BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 02-01-2008, 12:31 PM   #1
kantzow
New Member
 
Join Date: Feb 2008
Model: 8320
PIN: N/A
Carrier: C&W
Posts: 4
Default BIS Email Encryption?

Please Login to Remove!

Hi All,

Well after reading through a few posts here about email security I still need some clarification on the matter.

I understand that mail between RIM and the BlackBerry is encrypted, however what if the Carrier wanted to tap the email between your [email address] can they do this since the email needs to pass through their RIM gateway on their network? I have no BES available.

The other thing is the surfing traffic through BDS, is this also encrypted or can it be "listened" to as well?

Thanks, Fred

Last edited by kantzow; 02-01-2008 at 12:38 PM..
Offline  
Old 02-02-2008, 12:21 AM   #2
Worm
Thumbs Must Hurt
 
Join Date: Feb 2007
Model: All
Carrier: Plead the fifth.
Posts: 63
Default

Odd first post m8 ???

Anything can be listened to, you just have to decrypt it.

If someone wants to know what's contained within they'll just ask the network though, in this case RIM.

cheers

Worm
Offline  
Old 02-02-2008, 02:35 AM   #3
tsac
BlackBerry God
 
tsac's Avatar
 
Join Date: Mar 2005
Location: Others run out when we run in
Model: Z10
OS: Cheerios
PIN: No Pin just a Tack
Carrier: at&t
Posts: 10,030
Default

The only time a carrier will bother to "listen" is if the need is there. Anything sent via radio or Internet can be monitored....anything
__________________
Z10 on BES
Z10 on BIS
Offline  
Old 02-02-2008, 02:57 AM   #4
Dubdub
Appleinator
 
Dubdub's Avatar
 
Join Date: Nov 2005
Location: New Hampshire
Model: App6+
OS: AJBR549
PIN: Ask
Carrier: ATT & Verizon
Posts: 20,038
Default

Feeling paranoid?
Offline  
Old 02-02-2008, 04:55 AM   #5
kantzow
New Member
 
Join Date: Feb 2008
Model: 8320
PIN: N/A
Carrier: C&W
Posts: 4
Post

Paranoid? Yes very, if you were in my shoes you would be too.

I'm located in Barbados where C&W have had monopoly on telecommunications for as long as they have been available. They have used this advantage and vacuumed the market with ridiculousy overpriced services. During 1995-2005 80% of the total income world wide for C&W was accumulated in the Caribbean alone.

Anyhow nuff history, the market today is different. It is supposedly more open and "anybody" could today register a telephone company. Sure it costs around US$ 250000 a year in license fees and another US$50000 in bribes but besides the point. I'm in the telecoms business and the mere fact that "funny" things have happened after a few conversations over the cell with my collegues (ports closed, IMEI's blacklisted of GSM gateways, "random packet dropping" on Internet links etc list is long) is just proof that our phones are being monitored by C&W staff to make the already hard market mere impossible for new actors. Thank god there is another cell operator (Digicel) where any phone tapping would have no use (unless you doing something illegal off course).

Any how to make a long story short, if I'm now going to have my email (Relayed from outside C&W network through VPN and SSL to local internal mail server) going through their network and therefor enabling them to read everything you could kind of see my problem here :D

Anybody got some security advise here, Digicel don't offer BlackBerry services as of yet. Maybe it's time to think back on the times of East and West Germany when people were smuggled under the back seat of a car and Gestapo inspected every inch of vehicle. ^^

Last edited by kantzow; 02-02-2008 at 05:03 AM..
Offline  
Old 02-02-2008, 01:41 PM   #6
Dubdub
Appleinator
 
Dubdub's Avatar
 
Join Date: Nov 2005
Location: New Hampshire
Model: App6+
OS: AJBR549
PIN: Ask
Carrier: ATT & Verizon
Posts: 20,038
Default

That explains the reason for the question.
Offline  
Old 02-02-2008, 07:49 PM   #7
Berry One
BlackBerry Extraordinaire
 
Join Date: Oct 2005
Model: 8220
Carrier: WiFi hotspot
Posts: 1,009
Default

Here is how your BIS email goes from blackberry, with capital E means encrypted:

device -E-> carrier -E-> RIM (Canada) -> Internet

Here is how it comes to your device from Internet:

Internet -> RIM (Canada) -E-> carrier -E-> device

As you can see, carrier can not wiretap your emails. Even if they want to.


Here is for BES emails, from the Internet to device:

Internet -> Exchange/BES (in your office) -E-> RIM -E-> carrier -E-> device

From device to Internet:

device -E-> carrier -E-> RIM -E-> Exchange/BES (in your office) -> Internet
Offline  
Old 02-02-2008, 08:21 PM   #8
kantzow
New Member
 
Join Date: Feb 2008
Model: 8320
PIN: N/A
Carrier: C&W
Posts: 4
Default

Ok, thanks for the reply!
Offline  
Old 02-02-2008, 08:25 PM   #9
tsac
BlackBerry God
 
tsac's Avatar
 
Join Date: Mar 2005
Location: Others run out when we run in
Model: Z10
OS: Cheerios
PIN: No Pin just a Tack
Carrier: at&t
Posts: 10,030
Default

Quote:
Originally Posted by Berry One View Post
Here is how your BIS email goes from blackberry, with capital E means encrypted:

device -E-> carrier -E-> RIM (Canada) -> Internet

Here is how it comes to your device from Internet:

Internet -> RIM (Canada) -E-> carrier -E-> device

As you can see, carrier can not wiretap your emails. Even if they want to.


Here is for BES emails, from the Internet to device:

Internet -> Exchange/BES (in your office) -E-> RIM -E-> carrier -E-> device

From device to Internet:

device -E-> carrier -E-> RIM -E-> Exchange/BES (in your office) -> Internet
Not to add to this paranoia but even in your example the traffic goes via a carrier. I would say he has another issue. One that if he has had his cell blacklisted in a few cell sites he must have riled the wrong person who has access to the cell controller and user database. Remember when you call any company for service , if you piss off the guy at the controls it is simple for him to make a few “ mistakes” and delete something. Believe me when I say this is not too uncommon. Big carriers keep records of all system access but a person with the right knowledge can do amazing things. Just look at the hacking going on around the world. And if the guy called has a brother or friend in the outside plant, guess what, it’s even easier.

If this doesn’t get him diving for the cave nothing will.
__________________
Z10 on BES
Z10 on BIS
Offline  
Old 02-02-2008, 09:41 PM   #10
livinginx
Knows Where the Search Button Is
 
Join Date: Oct 2004
Location: PoDunk, MN
Model: 7100i
Carrier: Nextel
Posts: 47
Default

Quote:
Originally Posted by tsac View Post
Not to add to this paranoia but even in your example the traffic goes via a carrier. I would say he has another issue. One that if he has had his cell blacklisted in a few cell sites he must have riled the wrong person who has access to the cell controller and user database. Remember when you call any company for service , if you piss off the guy at the controls it is simple for him to make a few “ mistakes” and delete something. Believe me when I say this is not too uncommon. Big carriers keep records of all system access but a person with the right knowledge can do amazing things. Just look at the hacking going on around the world. And if the guy called has a brother or friend in the outside plant, guess what, it’s even easier.

If this doesn’t get him diving for the cave nothing will.
The nice thing with most carriers though is that anytime somebody makes a change to your account, those changes are signed. It would take a lot on any carrier that I have worked for to get screwed and not be able to revert to a previous state.
Offline  
Old 02-03-2008, 12:07 AM   #11
kantzow
New Member
 
Join Date: Feb 2008
Model: 8320
PIN: N/A
Carrier: C&W
Posts: 4
Default

This is understandable in a world where insight and control mechanisms exists, however this does not apply to most developing countries where the governments simply choose "not to interfere", obviously because of brides (cars, money, travel, free this free that).

C&W does have a lot of control mechanisms within their corporation, every login to the DSLAMs, Cell stations etc is logged and there is a trail. Now imagine this, if you tell anybody of what is going on even if it's illegal within their corporation (former employees as sources) you will be fired, and once fired from a corporation like C&W in the Caribbean you will have a hard time to find work elsewhere due to the very high ranking connections of the "top" in the company.

LOL this is really starting to sound like a conspiracy theory, except this is pretty much the reality in the Caribbean.

I doubt this is a problem in modern industrial countries, like western europe and the US since people can actually act against companies with success. Even though the company have "misplaced" or deleted the logs over access and traces of the corruption once a court order has been issued (if ever).

Last edited by kantzow; 02-03-2008 at 12:09 AM..
Offline  
Old 02-03-2008, 02:31 PM   #12
Berry One
BlackBerry Extraordinaire
 
Join Date: Oct 2005
Model: 8220
Carrier: WiFi hotspot
Posts: 1,009
Default

Well, if they don't like you they can just terminate your blackberry service.

The concern was wiretapping of BlackBerry email conversations somewhere on carrier wireless network, the response is: unlikely.
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Fanuc S-RAM Memory Module A20B-3900-0284/01A *New No Box* picture

Fanuc S-RAM Memory Module A20B-3900-0284/01A *New No Box*

$154.95



Fanuc S-RAM Memory Module A20B-3900-0061/02B picture

Fanuc S-RAM Memory Module A20B-3900-0061/02B

$99.95



JLG 1684465 Lockout Ram Cylinder 1001168875 picture

JLG 1684465 Lockout Ram Cylinder 1001168875

$429.49



Single-acting Hollow Ram Cylinder (20tons - 4

Single-acting Hollow Ram Cylinder (20tons - 4") (YG-20100K)

$169.00



2021 Dodge Ram 1500 TRX Ignition Push Start Button OEM 68453905AA picture

2021 Dodge Ram 1500 TRX Ignition Push Start Button OEM 68453905AA

$125.00



Make Offer Oem Caterpillar 2613222 Mount Ram picture

Make Offer Oem Caterpillar 2613222 Mount Ram

$75.00







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.