<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: RIM Security VP Worried About Smartphone DDOS Attacks &#8211; Why?</title>
	<atom:link href="http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/</link>
	<description>BlackBerry News and Reviews You Can Use</description>
	<lastBuildDate>Sun, 12 Feb 2012 14:59:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: SusanC</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-37198</link>
		<dc:creator>SusanC</dc:creator>
		<pubDate>Sun, 22 Nov 2009 06:56:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-37198</guid>
		<description>Ronen,

I use SMobile Security Shield on my BlackBerry. While I&#039;ve never had a virus, and I wouldn&#039;t download something unless it&#039;s from a trusted source, social engineering is a consideration. You never know...we need to be aware and realistic. After all, look at how many worms and all have been created for the iPhone in just a few months, and how many vulnerabilities they&#039;ve found with the Droid. One can never be too safe.</description>
		<content:encoded><![CDATA[<p>Ronen,</p>
<p>I use SMobile Security Shield on my BlackBerry. While I&#8217;ve never had a virus, and I wouldn&#8217;t download something unless it&#8217;s from a trusted source, social engineering is a consideration. You never know&#8230;we need to be aware and realistic. After all, look at how many worms and all have been created for the iPhone in just a few months, and how many vulnerabilities they&#8217;ve found with the Droid. One can never be too safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Derek Brown</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-37027</link>
		<dc:creator>Derek Brown</dc:creator>
		<pubDate>Fri, 20 Nov 2009 12:33:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-37027</guid>
		<description>Regarding number 2, I complained about this in another article when I won a free copy of Shape Service&#039;s IM plus.  The software will install, but fail to run unless you grant ALLOW for everything.  I actually never even got it working, as that just screams unnecessary to me.  Not that I have anything to hide, but I see no reason an IM app would need access to certain things...like input simulation.  Anyway, I gave my free copy away for that very reason.</description>
		<content:encoded><![CDATA[<p>Regarding number 2, I complained about this in another article when I won a free copy of Shape Service&#8217;s IM plus.  The software will install, but fail to run unless you grant ALLOW for everything.  I actually never even got it working, as that just screams unnecessary to me.  Not that I have anything to hide, but I see no reason an IM app would need access to certain things&#8230;like input simulation.  Anyway, I gave my free copy away for that very reason.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RIM talks about security threat of DDOS attacks on carriers at SmartPhoneCool.com</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-37004</link>
		<dc:creator>RIM talks about security threat of DDOS attacks on carriers at SmartPhoneCool.com</dc:creator>
		<pubDate>Fri, 20 Nov 2009 00:00:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-37004</guid>
		<description>[...] is this really a big concern? I have to agree with Ronen at BerryReview, that someone stealing personal data with an application seems like a bigger concern. All you have [...]</description>
		<content:encoded><![CDATA[<p>[...] is this really a big concern? I have to agree with Ronen at BerryReview, that someone stealing personal data with an application seems like a bigger concern. All you have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DavidB</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36999</link>
		<dc:creator>DavidB</dc:creator>
		<pubDate>Thu, 19 Nov 2009 22:36:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36999</guid>
		<description>1. Even WORSE are the hybrids...!
2. Did you see the QuickPull in order to work on OS5 wants you to change ALL default security policies to ALLOW!?! And amazingly people just blindly go off and do it! Madness. And RIM tacitly approves of such activity by failing to revoke signing keys. For all its security there is still no centralized control point by RIM that could remotely revoke an app&#039;s ability to run or interact. BUT, would users tolerate that? Look at all the broohaha surrounding iTunes and their walled garden. RIM had the ultimate walled garden and benevolently complete control of the experience but has totally ceeded it in the name of consumer market share. 

From my BlackBerry Tour...</description>
		<content:encoded><![CDATA[<p>1. Even WORSE are the hybrids&#8230;!<br />
2. Did you see the QuickPull in order to work on OS5 wants you to change ALL default security policies to ALLOW!?! And amazingly people just blindly go off and do it! Madness. And RIM tacitly approves of such activity by failing to revoke signing keys. For all its security there is still no centralized control point by RIM that could remotely revoke an app&#8217;s ability to run or interact. BUT, would users tolerate that? Look at all the broohaha surrounding iTunes and their walled garden. RIM had the ultimate walled garden and benevolently complete control of the experience but has totally ceeded it in the name of consumer market share. </p>
<p>From my BlackBerry Tour&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luciano</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36996</link>
		<dc:creator>Luciano</dc:creator>
		<pubDate>Thu, 19 Nov 2009 22:04:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36996</guid>
		<description>Two big problems:

1) RIM fosters an irresponsible culture whereby people fetch shady &quot;leaked&quot; updates at RapidShare because there is no centralized, official distribution. RIM will be to blame when someone posts up a malicious OS somewhere and users download it without giving it a second thought because we have developed the habit of using those. This practice has led lots of Blackberry users to trust something that they shouldn&#039;t. 

2) Likewise, some applications refuse to work until you grant them access to everything or even *specifically* e-mail, PIM and personal data. Even if personal data is completely irrelevant to the purpose of the app. And nobody raises a stink about such apps. People just grant the permission because, heck, they can hardly wait to play with the toy. They just surrender the data.

These combined create the perfect ground for a &quot;social engineering&quot; con artist. Screw the security around the Blackberry platform from the purely technical standpoint. Just target these human vulnerabilities that both RIM and app developers have been fostering, and go to town!</description>
		<content:encoded><![CDATA[<p>Two big problems:</p>
<p>1) RIM fosters an irresponsible culture whereby people fetch shady &#8220;leaked&#8221; updates at RapidShare because there is no centralized, official distribution. RIM will be to blame when someone posts up a malicious OS somewhere and users download it without giving it a second thought because we have developed the habit of using those. This practice has led lots of Blackberry users to trust something that they shouldn&#8217;t. </p>
<p>2) Likewise, some applications refuse to work until you grant them access to everything or even *specifically* e-mail, PIM and personal data. Even if personal data is completely irrelevant to the purpose of the app. And nobody raises a stink about such apps. People just grant the permission because, heck, they can hardly wait to play with the toy. They just surrender the data.</p>
<p>These combined create the perfect ground for a &#8220;social engineering&#8221; con artist. Screw the security around the Blackberry platform from the purely technical standpoint. Just target these human vulnerabilities that both RIM and app developers have been fostering, and go to town!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RIM talks about security threat of DDOS attacks on carriers &#124; BlackBerry Cool</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36992</link>
		<dc:creator>RIM talks about security threat of DDOS attacks on carriers &#124; BlackBerry Cool</dc:creator>
		<pubDate>Thu, 19 Nov 2009 21:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36992</guid>
		<description>[...] is this really a big concern? I have to agree with Ronen at BerryReview, that someone stealing personal data with an application seems like a bigger concern. All you have [...]</description>
		<content:encoded><![CDATA[<p>[...] is this really a big concern? I have to agree with Ronen at BerryReview, that someone stealing personal data with an application seems like a bigger concern. All you have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RIM talks about security threat of DDOS attacks on carriers &#124; BlackBerry Cool</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36991</link>
		<dc:creator>RIM talks about security threat of DDOS attacks on carriers &#124; BlackBerry Cool</dc:creator>
		<pubDate>Thu, 19 Nov 2009 21:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36991</guid>
		<description>[...] is this really a big concern? I have to agree with Ronen at BerryReview, that someone stealing personal data with an application seems like a bigger concern. All you have [...]</description>
		<content:encoded><![CDATA[<p>[...] is this really a big concern? I have to agree with Ronen at BerryReview, that someone stealing personal data with an application seems like a bigger concern. All you have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DavidB</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36989</link>
		<dc:creator>DavidB</dc:creator>
		<pubDate>Thu, 19 Nov 2009 19:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36989</guid>
		<description>AND, WHY is RIM seemingly powerless to force carriers to deploy an updated OS for the browser vulnerability that has been public for MANY WEEKS now?  Very few carriers have released patched OS&#039;s to date. MILLIONS of BlackBerry smartphones worldwide remain vulnerable and RIM fiddles like Nero. Luckily, nobody (that we know of anyway) has yet figured out way to really exploit it or Rome would truly be burning.</description>
		<content:encoded><![CDATA[<p>AND, WHY is RIM seemingly powerless to force carriers to deploy an updated OS for the browser vulnerability that has been public for MANY WEEKS now?  Very few carriers have released patched OS&#8217;s to date. MILLIONS of BlackBerry smartphones worldwide remain vulnerable and RIM fiddles like Nero. Luckily, nobody (that we know of anyway) has yet figured out way to really exploit it or Rome would truly be burning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dev_guy</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36988</link>
		<dc:creator>dev_guy</dc:creator>
		<pubDate>Thu, 19 Nov 2009 19:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36988</guid>
		<description>&quot;Flexilis researchers have already identified virus-tainted versions of popular smartphone applications such as Google Inc&#039;s Google Maps software and computer games.&quot;

This is the problem.  There are a lot of free application sites popping up, and you really can&#039;t be sure what you&#039;re getting.  Even on the mobihand network I may be mistaken, but I don&#039;t think theres any sort of review process do ensure that harmful software is being kept out.  

As you said Ronen, anyone with $20 can get access to the secure API&#039;s and find out all the information about every contact on your phone, as well as all the email conversations you&#039;ve had, what apps you have etc. etc.

Information is money, this is what they want, and it&#039;s not hard to get it if someone installs the program (And as this article says, you may think you&#039;re installing something else).</description>
		<content:encoded><![CDATA[<p>&#8220;Flexilis researchers have already identified virus-tainted versions of popular smartphone applications such as Google Inc&#8217;s Google Maps software and computer games.&#8221;</p>
<p>This is the problem.  There are a lot of free application sites popping up, and you really can&#8217;t be sure what you&#8217;re getting.  Even on the mobihand network I may be mistaken, but I don&#8217;t think theres any sort of review process do ensure that harmful software is being kept out.  </p>
<p>As you said Ronen, anyone with $20 can get access to the secure API&#8217;s and find out all the information about every contact on your phone, as well as all the email conversations you&#8217;ve had, what apps you have etc. etc.</p>
<p>Information is money, this is what they want, and it&#8217;s not hard to get it if someone installs the program (And as this article says, you may think you&#8217;re installing something else).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jamie</title>
		<link>http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36986</link>
		<dc:creator>Jamie</dc:creator>
		<pubDate>Thu, 19 Nov 2009 19:10:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.berryreview.com/2009/11/19/rim-security-vp-worried-about-smartphone-ddos-attacks-why/#comment-36986</guid>
		<description>I don&#039;t think we will honestly have to worry about someone breaking into the BlackBerry OS anytime soon. In all the time we&#039;ve had leaks I don&#039;t think we have ever found an OS with a vulnerability. I would guess that they literally destroy / trash all builds ASAP that show any signs of insecurities. 

The Java platform may be buggy / slow at times but RIM has made it damn secure.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think we will honestly have to worry about someone breaking into the BlackBerry OS anytime soon. In all the time we&#8217;ve had leaks I don&#8217;t think we have ever found an OS with a vulnerability. I would guess that they literally destroy / trash all builds ASAP that show any signs of insecurities. </p>
<p>The Java platform may be buggy / slow at times but RIM has made it damn secure.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic (Feed is rejected)
Page Caching using disk: basic (User agent is rejected)
Object Caching 363/367 objects using disk: basic
Content Delivery Network via cdn3.berryreview.com

Served from: www.berryreview.com @ 2012-02-12 11:31:16 -->
