BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 06-05-2006, 10:04 AM   #1
r0adster
New Member
 
Join Date: Apr 2005
Location: Boston, MA
Model: 8700v
Posts: 8
Default How competent is BB security options?

Please Login to Remove!

I would like to protect my BB from the thieves and unruly people who expect to take out my BB without me noticing and reading my messages (thanks, wife, boss, IT guy.) And I've turned on content protection and have passwords set up.

But how competent is the security?

Let's say...

Would this PW still be active after a handheld wipe (even JavaLoader wipe)?

-------------------------------------------------------------------------

I know I can't deter ALL of those people. But I would like to gain the satisfaction of knowing that my device is protected.
__________________
BB 8700v on Cingular
PIN: 23D40FEA
Offline  
Old 06-05-2006, 10:11 AM   #2
chrisl
Knows Where the Search Button Is
 
Join Date: Mar 2006
Model: 8100
Carrier: Vodafone UK
Posts: 24
Default

No it wouldn't....but if the device had been wiped there will be no emails on your device anyway and it will not be receiving or sending any emails anyway as it would've been wiped.

With the passwords...there are no hints or clues so the person has literally got to guess your password. And if you make it a strong password they aren't likely to get it in 10 attempts at which point the device wipes itself to protect the information
Offline  
Old 06-05-2006, 10:22 AM   #3
cooperpwc
BlackBerry Extraordinaire
 
cooperpwc's Avatar
 
Join Date: Mar 2006
Location: Toronto Canada
Model: 8700R
Carrier: Rogers
Posts: 1,001
Default

Well I don't agree at all. The password is still active after a wipe. It is embedded much deeper. If the password was activated when they get the unit (or activates itself on a time-out) they cannot use the Blackberry. Period.
EDIT: Not. See my retraction at #13 below.

Last edited by cooperpwc; 06-08-2006 at 02:34 PM..
Offline  
Old 06-05-2006, 10:35 AM   #4
Zipper
Knows Where the Search Button Is
 
Join Date: Mar 2006
Location: USA
Model: 8520
Carrier: T-Mobile
Posts: 25
Default

Quote:
Originally Posted by cooperpwc
Well I don't agree at all. The password is still active after a wipe. It is embedded much deeper. If the password was activated when they get the unit (or activates itself on a time-out) they cannot use the Blackberry. Period.
Good,
Offline  
Old 06-05-2006, 06:14 PM   #5
jsuen
Knows Where the Search Button Is
 
Join Date: Apr 2006
Model: 7130e
Carrier: cingular
Posts: 36
Default

Blackberry content protection is seriously secure. One of their documents somewhere details the entire process, but basically the data is encrypted by a 256-bit AES key derived from your password, so the security of the thing is based on how good your password is.

In a wipe, RAM is overwritten 7 times, and the flash is overwritten 8.
Offline  
Old 06-08-2006, 12:55 AM   #6
prolepsis
Knows Where the Search Button Is
 
Join Date: Apr 2005
Model: 8700c
Carrier: Rogers
Posts: 23
Default

Quote:
Originally Posted by cooperpwc
Well I don't agree at all. The password is still active after a wipe. It is embedded much deeper. If the password was activated when they get the unit (or activates itself on a time-out) they cannot use the Blackberry. Period.
Is this for all wipes? I just tried on my 8700 BBerry (I am not on a BES).

1) Enabled and set a password.
2) Purposely entered the wrong password 10x.
3) BlackBerry gets wiped.

Upon reboot, my password is no longer stored (when I check in Security it says "Disabled" for the Password field.

Data is gone, but Google Maps (and I would assume other apps) are still there

This means that if a BBerry was stolen, someone theoretically could use the BBerry, though not recover the data. Since the password also seems to get wiped, unless the PIN or IMEI is blocked, it looks like anyone can use it(?). I was hoping that after the wipe the BBerry would still ask me for my password.
Offline  
Old 06-08-2006, 02:10 AM   #7
wibbly
CrackBerry Addict
 
wibbly's Avatar
 
Join Date: Apr 2005
Location: UK
Model: 9700
Carrier: T-Mobile UK
Posts: 857
Default

For BIS users, after a wipe, won't/can't a BB get its service books back OTA and start receiving NEW (and presumably private) mail? And the user can reply to it!? So you have to spot your BB's missing and kill off email forwarding to the BB and/or POP3 polling...
Offline  
Old 06-08-2006, 02:17 AM   #8
EricaJ1074
CrackBerry Addict
 
Join Date: Apr 2006
Model: 7105t
Posts: 981
Default

Sometimes it does automatically re-register itself on the wireless network. For BIS users, if that does not happen, to get the service books back, go to Options>Advanced Options>Host Routing Table>Register Now to send the service books (along with the enterprise activation, web browser, download fun, and setup internet email icons). To start sending/receiving mail, log into your account, go to Set Up Internet Email and click on Send Service Book.
__________________
PIN: 23CF4BE6
Yahoo: ericablackberry
GTalk: ericablackberry
Offline  
Old 06-08-2006, 02:58 AM   #9
wibbly
CrackBerry Addict
 
wibbly's Avatar
 
Join Date: Apr 2005
Location: UK
Model: 9700
Carrier: T-Mobile UK
Posts: 857
Default

That's my point, EricaJ, I think a person who steals/gets your BB can start receiving YOUR new mail, even after the device has been wiped, if you're not careful...
Offline  
Old 06-08-2006, 08:00 AM   #10
cooperpwc
BlackBerry Extraordinaire
 
cooperpwc's Avatar
 
Join Date: Mar 2006
Location: Toronto Canada
Model: 8700R
Carrier: Rogers
Posts: 1,001
Default

Am I wrong about this? I have wiped and reinstalled the OS many times and the password was always active. I have not however ever entered the wrong password 10 times. I'm truly surprised if that will disable the password function. Anyone else have feedback?
Offline  
Old 06-08-2006, 11:12 AM   #11
prolepsis
Knows Where the Search Button Is
 
Join Date: Apr 2005
Model: 8700c
Carrier: Rogers
Posts: 23
Default

Quote:
Originally Posted by cooperpwc
Am I wrong about this? I have wiped and reinstalled the OS many times and the password was always active. I have not however ever entered the wrong password 10 times. I'm truly surprised if that will disable the password function. Anyone else have feedback?
I haven't tried a wipe + reinstall of the OS so I don't know. I'm hoping someone else will try to and report back.

Late last night, I also tried the "Wipe Handheld" option from the Password field. Upon wipe, my apps were present (data gone) and the Password field showed up as being "Disabled."

Perhaps when someone gets a new BBerry they can try entering some data and then wiping it.

I wish that for BIS users we had a "kill" BBerry option as well, like the BES folks. Or something where you could call the carrier, verify your identity, and then get them to send a "kill pill." (Since if users have this option I can imagine some users accidently activating it!)
Offline  
Old 06-08-2006, 01:49 PM   #12
jcjwireless
Knows Where the Search Button Is
 
Join Date: May 2006
Model: 8700c
Posts: 17
Default

Quote:
Originally Posted by cooperpwc
Am I wrong about this? I have wiped and reinstalled the OS many times and the password was always active. I have not however ever entered the wrong password 10 times. I'm truly surprised if that will disable the password function. Anyone else have feedback?
On the 8700c if you try the password over 10times it will wipe the entire BB and the password feature will be disabled. Know form experience.
Offline  
Old 06-08-2006, 02:33 PM   #13
cooperpwc
BlackBerry Extraordinaire
 
cooperpwc's Avatar
 
Join Date: Mar 2006
Location: Toronto Canada
Model: 8700R
Carrier: Rogers
Posts: 1,001
Default

Quote:
Originally Posted by jcjwireless
On the 8700c if you try the password over 10times it will wipe the entire BB and the password feature will be disabled. Know form experience.
Okay, so with apologies to chrisl, I stand corrected. Password protection apparently only protects your data. It won't stop a thief from using your Blackberry as a phone or PIM.
Offline  
Old 06-08-2006, 02:42 PM   #14
richardsbd
Thumbs Must Hurt
 
richardsbd's Avatar
 
Join Date: Apr 2006
Location: work in Washington, DC, USA
Model: 8700c
Carrier: The 'new' AT&T (formerly known as Cingular)
Posts: 123
Default

I can only speak from my experience with BB7290s - when you type the password wrong 10 times, the device is wiped, and when it comes back up, you are prompted to create a new password (which is a bit different from statements of "the password feature will be disabled").

On top of that, the IT Policy is still in place, so if device password protection was enabled before the wipe, it is still enabled (and cannot be disabled) afterwards. We are on BES...
__________________
Brian

user and maintainer of a bunch of BB8700s

current project - nordoxandsoaps.com | View my LinkedIn profile
Offline  
Old 06-08-2006, 02:50 PM   #15
wibbly
CrackBerry Addict
 
wibbly's Avatar
 
Join Date: Apr 2005
Location: UK
Model: 9700
Carrier: T-Mobile UK
Posts: 857
Default

> won't stop a thief from using your Blackberry as a phone or PIM.

Or seeing any new mails sent to the device, or impersonating you in mails they send from the device, unless you kill off the BIS config for that device, right?

> the IT Policy is still in place

Only if you run via a BES. BIS users have no IT policy.
Offline  
Old 06-08-2006, 03:03 PM   #16
prolepsis
Knows Where the Search Button Is
 
Join Date: Apr 2005
Model: 8700c
Carrier: Rogers
Posts: 23
Default

Quote:
Originally Posted by wibbly
> won't stop a thief from using your Blackberry as a phone or PIM.

Or seeing any new mails sent to the device, or impersonating you in mails they send from the device, unless you kill off the BIS config for that device, right?

> the IT Policy is still in place

Only if you run via a BES. BIS users have no IT policy.
Looks like it. So for BIS users, if you lose your BBerry, you need to:

1) Call your provider to get them to block the SIM
2) Get then to disassociate your PIN with your BIS/blackberry email account (once this step is done the BBerry user won't be able to impersonate you)
3) Get them to block your IMEI/PIN (if they offer this feature)

The thing is, from what I was told, IMEI blocks/blacklists aren't necessarily shared between providers. So for GSM BBerries, someone could easily pop in a different SIM and use your device, especially if it's unlocked, at least as a phone. Not sure about PIN blocking, however, since that's BB-specific.

The good news out of all this is that at least your data will be wiped! That's my main concern and probably a number of others', too.
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


CH341A 24 25 Series EEPROM Flash BIOS USB Programmer Module + SOIC8 Test Clip picture

CH341A 24 25 Series EEPROM Flash BIOS USB Programmer Module + SOIC8 Test Clip

$5.88



10PCS DIP-28 Eeproms Programmable Flash Chip For SST27SF512-70-3C-PG SST 27SF512 picture

10PCS DIP-28 Eeproms Programmable Flash Chip For SST27SF512-70-3C-PG SST 27SF512

$27.89



Eeprom Bios Usb Programador Ch341a + Soic8 Clip + 1.8V Adaptador + Soic8 Ada picture

Eeprom Bios Usb Programador Ch341a + Soic8 Clip + 1.8V Adaptador + Soic8 Ada

$23.15



USB BIOS EEPROM SPI FLASH Programmer CH341A 24 25 series BIOS Writer Burner Chip picture

USB BIOS EEPROM SPI FLASH Programmer CH341A 24 25 series BIOS Writer Burner Chip

$7.57



10PCS For SST27SF512-70-3C-PG SST 27SF512 DIP-28 Eeproms Programmable Flash Chip picture

10PCS For SST27SF512-70-3C-PG SST 27SF512 DIP-28 Eeproms Programmable Flash Chip

$27.69



10PCS W27C512-45Z W27C512 DIP IC EEPROM 512KBIT 45NS Winbond EEPROMs USA picture

10PCS W27C512-45Z W27C512 DIP IC EEPROM 512KBIT 45NS Winbond EEPROMs USA

$17.98







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.