
Researchers plan to show today how to break the encryption that protects information sent over the General Packet Radio Service (GPRS), a standard commonly used to send data to and from mobile devices, and from other devices such as smart meters. This breach makes it possible to listen in on data communications such as e-mail, instant messages, and Web browsing on smart phones, as well as updates from automated industrial systems.
The researchers, who will make their announcement at the Chaos Communication Camp, a hacker event taking place near Berlin, Germany, previously cracked the Global System for Mobile Communications (GSM), which is used to carry calls among 80 percent of the world's mobile phones. GPRS is an older technology that often supplements GSM, for example when faster 3G connections are unavailable. Smart phones, including the iPhone, use GPRS when operating on Edge networks (when the network connection says "E" rather than "3G"). Phones that don't support 3G use GPRS all the time. Both GSM and GPRS are used worldwide, though in the United States some major carriers, including Verizon and Sprint, use a competing standard.
Phones might be the most familiar devices affected by the research, says Karsten Nohl, founder of Security Research Labs, a Berlin-based research consultancy that conducted the work. But the standard is also used in some cars, automated industrial systems, and electronic tollbooths. "It carries a lot of sensitive data," Nohl says.
Security researchers haven't looked at the GPRS standard much in the past, Nohl says, but since more and more devices are using GPRS, he believes the risk posed by poor security is growing.
Nohl's group found a number of problems with GPRS. First, he says, lax authentication rules could allow an attacker to set up a fake cellular base station and eavesdrop on information transmitted by users passing by. In some countries, they found that GPRS communications weren't encrypted at all. When they were encrypted, Nohl adds, the ciphers were often weak and could be either broken or decoded with relatively short keys that were easy to guess.
The group generated an optimized set of codes that an attacker could quickly use to find the key protecting a given communication. The attack the researchers designed against GPRS costs about 10 euros for radio equipment, Nohl says.
GPRS has not suffered very many security problems in the past, says Jukka Nurminen, a professor of data communications at Aalto University in Finland who spent 25 years at the Nokia Research Center. If the researchers have truly achieved what they claim, Nurminen says, many mobile communications could be much less secure. Depending on mobile operator and subscription plan, some devices maintain a GPRS connection at all times, particularly those whose users access e-mail and instant message applications from their phones.
However, Nurminen adds, it might be possible to mitigate the risk by encrypting communications when they are sent, using common e-mail and Web-browsing tools. He notes that GPRS security is also affected by regulations in different countries, and that some laws undermine security by requiring governments to be able to break into communications if necessary.
The GSM Association, a London-based organization representing mobile operators, handset makers, and other industry interests, regulates GPRS as well as GSM. The organization says it is reviewing Nohl's research but has not yet learned enough to comment.
Nohl says companies will be negligent if they ignore the risks. He suggests that mobile applications take steps now to use encryption such as SSL, which already protects much of the sensitive information sent over the Internet. Nohl hopes that cellular network companies will require better authentication among devices and base stations communicating over GPRS. He also believes the ciphers used by the standard should be upgraded.




















Recently, a leaked image of the Droid Incredible 2 has established one thing for sure, that this handset will be coming Verizon branded. Many rumors have surfaced regarding the branding of the smartphone which is yet to hit the stores. The picture also discloses that this phone will be quire similar to the Incredible S in outer features. The fact that Incredible S holds the same brand is perhaps a plain coincidence besides other similarities. Though, we are not definite whether or not Android 2.3 would be the final OS, the leaked image shows it is running on Android 2.2.1.
VMware, the virtualisation and cloud infrastructure specialist, has launched its VMware View app for the iPad, enabling it to run its program on the device. The VMware View software allows users to remotely access virtual Windows desktops through the device, as well as data from anywhere. Best of all, the app comes free of cost!

Samsung has further expanded its Galaxy brand of Android devices this week with the introduction of three new handhelds, each running various forms of the Android operating system. It's added the Galaxy S II, the Galaxy Mini and the Galaxy S WiFi as an iPod touch competitor. But will Samsung be able to maintain line cohesion as the Android OS evolves and fragments?
With a few small exceptions, MWC this year was all about Android. It's not so much that Android stole the show -- more like it was given the show. Other platforms were there, of course, but their presence didn't move the needle much compared to ubiquity of Google's mobile OS. How much of an edge did this conference give Android over its rival platforms?
Users of certain Samsung phones running the Windows Phone 7 mobile operating system have complained that a recent software update issued by Microsoft has bricked their handsets. It's likely that the update wasn't thoroughly tested and was failing partway through the installation on the Samsung devices, speculated Chris Hazelton, a research director at the 451 Group.


