This is the headline to Boy Genius Report’s (BGR’s) article regarding a group of 5 hackers that claim to have cracked a 64 bit GSM encryption scheme. While their headline implied doom and gloom for security engineers around the world, the content of the article is more reasoned and accurate. According to BGR, “it is important to point out that the GSM algorithm that was cracked was the older and less secure 64-bit A5/1 algorithm, not the newer 128-bit A5/3 algorithm.” Other news sources also report that the cracked codes still require thousands of dollars of computer and radio equipment to access the wireless conversations they want to compromise. What is left out of the article is actually more important than what is said. Let’s cover what BGR did not.
The 64-bit A5/1 algorithm is only used to scramble voice conversations on older GSM equipment. This means that:
Good News
1) Your data transmissions are not impacted by this development.
2) Calls made with a 3G capable phone over a 3G connection are not impacted.
3) According to some sources, T-Mobile has converted its entire network to the newer encryption algorithm.
4) The same sources claim that AT&T has converted part, but not all, of its network to the newer encryption algorithm.
5) There are 3 pillars to information security. The pillar that this development impacts is Access, or the ability to listen to a voice conversation. It doesn’t impact Integrity or Identification. This means that no one can make phone calls or data transmissions posing as you. This also means that no one can alter your voice or data transmission.
Bad News
1) Because newer network equipment is designed to work with older handsets, even the latest in network equipment will accept the older algorithm. This means that any GSM user with an older handset (manufactured before 2007) may still be susceptible to eavesdropping even if the carrier (T-Mobile, AT&T, etc.) has upgraded the encryption algorithm in that area of their network.
In a nutshell, only very sophisticated and well funded criminal organizations will have the means to eavesdrop on your calls. Even if they try, they need to be very close to you to intercept your radio signal. They may need to be within feet of you in some buildings to within miles in some rural areas. They also need to catch you while your call is being handled by an older AT&T cellular site or they need to catch you while you are using an older model phone. Lastly, your conversation needs to be of such value that a very sophisticated and well funded criminal organization would want to go through all of the trouble we have outlined in order to listen in. If you regularly partake in these kinds of conversations, I would suggest you look into buying a TalkSecure Wireless phone from General Dynamics (http://www.gdc4s.com/content/detail.cfm?item=90bdc199-8775-4439-9b83-c021dc7e9e76) it runs your conversation through another 128-bit encryption algorithm on top of the one used by the carrier.
If you don’t partake in these kinds of conversations, I really wouldn’t worry about it.
Showing posts with label T-Mobile. Show all posts
Showing posts with label T-Mobile. Show all posts
Monday, January 11, 2010
Wednesday, January 06, 2010
T-Mobile 3G users get an upgrade for 2010
According to PhoneScoop:
"Today (January 5, 2010) T-Mobile announced that it has upgraded its entire 3G network to HSPA 7.2Mbps (peak speeds). That's an improvement from 3.6Mbps, and should allow for faster wireless downloads. T-Mobile also pointed out that its 3G footprint now covers some 200 million Americans. T-Mobile also said that it plans to be the first U.S. carrier to deploy HSPA+ across its network by mid 2010. T-Mobile currently has an HSPA+ trial under way in Philadelphia. Once fully enabled, HSPA+ will offer up to 21Mbps downloads."
This is great news for many of T-Mobile’s 3G subscribers, but not all of them. While the network supports the higher speeds, some T-Mobile 3G handsets do not. Here is the list of T-Mobile’s 3G handsets and their supported network throughput.
HSPA 7.2 (High Speed Packet Access)
T-Mobile Dash 3G
T-Mobile G1
T-Mobile myTouch 3G
HTC Touch Pro2
Motorola CLIQ
Sidekick LX 2009
T-Mobile webConnect
T-Mobile webConnect Jet
These devices can download data at speeds up to 7.2Mbps and upload at up to 1.8Mbps. In all honesty, these speeds are theoretical. Real world performance will be slightly slower. Other HSPA 7.2 networks are seeing roughly 3Mbps download speeds and 1Mbps upload speeds in real world usage. At 3Mbps, it would take 8 seconds to download a 3 MB file, or the equivalent of a 3 minute MP3 track.
HSDPA 3.6 (High Speed Download Packet Access)T-Mobile Tap
BlackBerry Bold 9700
Samsung Behold II
Samsung Comeback
Samsung Gravity 2
Samsung Highlight
Samsung Memoir
Samsung t659
Sony Ericsson Eqiunox
These phones can download data at speeds up to 3.6Mbps and upload at up to 384Kbps. As with HSPA, these speeds are theoretical. Real world performance will be in the neighborhood of 1Mbps download and 100Kbps upload. At 1Mbps, it would take 24 seconds to download a 3 MB file, or the equivalent of a 3 minute MP3 track.
UMTS (Universal Mobile Telecommunications System)Samsung t639
Samsung t819
Samsung Behold
Nokia 3711
The theoretical speeds for early 3G devices using UMTS are 384Kbps for the uplink and downlink. Most UMTS users are seeing speeds in the area of 100Kbps. At 100Kbps, it would take 4 minutes to download a 3 MB file, or the equivalent of a 3 minute MP3 track.
NOTE: Operating systems, processor speeds, and even display components can impact the apparent speed of any wireless device. Don’t think that your BlackBerry Bold 9700 is outdated or slow because other devices move data through the air faster than yours. Use these numbers to compare Beholds to Behold IIs or T-Mobile’s HTC Touch Pro2 (at 7.2Mbps maximum) to Verizon’s Touch Pro2 (at 3.1Mbps maximum). As Albert Einstein (or the punk band Cigar) would point out, speed is relative.
Happy new year T-Mobile 3G subscribers!
"Today (January 5, 2010) T-Mobile announced that it has upgraded its entire 3G network to HSPA 7.2Mbps (peak speeds). That's an improvement from 3.6Mbps, and should allow for faster wireless downloads. T-Mobile also pointed out that its 3G footprint now covers some 200 million Americans. T-Mobile also said that it plans to be the first U.S. carrier to deploy HSPA+ across its network by mid 2010. T-Mobile currently has an HSPA+ trial under way in Philadelphia. Once fully enabled, HSPA+ will offer up to 21Mbps downloads."
This is great news for many of T-Mobile’s 3G subscribers, but not all of them. While the network supports the higher speeds, some T-Mobile 3G handsets do not. Here is the list of T-Mobile’s 3G handsets and their supported network throughput.
HSPA 7.2 (High Speed Packet Access)
T-Mobile Dash 3G
T-Mobile G1
T-Mobile myTouch 3G
HTC Touch Pro2
Motorola CLIQ
Sidekick LX 2009
T-Mobile webConnect
T-Mobile webConnect Jet
These devices can download data at speeds up to 7.2Mbps and upload at up to 1.8Mbps. In all honesty, these speeds are theoretical. Real world performance will be slightly slower. Other HSPA 7.2 networks are seeing roughly 3Mbps download speeds and 1Mbps upload speeds in real world usage. At 3Mbps, it would take 8 seconds to download a 3 MB file, or the equivalent of a 3 minute MP3 track.
HSDPA 3.6 (High Speed Download Packet Access)T-Mobile Tap
BlackBerry Bold 9700
Samsung Behold II
Samsung Comeback
Samsung Gravity 2
Samsung Highlight
Samsung Memoir
Samsung t659
Sony Ericsson Eqiunox
These phones can download data at speeds up to 3.6Mbps and upload at up to 384Kbps. As with HSPA, these speeds are theoretical. Real world performance will be in the neighborhood of 1Mbps download and 100Kbps upload. At 1Mbps, it would take 24 seconds to download a 3 MB file, or the equivalent of a 3 minute MP3 track.
UMTS (Universal Mobile Telecommunications System)Samsung t639
Samsung t819
Samsung Behold
Nokia 3711
The theoretical speeds for early 3G devices using UMTS are 384Kbps for the uplink and downlink. Most UMTS users are seeing speeds in the area of 100Kbps. At 100Kbps, it would take 4 minutes to download a 3 MB file, or the equivalent of a 3 minute MP3 track.
NOTE: Operating systems, processor speeds, and even display components can impact the apparent speed of any wireless device. Don’t think that your BlackBerry Bold 9700 is outdated or slow because other devices move data through the air faster than yours. Use these numbers to compare Beholds to Behold IIs or T-Mobile’s HTC Touch Pro2 (at 7.2Mbps maximum) to Verizon’s Touch Pro2 (at 3.1Mbps maximum). As Albert Einstein (or the punk band Cigar) would point out, speed is relative.
Happy new year T-Mobile 3G subscribers!
Wednesday, June 06, 2007
Why Computer geeks need Wireless Wonks!
Lance Ulanof, an Editor at PC Magazine, was on Fox News recently talking about cool cell phone alternatives to the iPhone. Now, a lot of people question Fox's ability to present factual reporting. I cover those issues in a different blog. As for technology, Fox and Lance continue the questionable facts tradition. Click on the link and watch the video. You will see Lance hold up a T-Mobile Dash and present it as a Motorola Q. He corrects this slip a bit later, but goes on to say that the T-Mobile Dash is available from AT&T Wireless/Cingular and that it uses the Palm Operating System. OMG! He messed up 1) the manufacturer, 2) the name, 3) the carrier, and 4) the operating system.
With this kind of awareness in the PC world, no wonder Apple (a computer company) thinks they can corner cell phones.
Fox News Scorecard:
1) The manufacturer of the T-Mobile Dash is not Motorola, it is HTC for T-Mobile.
2) The name of the T-Mobile Dash is not Q, it is Dash.
3) The carrier for the T-Mobile Dash is not AT&T Wireless/Cingular, it is . . . wait for it . . . check out the name for a hint . . . T-Mobile.
4) The OS is for the T-Mobile Dash is not the Palm OS, it is Windows Mobile 5.0 Smartphone Edition
With this kind of awareness in the PC world, no wonder Apple (a computer company) thinks they can corner cell phones.
Fox News Scorecard:
1) The manufacturer of the T-Mobile Dash is not Motorola, it is HTC for T-Mobile.
2) The name of the T-Mobile Dash is not Q, it is Dash.
3) The carrier for the T-Mobile Dash is not AT&T Wireless/Cingular, it is . . . wait for it . . . check out the name for a hint . . . T-Mobile.
4) The OS is for the T-Mobile Dash is not the Palm OS, it is Windows Mobile 5.0 Smartphone Edition
Tags:
Dash,
Fox News,
iPhone,
Lance Ulanof,
Motorola,
PC Magazine,
Q,
T-Mobile
Monday, February 21, 2005
Paris Hilton / T-Mobile Sidekick Hacked
Well, the forums are abuzz with voyeurs and conspiracy theorists trying to figure out the latest T-Mobile Sidekick hack.
It's a hoax or a twisted PR move. I looked at the pictures. Ya, all of them. I don't think these are all Sidekick pictures. In fact, I not sure any are. Here's why.
1) EVERY picture is of Paris. Where are the pictures of friends at an event, or at a bar? Also, her makeup and hair are perfect in every picture. Where are the no makeup, hair down, pictures? She would have to be as self centered as the "media" says she is for me to believe these.
2) The topless pictures seem to have a fog around the edges. I know there is a special lens that does this, but I've never seen it on a Sidekick.
It's real.
1) I've read too many forum entries of people gutsy, err inconsiderate, enough to call some of the phone numbers. Filled mail boxes, real people hanging up on the caller, and disconnected numbers all point at these being real numbers. Even if these aren't the numbers to the stars, it is unlikely a planned PR stunt would include the phone numbers and e-mails of real people.
2) If T-Mobile was complicit in this "stunt", it would be like staging a train wreck in hopes of getting your railroad some additional press. Unfortunately, celebrities who wish to stay in the spotlight DO stage train wrecks in search of publicity. Maybe this point should go under "undecided".
Undecided. That's where I'm at today. Some things look mighty fishy, but this is just too ugly to be a stunt or a hoax.
Now for the Wireless take on this.
This is not the first news of T-Mobile's Sidekick users getting hacked. I blogged this same issue a month ago. I also posted some precautions to take.
My recommendation: If you are a T-Mobile customer, be assured that all indications are that your personal information is safe. That being said, I would recommend that all T-Mobile subscribers who use My T-Mobile or the SideKick services change their account passwords, more for piece of mind than necessity. Besides, it is always a good practice to change passwords periodically anyway.
I would also add that as long as you are not a publicity starved model, or absent minded Secret Service agent, you shouldn't need to worry too much. But again, it's better to side on the safe side, and change your passwords more than once in a lifetime, don't use your dog's name for your password, and if security is at all a concern, get a BlackBerry. Some of the media outlets have referred to Paris' phone as a BlackBerry. This is wrong. It was a Sidekick.
I though T-Mobile dodged a bullet with the deafening silence around the last hacking story. I think people will pay a little more attention to this shot.
It's a hoax or a twisted PR move. I looked at the pictures. Ya, all of them. I don't think these are all Sidekick pictures. In fact, I not sure any are. Here's why.
1) EVERY picture is of Paris. Where are the pictures of friends at an event, or at a bar? Also, her makeup and hair are perfect in every picture. Where are the no makeup, hair down, pictures? She would have to be as self centered as the "media" says she is for me to believe these.
2) The topless pictures seem to have a fog around the edges. I know there is a special lens that does this, but I've never seen it on a Sidekick.
It's real.
1) I've read too many forum entries of people gutsy, err inconsiderate, enough to call some of the phone numbers. Filled mail boxes, real people hanging up on the caller, and disconnected numbers all point at these being real numbers. Even if these aren't the numbers to the stars, it is unlikely a planned PR stunt would include the phone numbers and e-mails of real people.
2) If T-Mobile was complicit in this "stunt", it would be like staging a train wreck in hopes of getting your railroad some additional press. Unfortunately, celebrities who wish to stay in the spotlight DO stage train wrecks in search of publicity. Maybe this point should go under "undecided".
Undecided. That's where I'm at today. Some things look mighty fishy, but this is just too ugly to be a stunt or a hoax.
Now for the Wireless take on this.
This is not the first news of T-Mobile's Sidekick users getting hacked. I blogged this same issue a month ago. I also posted some precautions to take.
My recommendation: If you are a T-Mobile customer, be assured that all indications are that your personal information is safe. That being said, I would recommend that all T-Mobile subscribers who use My T-Mobile or the SideKick services change their account passwords, more for piece of mind than necessity. Besides, it is always a good practice to change passwords periodically anyway.
I would also add that as long as you are not a publicity starved model, or absent minded Secret Service agent, you shouldn't need to worry too much. But again, it's better to side on the safe side, and change your passwords more than once in a lifetime, don't use your dog's name for your password, and if security is at all a concern, get a BlackBerry. Some of the media outlets have referred to Paris' phone as a BlackBerry. This is wrong. It was a Sidekick.
I though T-Mobile dodged a bullet with the deafening silence around the last hacking story. I think people will pay a little more attention to this shot.
Tuesday, January 25, 2005
"Bleeding Edge" isn't painless
This blog is for the whiners on the HP iPAQ forum linked above.
Let me preface this posting with the fact that I don't work for HP or for T-Mobile. I have been a T-Mobile customer for 7+ years, and I have personally owned several HP Palmtops and Pocket PCs since my first 95lx. This means that I have had several opportunities to see both companies at their best and worst. I am also a happy HP iPAQ 6315 user.
The 6315 is neither! Sure it has glitches. Sure it rides more like a truck than a sedan. It needs some work to make it ready for the masses. If you didn't expect this when you purchased the first product to integrate WiFi, Bluetooth and GPRS, consider this a lesson learned. If you didn't expect a few bumps in the road for HP's first Pocket PC Phone Edition, wake up and smell the coffee. If you expected either company to market this product as anything less than a terrific marriage of technology and a terrific personal productivity tool, you're fools.
I have 3 points I want to make to all of the whiners in this string.
1) If this is the first time you have purchased a "technological first" product. I'm sorry to say you have just learned a lesson that will be repeated as often as you continue to purchase first generation products.
2) If this is not your first time riding the bleeding edge, get out the band-aids and get over it. You have choices you seem to dismiss too easily. If the company over-promises on features and stability, and you discover this with the product, RETURN IT while you can. Why should you believe the company's claims that they will fix it for you, when they couldn't deliver on their claims that it worked right the first time. If you think that you know more than the company (as many of you seem to) and you think that you can fix these problems when they can't, then do it.
3) I don't think the term "bleeding edge" technology comes from a lab incident, or a company's slow hemorrhage of funds on an unproven product. I think "bleeding edge" is defined in this string. You all have your nicks and cuts. I do too. I've seen many of the issues you have articulated. I've also worked through most of them. My iPAQ ain't perfect, mind you, but it is better in it's current state than any other product on the market. The reason I'm not bemoaning the unfortunate demise of marketing or customer service ethics is because I EXPECTED IT. I knew this would happen. I knew my product wouldn't be perfect. I knew that the corporate marketing machine would paint a pretty picture, kiss our little ouchie, and tuck us in for a little nap. It happens every time a first to market product is launched. It's called product development. I have shelves and shelves of first release products. I've not only been through this battle before, I seek it out and jump in knowing full well that I will not get to sleep some nights because my router and my PDA are incompatible and no one told me. Or that I will have wasted time with an accessory (or many in my case) that isn't compatible with my specific model, although it wasn't printed on the box. You know what I did with those accessories? I returned them!
If you want your technical world to be comfy and cozy, there are many, many great HP iPAQs that will fill your needs. T-Mobile has phones that are in their umpteenth generation, and they will work wonders for you. If you want to live life on the technological edge, put on your body armor, put on a large pot of coffee (or a 12 pack of cold caffeine in my case) and be ready to do battle with your product, your patience and the company’s customer care team.
By the way. I don't want to discredit the legitimate product claims that many of you have. They need to be aired out here. What I do despise is the arrogance of those who think that companies aren't aware of the spoils of first product releases. Or those with the audacity to think that there is some level of malicious intent to releasing a less that stellar product. Worst of all, is those of you who have been here before, and have not yet learned the lessons. The fact of the matter is, the best place to test new technology is in YOUR hands, not the limited hands they employ. No matter how it is spun, version 1 of any product is always a wide release beta, and most of you should know that by now. If you don't want to test, don't buy rev. 1, or at least return it within the allotted time. 30 days is plenty to calculate how many sleepless nights it will take to make the product tolerable
HP and T-Mobile do read these strings. Do you want to know how I know? See what version 2 of the product brings, then tell me they didn't pay attention.
Let me preface this posting with the fact that I don't work for HP or for T-Mobile. I have been a T-Mobile customer for 7+ years, and I have personally owned several HP Palmtops and Pocket PCs since my first 95lx. This means that I have had several opportunities to see both companies at their best and worst. I am also a happy HP iPAQ 6315 user.
The 6315 is neither! Sure it has glitches. Sure it rides more like a truck than a sedan. It needs some work to make it ready for the masses. If you didn't expect this when you purchased the first product to integrate WiFi, Bluetooth and GPRS, consider this a lesson learned. If you didn't expect a few bumps in the road for HP's first Pocket PC Phone Edition, wake up and smell the coffee. If you expected either company to market this product as anything less than a terrific marriage of technology and a terrific personal productivity tool, you're fools.
I have 3 points I want to make to all of the whiners in this string.
1) If this is the first time you have purchased a "technological first" product. I'm sorry to say you have just learned a lesson that will be repeated as often as you continue to purchase first generation products.
2) If this is not your first time riding the bleeding edge, get out the band-aids and get over it. You have choices you seem to dismiss too easily. If the company over-promises on features and stability, and you discover this with the product, RETURN IT while you can. Why should you believe the company's claims that they will fix it for you, when they couldn't deliver on their claims that it worked right the first time. If you think that you know more than the company (as many of you seem to) and you think that you can fix these problems when they can't, then do it.
3) I don't think the term "bleeding edge" technology comes from a lab incident, or a company's slow hemorrhage of funds on an unproven product. I think "bleeding edge" is defined in this string. You all have your nicks and cuts. I do too. I've seen many of the issues you have articulated. I've also worked through most of them. My iPAQ ain't perfect, mind you, but it is better in it's current state than any other product on the market. The reason I'm not bemoaning the unfortunate demise of marketing or customer service ethics is because I EXPECTED IT. I knew this would happen. I knew my product wouldn't be perfect. I knew that the corporate marketing machine would paint a pretty picture, kiss our little ouchie, and tuck us in for a little nap. It happens every time a first to market product is launched. It's called product development. I have shelves and shelves of first release products. I've not only been through this battle before, I seek it out and jump in knowing full well that I will not get to sleep some nights because my router and my PDA are incompatible and no one told me. Or that I will have wasted time with an accessory (or many in my case) that isn't compatible with my specific model, although it wasn't printed on the box. You know what I did with those accessories? I returned them!
If you want your technical world to be comfy and cozy, there are many, many great HP iPAQs that will fill your needs. T-Mobile has phones that are in their umpteenth generation, and they will work wonders for you. If you want to live life on the technological edge, put on your body armor, put on a large pot of coffee (or a 12 pack of cold caffeine in my case) and be ready to do battle with your product, your patience and the company’s customer care team.
By the way. I don't want to discredit the legitimate product claims that many of you have. They need to be aired out here. What I do despise is the arrogance of those who think that companies aren't aware of the spoils of first product releases. Or those with the audacity to think that there is some level of malicious intent to releasing a less that stellar product. Worst of all, is those of you who have been here before, and have not yet learned the lessons. The fact of the matter is, the best place to test new technology is in YOUR hands, not the limited hands they employ. No matter how it is spun, version 1 of any product is always a wide release beta, and most of you should know that by now. If you don't want to test, don't buy rev. 1, or at least return it within the allotted time. 30 days is plenty to calculate how many sleepless nights it will take to make the product tolerable
HP and T-Mobile do read these strings. Do you want to know how I know? See what version 2 of the product brings, then tell me they didn't pay attention.
Wednesday, January 12, 2005
T-Mobile Hacked
SecurityFocus.com just broke a story of a pretty significant breach of T-Mobiles computer systems. Life in the wireless world just got a lot tougher. For users, their comfort and confidence just took a big hit. For those of us who sell wireless, security just moved from the benefit column to the challenges column. The main reason for this level of impact is not because of this incident alone, but due to the implications that it could happen again. It's hard to worry about something that has never happened. It's easier to worry when you can point at even one situation where it did happen.
Even though T-Mobile has not responded to the story yet, I do want to share some of my observations to help put this in a proper perspective. The sky is NOT falling in wireless security. Some plaster has been shaken loose though.
The Bad News: The hacker got names, Social Security Numbers, and birth dates for many customers. The hacker also got pretty deep into the SideKick server. This server relays messages for SideKick users. It also can store on-line copies of the users contact list and calendar if the customer chooses to do so. Here, the hacker got SideKick account passwords, SIM numbers and IMEI's. These are basically serial numbers for the SideKick and the "Subscriber Identity Module" that is in the SideKick. The biggest news is that one of the SideKick users that the hacker monitored was the Secret Service agent tracking the hacker. The hacker also copied some of this agents SideKick e-mails off of the SideKick server. Some press reports make it sound like the hacker pulled them directly off of the SideKick. This is HIGHLY unlikely, and unnecessary since all SideKick e-mails pass through the server that was hacked.
Good News: According to T-Mobile, everyone who's accounts were compromised has already been notified of the breach. If you haven't been notified, you are probably safe. Although the breach of the SideKick server is serious, there is no indication of a breach of the BlackBerry Web Client (BWC). The BWC is a similar server for BlackBerry users and is hosted by RIM. Knowing quite a bit about the security involved with the BWC, it is safe to say that this breach had little, if any, impact on the BlackBerry services. Here is a great reason to choose BlackBerry and a BlackBerry Enterprise Server (BES) over any Web Hosted solution. The BES is a server that the customer hosts themselves, behind their own firewall, and that they have total control over.
My recommendation: If you are a T-Mobile customer, be assured that all indications are that your personal information is safe. That being said, I would recommend that all T-Mobile subscribers who use My T-Mobile or the SideKick services change their account passwords, more for piece of mind than necessity. Besides, it is always a good practice to change passwords periodically anyway.
This is not a pretty situation, but understand that this kind of breech is not unique to your wireless carrier. I know, that is not very reassuring, but the truth is that these same kinds of breeches have occurred with banks, airlines, medical insurance companies, and many other businesses. For those of you directly affected by these events, I understand the tragic impact this can have. For everyone else, understand that this is one of the risks of the information age. For anyone interested in law enforcement, may I recommend cyber-security as a career. This truly is the "wild west" of modern crime and lawlessness.
I'll probably comment more when I see what T-Mobile and others have to say over the next couple days.
Even though T-Mobile has not responded to the story yet, I do want to share some of my observations to help put this in a proper perspective. The sky is NOT falling in wireless security. Some plaster has been shaken loose though.
The Bad News: The hacker got names, Social Security Numbers, and birth dates for many customers. The hacker also got pretty deep into the SideKick server. This server relays messages for SideKick users. It also can store on-line copies of the users contact list and calendar if the customer chooses to do so. Here, the hacker got SideKick account passwords, SIM numbers and IMEI's. These are basically serial numbers for the SideKick and the "Subscriber Identity Module" that is in the SideKick. The biggest news is that one of the SideKick users that the hacker monitored was the Secret Service agent tracking the hacker. The hacker also copied some of this agents SideKick e-mails off of the SideKick server. Some press reports make it sound like the hacker pulled them directly off of the SideKick. This is HIGHLY unlikely, and unnecessary since all SideKick e-mails pass through the server that was hacked.
Good News: According to T-Mobile, everyone who's accounts were compromised has already been notified of the breach. If you haven't been notified, you are probably safe. Although the breach of the SideKick server is serious, there is no indication of a breach of the BlackBerry Web Client (BWC). The BWC is a similar server for BlackBerry users and is hosted by RIM. Knowing quite a bit about the security involved with the BWC, it is safe to say that this breach had little, if any, impact on the BlackBerry services. Here is a great reason to choose BlackBerry and a BlackBerry Enterprise Server (BES) over any Web Hosted solution. The BES is a server that the customer hosts themselves, behind their own firewall, and that they have total control over.
My recommendation: If you are a T-Mobile customer, be assured that all indications are that your personal information is safe. That being said, I would recommend that all T-Mobile subscribers who use My T-Mobile or the SideKick services change their account passwords, more for piece of mind than necessity. Besides, it is always a good practice to change passwords periodically anyway.
This is not a pretty situation, but understand that this kind of breech is not unique to your wireless carrier. I know, that is not very reassuring, but the truth is that these same kinds of breeches have occurred with banks, airlines, medical insurance companies, and many other businesses. For those of you directly affected by these events, I understand the tragic impact this can have. For everyone else, understand that this is one of the risks of the information age. For anyone interested in law enforcement, may I recommend cyber-security as a career. This truly is the "wild west" of modern crime and lawlessness.
I'll probably comment more when I see what T-Mobile and others have to say over the next couple days.
Subscribe to:
Posts (Atom)