiMadness
    Last edited by Daniel.Black; 09-29-09 at 04:29 PM.
    09-29-09 01:48 PM
  2. garbagefairy1967's Avatar
    Thanks for the heads up!! Kinda unsettling actually..
    09-29-09 01:52 PM
  3. JRSCCivic98's Avatar
    OMG!!! What?!??! Blackberry is not as secure as everyone thought?
    09-29-09 02:42 PM
  4. lordcliff's Avatar
    So I need 4.5.0.173 but .162 is latest available for 8320? What sense does that make? Well, .81 is what my carrier (tmo) has last I checked.

    Posted from my CrackBerry at wapforums.crackberry.com
    09-29-09 03:03 PM
  5. p08757's Avatar
    Thank you. Will this kick our carriers in the **** to release a good version of 5.0 any sooner? I hope so!
    09-29-09 03:15 PM
  6. Mr Pogle's Avatar
    Oh wow...... something else I've learned about my BB


    Mr Pogle
    09-29-09 03:51 PM
  7. OskahOfDisastah's Avatar
    so does an 8900 on t-mobile running 4.6.1.231 need an upgrade? because i dont see the link for t-mobile devices
    09-29-09 04:23 PM
  8. Daniel.Black's Avatar
    so does an 8900 on t-mobile running 4.6.1.231 need an upgrade? because i dont see the link for t-mobile devices
    Based on the chart yes and I have added in the T-Mobile download link.
    09-29-09 04:30 PM
  9. OskahOfDisastah's Avatar
    Based on the chart yes and I have added in the T-Mobile download link.
    wow yeah i see it now, i must have been blind for that moment, thanks!
    09-29-09 06:03 PM
  10. Coruptyed's Avatar
    wow thanks for the update! and too bad the os isnt available..
    09-29-09 10:08 PM
LINK TO POST COPIED TO CLIPBOARD