Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, November 14, 2011

BlackBerry 7 OS Awarded Common Criteria EAL4+ Security Certification

Common Criteria BlackBerry

RIM really knows how to woo security organizations to certify their products. The latest gives the new BlackBerry 7 OS the third party Common Criteria evaluation certification and meet the security criteria for evaluation assurance level (EAL) 4+. EAL is a ranking from 1 to 7 but a higher number does not necessarily mean it is more secure. It just means that the TOE (Target of Evaluation) has been put through more extensive verification.

In other words companies can now confidently deploy BlackBerry 7 OS devices knowing that they have yet another certification under their belt. The EAL4+ certification for the BlackBerry Bold 9900, BlackBerry Torch 9810, BlackBerry Torch 9860 and BlackBerry Curve 9360 which currently run the BlackBerry 7 OS is posted on the Common Criteria Portal. Full press release below:

BlackBerry 7 OS Awarded Common Criteria EAL4+ Certification

WATERLOO, ONTARIO–(Marketwire – Nov. 14, 2011) – Research In Motion (RIM) (NASDAQ:RIMM)(TSX:RIM) today announced that BlackBerry(R) smartphones running on the BlackBerry(R) 7 Operating System (OS) have been independently evaluated by a third-party Common Criteria evaluation facility and meet the security criteria for evaluation assurance level (EAL) 4+.
The Common Criteria is an international standard for validating that products meet specific security requirements. Widely respected for its extensive and comprehensive evaluation by an independent third party, EAL4+ accreditation examines a product’s design, software development methodology, and security mechanisms. EAL4+ is the highest level of accreditation under the Common Criteria Recognition Arrangement (CCRA) by 26 countries.
"Security is one of the most important considerations for enterprise customers and we are proud that BlackBerry 7 OS has earned this rigorous certification," said Scott Totzke, Senior Vice President, BlackBerry Security at RIM. "RIM is renowned as a market leader in the delivery of secure mobile solutions, and this achievement helps to provide our customers globally with continued confidence in deploying BlackBerry solutions throughout their organizations."
As a market leader in the area of information assurance and compliance, RIM is committed to independent, third party security testing and certifications of BlackBerry products. RIM is active in the Cryptographic Module Validation Program in North America, United Kingdom CESG Assisted Product Service (CAPS) and International Common Criteria evaluation scheme. BlackBerry(R) Enterprise Server has been previously awarded EAL4+ certification and the BlackBerry Enterprise Solution has also been previously approved for storing and transmitting sensitive data by the North Atlantic Treaty Organization (NATO) as well as government organizations in the United States, Canada, the United Kingdom, Austria, Australia and New Zealand.
The EAL4+ certification for the BlackBerry(R) Bold(TM) 9900, BlackBerry(R) Torch(TM) 9810, BlackBerry(R) Torch(TM) 9860 and BlackBerry(R) Curve(TM) 9360 smartphones based on BlackBerry 7 OS is posted on the Common Criteria Portal (http://www.commoncriteriaportal.org/products). EAL4+ certification for other BlackBerry 7 OS smartphones including the BlackBerry Bold 9930, BlackBerry Torch 9850, BlackBerry Curve 9350, BlackBerry Curve 9370 and Porsche Design P’9981 Smartphone from BlackBerry are expected early next year.
To find out more about BlackBerry security certifications please visitwww.blackberry.com/go/security.

Tags:

More on BerryReview

August 22, 2011

October 26, 2011

May 1, 2008

July 27, 2011

Please enter your name

Please enter a valid email address

Please enter your message

Notify me of followup comments via e-mail. You can also subscribe without commenting.

Tuesday, October 25, 2011

RIM Publishes Full Security Advisory for Old BlackBerry 6 WebKit Vulnerability

BlackBerry Torch 9800 hacked

This latest security advisory goes to show why RIM’s current model for carrier approved OS updates is not ideal. RIM put out what they call a security notice about a BlackBerry 6 WebKit browser vulnerability back in March of this year for an exploit found in the BlackBerry 6 Browser at Pwn2Own that month. RIM said back then that devices updated to OS 6.0.0.526+ were safe from the vulnerability. They then finally issued a security advisory this week for the same old vulnerability with quite a few more details about it.

The reason RIM took so long to release the advisory was because RIM had to wait for carriers to approve the security software update. RIM provided the fix within two weeks of learning of the vulnerability. Now SIX MONTHS LATER RIM has found that “a sufficient number of wireless services providers” have made the update available to their customers.

Here is RIM’s explanation for the delay:

A sufficient number of wireless service providers must make a security software update for BlackBerry smartphones publicly available to customers before RIM will publish full details of the software update in a Security Advisory. RIM delivered the software updates to its wireless service provider partners. Where a wireless service provider may not have then provided the software updates to all customers, this policy is intended to protect those customers from increased risk of exploitation.

Within two weeks of learning of the vulnerabilities that this Security Advisory addresses RIM tested and delivered fixed software to our wireless service provider partners for their Technical Acceptance process. During the Technical Acceptance process, RIM monitored update availability for nine affected devices available through nearly 500 carriers globally until an availability level was achieved that allowed us to be confident that disclosure of the security vulnerabilities addressed by the software update would protect the interests of the majority of our customers.

RIM continues to work with our partners to expedite the process of software update delivery to BlackBerry smartphone customers.

Note: KB26132 was previously published as a Security Notice to responsibly advise customers about the existence of one of the three vulnerabilities, which had been publicly disclosed, and provide workaround options in lieu of a software update to address that issue for all affected customers. This Security Advisory replaces that Security Notice and provides full details of publicly available software updates that address that issue and two related issues, and urges affected customers to upgrade.

Six months to roll out a relatively critical software update is simply ridiculous in this fast changing security scene… Thankfully the PlayBook QNX based OS has been consistently pushing out security updates within 2 weeks or so.

More on BerryReview

Thursday, October 13, 2011

RIM Explains how to Secure Your BlackBerry PlayBook & Wi-Fi Sharing

Wi-Fi file sharing password

I still remember when RIM was handing out BlackBerry PlayBook’s at BlackBerry World many of them were setup by users to share files over Wi-Fi with no passwords. While some users may be smart enough to set a device password on their PlayBook it may not be necessary for all users. On the other hand Wi-Fi sharing passwords should be turned on for 99% of use cases. If you turn on Wi-Fi sharing on your BlackBerry PlayBook to share files over Wi-Fi and don’t setup a password then anybody on the same Wi-Fi network can access your PlayBooks media files including pictures, documents, videos, etc. Not good…

RIM was kind enough to put together a simple graphical tutorial on how to setup a BlackBerry PlayBook devices password and Wi-Fi sharing password. If you need help setting one up after reading their guide on it let us know in the comments.

More on BerryReview

Monday, September 12, 2011

Review: iLocker Pro - App Lock and Privacy Protection


iLocker Pro


If you've just gotten a new BlackBerry then probably one of the most important to-do's on your list is protecting your device. Now I'm not talking about cases or screen protectors but about your personal information. Some of us just go about our business and don't always realize how much of our "stuff" is out there for everyone to see especially when we hand off our device to friends, family and little ones too young to understand just exactly what they've been given.


Personally, I have a tendency to be absent-minded when it comes to my Torch. I think I must leave my device all over the place at work or at home. However, I've never been a fan of the native feature which locks down everything. That's why I decided to give iLocker by SKYANT a try so I could personally control which native or third party applications are accessible at any given moment.


 


iLocker Pro is just the thing to protect your files and applications from nosy intruders. From the developer that brought you Toast Message it comes in a free limited feature lite version (can't lock BBM) and a full feature paid version. It enables you to lock down any native or third party application and hide files and folders (if they use the files app) on your device or SD card from inquiring minds. 


When you first install iLocker it immediately asks you to create a password which can be up to 25 characters long. Just make sure you remember what this is as it will be used to unlock each and every app you choose to lockdown. There doesn't seem to be a limit on the number of invalid password attempts. I'm still undecided if this is a good thing.


 


iLocker Pro Input Password 


 


The main interface is broken down by four categories: Application, Hide / Unhide My Files, Schedule Lock, and Lock Option. By clicking on the native or third party line items you can select any or all applications to secure. The little lock icon to the right will turn blue when enabled. All of the core BlackBerry apps are there and it does a good job of password protecting them. For example if you choose Media under native apps, the music, pictures, and videos icons are all affected. However, I did notice an issue with the Manage Connections application. While the home screen icon is protected, the drop down at the top is still accessible.


 


iLocker Pro Apps Selection 


 


Hiding files and folders works pretty well. Not only does it hide files when using the built-in file explorer app but it also removes it from appearing in Documents to Go. If you store confidential documents and presentations on your device this is a great feature to use.


 


iLocker Pro - Files and Folders 


 


 


While other applications just protect iLocker allows users to lock down their applications by specific time frames and create a lockdown schedule. Users are given the option to lock by time (whole day/custom-start/end), frequency (days of the week), and if protection should start immediately, after backlight turns off, or after device lock. This is actually an interesting feature to include. It's perfect for me if I grab lunch and leave my BlackBerry at my desk. I can set it to lock during my lunch hour on weekdays. I must point out that you must enter in a time and select the day(s) of the week together in order to function.


 


iLocker Main Screen 


 


Once everything is selected and a schedule chosen all that's left is to enable and let the application run its course. Now you can sit back and relax knowing that your information is safe and secure.


Pros


Cons


iLocker Lite and iLocker Pro are available for most BlackBerry devices running OS 4.5 and higher. At the time of this post iLocker Pro is currently on sale for $2.99 from its normal price of $5.99.


Rating


iLocker is an easy to use application for your BlackBerry to hide personal data from prying eyes. Simply click and you're done. When holding someone else's device in your hands the temptation to sneak a peek at something you shouldn't is always there. I admit having an urge to snoop when my boss hands me his device to troubleshoot. iLocker makes sure the data you don't want anyone to see stays private. Although I would like to see them add a menu option to secure applications from the home screen and to get rid of the split second delay before the password box appears. Other than that is performs exactly the way it should.


More information / purchase iLocker Pro from BlackBerry App World 

More information / purchase iLocker Pro from the CrackBerry App Store

More information / download iLocker Lite from BlackBerry App World 

More information / download iLocker Lite from the CrackBerry App Store

Monday, August 22, 2011

BlackBerry Smart Card Reader Gets US Federal FIPS 120-2 Level 3 Certification

SCR2

In case you didn’t think RIM’s BlackBerry Smart Card Reader was secure enough RIM now has the US Federal Government standing behind it. They just announced FIPS 140-2 Level 3 certification for the smartcard badge reader. If I am not mistaken the device had FIPS 140-2 Level 2 certification for awhile but that has been updated. The cards are supposed to help government officials comply with the US Department of Defense Common Access Card program which wants mandatory reliable identification for government employees and contractors. I am guessing the new Level 3 certification will make the device an easier sell for RIM to its 1+ million US government BlackBerry users.

Check out the details below or at us.blackberry.com/ataglance/security/products/smartcardreader/

BlackBerry Smart Card Reader Achieves Advanced Security Certification for U.S. Federal Government

Waterloo, ON – Research In Motion (RIM) (NASDAQ: RIMM; TSX: RIM) announced today that the BlackBerry Smart Card Reader™ has achieved FIPS 140-2 certification level 3 – the highest certification achieved by any wireless smart card reader on the market. Smart cards support security programs like the U.S. Department of Defense’s Common Access Card (CAC) program and the Homeland Security Presidential Directive 12 (HSPD-12) which calls for a mandatory, government-wide standard for secure and reliable forms of identification issued by the federal government to its employees and to the employees of federal contractors. FIPS (Federal Information Processing Standard) certifications are assigned by the National Institute of Standards and Technology (NIST), an agency of the U.S. Department of Commerce.

“Our customers value the robust security provided with BlackBerry products and services and smart card readers are particularly important within the government sector,” said Scott Totzke, Senior Vice President, BlackBerry Security at Research In Motion. “This advanced certification of the BlackBerry Smart Card Reader for the U.S. Federal Government demonstrates our ongoing commitment to meet and exceed the expectations of our government customers.”

The BlackBerry Smart Card Reader is designed to work with personal identification cards issued by government organizations or other high-security organizations. Users insert a smart card into this lightweight reader and wear it on a lanyard as a two-factor authentication device for secure access to BlackBerry smartphones, desktop computers and facilities.  BlackBerry smartphones and desktop computers automatically lock when the user’s smart card is not in proximity.

FIPS 140-2 level 3 certification of the BlackBerry Smart Card Reader also verifies advanced security features of the smart card reader itself, such as tamper evidence and self destruction of critical security parameters upon device breach.

For more information, see   http://us.blackberry.com/ataglance/security/products/smartcardreader/.

More on BerryReview

Thursday, August 18, 2011

Security Testers Give the BlackBerry PlayBook a Thumbs Up

Attack area

Way back in April we pointed out some of the documentation RIM provided on the security features of the BlackBerry PlayBook. Those security features were put to the test by penetration testers working for NGS Secure who poked and prodded both actual PlayBook devices and the simulators and confirmed the devices security.

I did love some of the lines from the first part of the report which was just released like:

Although Neutrino is similar in many ways to a traditional UNIX environment, the QNX microkernel is substantially different from the monolithic Linux kernel.

Other stuff I found more interesting like the fact that early versions of the PlayBook simulator ran every application as Root but that has changed and now each app is assigned their own user and group for sandboxing. Also worth noting is the fact that the upd account is right behind root in terms of access to the system. On the other hand most people like developers will be relegated to the devuser which has very little privileges. NGS also tried mounting the file system and didn’t have much luck. On the other hand they found that the PlayBook runs NetBSD’s Bozotic HTTP server which is running as root which is odd… They found some interesting files through this web server but only managed to get them to crash the device. They also managed to make the device stop responding with a specially crafted HDMI fuzzer but once again nothing useful was gained from that. NGS also harped about the PlayBook allowing unsigned code in development mode but nothing much came of it.

The report is quite interesting if you want to learn about the attack surface of the PlayBook or simply what you can try to use to compile your own code or learn more about the OS. Check out the full PDF report on this page or directly at this link.

Thanks to everyone who sent this in!

More on BerryReview

Wednesday, July 27, 2011

RIM Explains PlayBook FIPS Government Certification & More

 FIPS Certification PlayBook Interview

The BlackBerry PlayBook became the first and only FIPS US government certified tablet this month which is a pretty big milestone for RIM. While their smartphones are certified RIM has already had the BlackBerry PlayBook cryptographic kernel certified for government use which opens up the doors for the biggest tech consumer in the US to purchase them.

RIM has thankfully posted a video interview with Michael K. Brown, Director of Security Product Management at RIM, to explain a bit about what FIPS certification is and why it is so important. He also explains why this kind of security certification is essential for government clients alongside healthcare and financial clients. Check out the video below including the golf carts driving by in the background… :)


Desktop Video Link | Mobile Video Link

More on BerryReview

Friday, July 15, 2011

RIM Explains BlackBerry PlayBook Work & Personal Info Security

BlackBerry Bridge

In the past we have mentioned a bit about what security measures RIM has put in place on the BlackBerry PlayBook but the documentation was a bit daunting. They have kindly summed much of it up into one comparably short knowledge base article. In short your work data over the Bridge is ultra secure with 512 bit encryption but your personal data is not. Hopefully that is fixed in the future but still this should be an easy sell for enterprises worried about jailbroken iPads and Android tablets.


Security of work and personal data on the BlackBerry PlayBook tablet

Article ID: KB27707

Does the tablet store any work data persistently in the work file system?

No.

When a tablet is connected to a BlackBerry® smartphone using BlackBerry® Bridge™, the tablet temporarily stores work data in the work file system on the tablet. The work file system is encrypted using XTS-AES-256. The keys that the BlackBerry® PlayBook™ tablet uses to encrypt the work file system are encrypted using the BlackBerry Bridge work key. The tablet stores the BlackBerry Bridge work key in RAM only.

When the Bluetooth® connection between a tablet and a smartphone closes, the tablet and the smartphone each delete their copy of the BlackBerry Bridge work key. All of the work data that is stored on the tablet is encrypted with keys that are encrypted using the BlackBerry Bridge work key, and both copies of the work key are deleted. This data and key encryption means that it is not possible to decrypt the work data after the Bluetooth connection closes and the smartphone and tablet delete their copies of the BlackBerry Bridge work key.

What is XTS-AES?

XTS-AES is an IEEE-approved Advanced Encryption Standard mode for disk encryption that provides protection against manipulation of encrypted data. XTS-AES-256 uses 512-bit cryptographic keys.

Does the tablet encrypt personal data?

No.

Can I disable the feature that allows work applications to attach personal files to work email messages or calendar entries?

No.

Is the cryptographic module on the BlackBerry PlayBook tablet FIPS validated?

The cryptographic module on the tablet is currently in the process of being validated for FIPS 140-2 certification.

Can I set a password on a tablet?

Yes. A user can configure the tablet password and timeout options using the Options menu on the tablet. If you set a password for the tablet, you must provide that password to log in to the tablet.

Is work data protected by the smartphone password?

Yes. After a BlackBerry PlayBook tablet user connects the tablet to a BlackBerry smartphone that requires a password, the tablet automatically requires the user to provide the smartphone password when the tablet accesses any smartphone data. Smartphone data can include email messages, calendar entries, tasks, memos, BlackBerry® Messenger messages, intranet content, files, or attachments that the user views on the tablet.

The requirement to provide the smartphone password to access work data is independent of the tablet password that a user may set.

Do the IT policy rules that control the password security level of a smartphone extend to a tablet?

Yes. If a user connects a tablet to a smartphone that is associated with a BlackBerry Enterprise Server, any IT policy rules that control the password security level of the smartphone apply to the smartphone password that the user must enter to access work data on the tablet.

What password security level is enforced if I connect a tablet to a smartphone with one set of IT policy rules, then disconnect and connect the tablet to a smartphone with a different set of IT policy rules?

While the tablet is connected to the first smartphone, the password security level that is set for that smartphone is enforced. This security level applies to the smartphone password that a user must enter to access work data on the tablet. It does not apply to the tablet access password that a user may set on the tablet.

When you connect the tablet to another smartphone, the tablet deletes the work file system that temporarily stored work data associated with the first smartphone. While the tablet is connected to the second smartphone, the password security level that is set for that smartphone is enforced. This security level applies to the smartphone password that a user must enter to access work data on the tablet. It does not apply to the password that a user may set on the tablet.

Environment

Additional Information

For more information on BlackBerry PlayBook tablet security see the BlackBerry PlayBook Security Technical Overview

More on BerryReview

Comment

Comment