View Single Post
Old 12-01-13, 06:01   #1
Ladybbird
 
Ladybbird's Avatar
 
Join Date: Feb 2011
Posts: 47,601
Thanks: 27,633
Thanked 14,458 Times in 10,262 Posts
Ladybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond repute

Awards Showcase
Best Admin Best Admin Gold Medal Gold Medal 
Total Awards: 8

Hacker Nokia Caught Wiretapping

Death Twitches: Nokia Caught Wiretapping Encrypted Traffic From Its Handsets

Rick Falkvinge, 11 Jan 2013

Wiretapped Phone





Privacy: Nokia, the cellphone manufacturer, has been listening in to all encrypted communications from its handsets. Every connection advertised as secure – banking, social networks, dating, corporate secrets – has been covertly wiretapped by Nokia themselves and decrypted for analysis.

Security researcher Gaurang posted an article on January 5 about some unexpected behavior with his Nokia handset. It would appear that no matter which browser they used, the traffic would get diverted through Nokia’s servers.

Then, a followup article on January 9 dropped the bomb, and though the article is quite technical: It wasn’t enough that Nokia diverted all traffic from its handsets through its own servers, it also decrypted the encrypted traffic, re-encrypting it before passing it on, issuing HTTPS certificates on the fly that the Nokia phone has been instructed to trust as secure.

This means that Nokia has deliberately been wiretapping all traffic that has been advertised as encrypted on Nokia handsets – including but not limited to banking, dating, and corporate secrets.

This means that Nokia puts itself between your bank and you, and presents itself as YourBank, Inc. to your phone. This wouldn’t normally be possible, if it weren’t for the fact that the phone had been specifically designed for this deceptive behavior, by installing a Nokia signing certificate on the phone.

(The wiretapping is not just limited to encrypted traffic, by the way; Nokia listens to non-encrypted traffic, too. However, in the case of proxying, this can be excused if given a very large benefit of the doubt.)

Nokia has confirmed this behavior in correspondence with TechWeek Europe (my highlight):

“The compression that occurs within the Nokia Xpress Browser means that users can get faster web browsing and more value [...] when temporary decryption of HTTPS connections is required on our proxy servers, to transform and deliver users’ content, it is done in a secure manner”, a Nokia spokesperson told TechWeek Europe.

So why is this a big deal?

It is a big deal because banks rely on having a secure connection all the way to you. As do corporate networks. As do news outlets’ protection of sources. Anybody listening in to the conversation in the middle breaks the whole concept of secrecy – and the phone was specifically designed by Nokia to allow Nokia to listen in without telling you.

My, my. Secure connections are presenting themselves as secure end-to-end, and a handset manufacturer breaches this most basic of trusts? We’d have a very hard time trusting a company that says “yes, we’re listening to all of your encrypted communications, but we’re not doing anything bad with it. No, really.”

If Nokia was in trouble over its handset sales already, this complete breach of trustworthiness has to be a death twitch.
__________________
PUTIN TRUMP & Netanyahu Will Meet in HELL


..................SHARKS are Closing in on TRUMP..........................







TRUMP WARNS; 'There'll Be a Bloodbath If I Don't Get Elected'..MAGA - MyAssGotArrested...IT's COMING


PLEASE HELP THIS SITE..Click DONATE
& Thanks to ALL Members of ... 1..

THIS SITE IS MORE THAN JUST WAREZ...& TO STOP SPAM-IF YOU WANT TO POST, YOUR FIRST POST MUST BE IN WELCOMES
Ladybbird is online now   Reply With Quote