New research on voice call interception

by Rodolfo on February 5, 2010


ABI Research released the results of a new survey. The gist of it is that less than a fifth of companies use voice encryption solutions to protect their sensitive information [1].

The good news obviously is that around 18% do protect their financial, legal and R&D info. John Pescatore, security analyst at Gartner, perviously remarked “that 18% is a bit [to the] right, but in the ballpark” [2].

The survey, conducted amongst 250 senior executives in both medium and large organizations showed that despite regularly discussing financial information (78%), employee data (66%), as well as IP (51%) and commercial secrets (50%), the majority of these conversations are unprotected despite over 80% of respondents believing mobile phones to be as vulnerable, if not more so, than e-mail communications if leaked. Of those who admitted to regularly discussing sensitive information, 80% believed, if leaked, this information would have a major impact on the organisation.

Read the full press release.

[1] Disclaimer: the ABI Research survey was funded by Cellcrypt.
[2] Huge caveat: his remark is taken wildly out of context and he did not read the ABI report, so please read John’s original post in full on his blog before quoting him anywhere.

{ 0 comments }

Femtocells can be rooted too!

by Rodolfo on February 2, 2010

TrustWave just published some research on Femtocells (GSM base stations for enterprise sites) and found that those can be compromised, The Register reports.

after “hours of sniffing traffic, changing IP address ranges, guessing passwords and investigating hardware pinouts,” they “obtained root access on these Linux-based cellular-based devices”.

Femtocells and Picocells are equally vulnerable and there are doubts of how much valuable information could be gained by hacking into these devices. However it is important to note that more attacks are coming this way. This is mostly due to the fact that the devices are relatively new on the market and only now hackers are getting hands on experience.

{ 0 comments }

BlackBerry Security Guide

by Rodolfo on February 1, 2010

symcConcerned about BlackBerry security? Then you should read Attack Surface Analysis of BlackBerry Devices.

This guide was published by Symantec in 2007, so while some of the details might be out of date, the overall guide is very interesting. It covers all the security aspects of the device and even if you are only concerned about, say, phone snoopers or losing your device, with over 30 pages there is lot of good advice there.

Download Attack Surface Analysis of Blackberry Devices (PDF)

{ 0 comments }

How to secure mobile calls webinar Feb 24

by Rodolfo on January 29, 2010

Dr Larry Ponemon (from the Ponemon Institute) is hosting a webcast on cell phone calls vulnerabilities with Cellcrypt and other leading industry experts.

Larry is best known for the annual reports on the Cost of Data Breach and he his now looking at the vulnerabilities in the cellular networks as well.

You can register for the event here, the webcast is on February 24th 2010 @ 1100EST.

Below the full press release:

On December 27th, 2009 researchers announced the codebook that unscrambles GSM calls – used in 80% of cell phones – had been computed and published on the web. Free for any criminal to use, this lowers the cost of cell phone eavesdropping below $10,000.

But recent research shows that while four out of five IT executives think mobile phones are equally/more vulnerable than email, less than 20% of businesses have adequate mobile voice protection in place and regularly discuss sensitive and confidential information on cell phones. This poses a corporate threat to commercial secrets, executive safety, data record breaches and of financial transaction confidentiality.

Hosted by Dr. Larry Ponemon, this webinar assembles a panel of experts to discuss the key issues of the GSM Cracking threat, the wider implications of cell phone interception and how to cost-effectively implement adequate protection.

In just one hour, you will be fully briefed on the facts and armed with the right information to act.

{ 0 comments }

In a survey published yesterday, Gartner revealed the top 10 business and technology priorities for 2010.

Besides the obvious “Business process improvement” (as opposed to recommending deterioration in business processes?) there are some very good indicators of what strategic areas CIOs and board should focus.

Virtualization and Cloud computing on top, increased used of information/analytics all point toward the “real-time” enterprise.

What is relevant to BlackBerry users if the focus on mobile, security and voice communications, which solve the need for improving enterprise workforce effectiveness. The need for secure voice communications wherever you are is here to stay and it has to align to the corporate platform as opposed just being an external appendage managed by the telco with no accountability.

gartner

Overall a fascinating read, and hopefully most large corporates will move towards that direction. It has been 10 years since the Cluetrain Manifesto came out (already!) but the concept of markets as conversations still is not widely implemented across the board. Of course for communications IP and security are core tenets that need to be in place before anything else can happen.

Read more: Gartner Top 10 Business and Technology Priorities in 2010

{ Comments on this entry are closed }

3G encryption broken

January 12, 2010

Last month at a conference in Japan a group of Israeli mathematicians led by Adi Shamir announced that they had found a way to crack A5/3, the encryption algorithm used to protect the privacy of 3G calls.
Today the same group released the details of the attack, and it’s pretty amazing. Turns out that during the [...]

Read the full article →

RSA keys cracked, again

January 11, 2010

Last week an international team of researchers broke the 768bit RSA key using several hundred computers, The Register reports.
It’s interesting news but has little practical value, however, the part of the article everyone should read is:
More importantly, it means it’s only a matter of another decade or so – sooner assuming there’s some sort of [...]

Read the full article →

GSM cracking news roundup

January 4, 2010

Over the last week most of the media across the world covered the cracking of A5/1, the algorithm responsible for the privacy of GSM voice calls. The announcement happened at the Chaos Communication Congress in Berlin on the 27th of December.
Have collected the best coverage, links below:
New York Times “Cellphone Encryption Code Is Divulged”
Financial Times [...]

Read the full article →

GSM Cracking, few inaccuracies and omissions

December 29, 2009

The New York Times broke the story of the A5/1 cracking (A5/1 being the encryption algorithm that protects the privacy of your GSM calls) last night, prompting a media frenzy.
The story goes like this: since 1994 researchers have warned that A5/1, developed in the late ’80s, was inadequate and could be cracked easily. The GSM [...]

Read the full article →

Intercepting drones and GSM calls in Iraq and Afghanistan

December 22, 2009

Everything you transmit will be used against you
Last week news broke out that late last year a laptop seized from an Iraqi insurgent contained video intercepted from US drones. Then in July, the Wall Street Journal reported that more laptops with feeds were discovered confirming that militants were tapping into the live video feed from [...]

Read the full article →