TechCentral

Thursday July 23, 2009

BlackBerry users tricked


DUBAI: BlackBerry users in the Middle East business centers of Dubai and Abu Dhabi who were directed by their service provider to upgrade their devices were actually installing spy software that could allow outsiders to peer inside, according to the device maker.

While many questions about the breach remain unanswered, including who ordered it sent and why, analysts say the disclosure highlights the security risks posed by increasingly popular smartphones like the BlackBerry.

Richard M. Smith, an Internet security and privacy consultant at Boston Software Forensics, said smartphones are “the perfect personal spying devices” because as tiny computers they can be programmed to send back a broad range of information.

“This is an evolving threat. As the technology advances, the security problems follow behind,” he said.

Research in Motion (RIM) Ltd, the Canadian company that makes the mobile gadgets, said in a statement e-mailed yesterday that it did not authorise the software installation and “was not involved in any way in the testing, promotion or distribution of this software application.”

It is directing customers on how to remove the software.

Spy in your pocket

“Independent sources have concluded that it is possible that the installed software could ... enable unauthorised access to private or confidential information stored on the user’s smartphone,” the company said in an eight-page statement strongly distancing itself from the decision to install the software.

The Abu Dhabi-based mobile service provider Etisalat, which is majority owned by the United Arab Emirates government, earlier sent text messages to BlackBerry customers in the country instructing them to follow a link to update their phones. Etisalat says it has more than 145,000 BlackBerry users in the UAE.

Some customers who installed the new software said it quickly drained the device’s batteries, prompting hundreds of complaints to Etisalat and sending users to Internet message boards looking for ways to fix the problem.

In a statement issued following complaints last week, Etisalat described the software change as an “upgrade ... required for service enhancements.” It said the upgrades were required and linked to a handover to the 3G wireless technology standard.

The BlackBerry maker dismissed that explanation.

“RIM is not aware of any technical network concerns with the performance of BlackBerry smartphones on Etisalat’s network in the UAE,” the company said, adding that it “does not endorse this software application.”

Etisalat did not respond to requests for comment yesterday.

Big mystery

RIM said the application users unwittingly installed was a surveillance program developed by a privately held Silicon Valley company called SS8 Networks Inc.

SS8 describes itself in a company brochure as “the leader in communications interception and a worldwide provider of regulatory compliant, electronic intercept and surveillance solutions.”

It markets its services to intelligence agencies, law enforcement and communications service providers.

A person who answered the phone at SS8’s Middle East office in Dubai declined to comment and refused to provide a name. He said the company’s regional head, Derek Roga, was out of the country. A spokesman at the company’s headquarters in Milpitas, California, could not be reached.

It is not clear why Etisalat encouraged users to install the application or if any private information was compromised.

Smith, the security and privacy consultant, said a data thief tapping into a smartphone in theory could turn on the microphone to listen in on a private conversation, provide a list of previous calls or send back the user’s location.

Bruce Schneier, an author and chief security technology officer at BT, the British telecommunications operator, said smartphones are “not inherently more secure.”

“We’ve mostly been protected because it’s annoying and inconvenient to write software for these devices,” he said.

The Persian Gulf country is the Arab world’s largest economy after Saudi Arabia. Its most populous city Dubai is trying to position itself as a leading commercial hub, making BlackBerry devices popular among its professional elite. — AP

  • E-mail this story
  • Print this story