PDA

View Full Version : Security and Privacy


BigJames
04-30-2009, 07:07 PM
I am using a company BELL (Canada) BB 7250 connected to our office BES server and Exchange 2007 server. We have unlimited texting on all our phones and a pooled data plan.

If I send a SMS text message on my phone, will the phone bill show the sender and receiver phone number? Is the actual content of the message retreivable by my account administrator?

If I send a PIN message on my phone, is the receiver PIN number retrievable? Is the content of the PIN message retrievable?

If I send an email using an external email address connected to my phone (i.e. gmail.com account or bell.blackberry.com account) , is it retrievable by my company system administrator via phone bills? Or would it appear as untraceable data used?

I guess I am curious as to how secure messages sent via SMS, PIN, or external email on the phone are. I am under the impression they are "more secure" than using my BES activated email address (in that the work email address activated on the phone goes through our corporate server and is therefore reviewable by the system admin).

I ask because one of my coworkers was using SMS to talk to his girlfriend and it was suggested to him that the content of SMS messages were viewable by the cell phone account administrator. I was under the impression that the number of messages was viewable, but not the content. But further, if we were using such messaging to relay confidential information, could be it retrieved?

Anyone shed light on this issue for me?

Thanks,

dc/dc
04-30-2009, 07:20 PM
Just about everything is readable by your BES admin should they so choose.

The best thing to do is to keep your business device for business use only unless your administrator has specifically authorized you to use your device for personal use. Otherwise, you should buy your own device and service for your personal use. This is "best practice".

juwaack68
04-30-2009, 07:25 PM
Give this a read....it's a frequently asked/discussed topic:

http://www.blackberryforums.com/bes-admin-corner/186374-private-info-bes.html

TXLady
05-01-2009, 09:22 AM
The best thing to do is to keep your business device for business use only unless your administrator has specifically authorized you to use your device for personal use. Otherwise, you should buy your own device and service for your personal use. This is "best practice".

+1.

Agree whole-heartedly with this advice. Which is why I have my company blackberry and my personal blackberry and use each one for the puposes for which it was purchased. My team mates frequently complain about how the company berries are locked down and they can't do whatever they want on them. I simply pull my personal BB out and say "I can do what I want with this one. If you want the same freedom, buy one for yourself."

BigJames
05-07-2009, 05:35 PM
I agree with you guys...absolutely and I told my coworkers the same thing. Can someone with BES Admin experience tell me something: I am an Admin on my system, when I log into my BES there is an heading called "monitor messages". Is this where the SMS and PINs would be found? When I select it, it says "this service is not available" or something like that. Let me know. I want to confirm what I am hearing so I can put this to bed...so to speak. LOL.

bertiebassett
05-07-2009, 05:56 PM
I agree with you guys...absolutely and I told my coworkers the same thing. Can someone with BES Admin experience tell me something: I am an Admin on my system, when I log into my BES there is an heading called "monitor messages". Is this where the SMS and PINs would be found? When I select it, it says "this service is not available" or something like that. Let me know. I want to confirm what I am hearing so I can put this to bed...so to speak. LOL.

Nah you need to change the IT policy for 'Log SMS messages' (not sure that's the exact wording but..) to true and similarly log pin messages & phone calls - then push this updated policy out to your users.

Then when a BB Device makes / receives an SMS message the policy will kick in and a copy of the message including the sender number or name from phonebook if listed in that device - i.e John Doe rather than 1-212-555-xxxx, and the date/time stamp is recorded in the log. Yes the full text of the messages sent as well as received is stored!!!

The log files are stored with the other log files on the BB server (could be \Program Files\RIM\BES\Logs or similar) and there's a separe log file for each days messages or phone calls. If you open the relevant text file you can read away and find out who's cheating on their partner or whatever else you need to know!!

When you first activate this policy then there's a dump of all the SMS messages stored still in the devices into that days log file, so as long as a message is still in the device memory activating this policy will pick it up!!

If you want to analyse/store these log files then I suggest a tool such as this one will make the process easier - GWAVA: Retain for BlackBerry (http://www.gwava.com/products/retain-for-blackberry-enterprise-server.html)

Have fun snooping but be sure you have permission/authority to do so as most people expect SMS to be like phone calls - once sent they're gone for good. Not so with BB & BES !!

BigJames
05-07-2009, 06:06 PM
Good info. Thanks. One other question, when I looked at the logs they only went back 7 or so days. Is this a default? Do the logs get deleted automatically after a certain number of days?

Thanks,