4 ms·
> Developers who deploy the BBM SDK will be asked to generate their own encryption keys, meaning BlackBerry will not have the ability to turn over to law enforc
by problems 10y ago
> Developers who deploy the BBM SDK will be asked to generate their own encryption keys, meaning BlackBerry will not have the ability to turn over to law enforcement any messages sent through this system, even if compelled by a court order.
Doesn't the entire security of BBM rely only on a very short code, one which Blackberry can easily swap with a different key which they posses in practice? Very similar to Apple iMessage.
Also last time I checked their enterprise offering was essentially static Triple DES key only - is their public offering any better?
EDIT: https://www.schneier.com/blog/archives/2016/04/blackberrys_glo.html https://www.schneier.com/blog/archives/2016/04/blackberrys_g...
Looks like as of last year they used a single static key for all the BBM encryption. And it's in the hands of Canadian authorities already.
Do we have any reason to believe they have or will change this? Seems completely silly to me to use something this broken.
- seibelj 10y agoEven a company with as many blunders as BlackBerry must know that publicly saying it can't be decrypted, when in fact it could easily be decrypted, would be a terrible blow to the product.
- problems 10y agoYeah, seems fairly ridiculous given how much they push being a security company. Apparently hard-coded 3DES key that anyone can reverse engineer = security. I'm tempted to pop their Android app up in IDA and see if it's really as bad as it sounds.