Risk
4/30/2013
11:53 AM
Connect Directly
RSS
E-Mail
50%
50%

Can You Hack This Smartphone App For £10,000?

Redact says its peer-to-peer iPhone messaging app is invulnerable to third-party eavesdropping, and invites you to prove it wrong.

Samsung Galaxy S 4: 11 Clever Tricks
Samsung Galaxy S 4: 11 Clever Tricks
(click image for slideshow)
A British tech firm is so convinced its smartphone messaging app is unbreakably secure it's offering a £10,000 ($15,000) bounty to anyone who can prove it wrong.

If you're feeling up to the challenge, head on over to a micro-site called Modern Day Turing, named in honor of famous British computer scientist and breaker of Wehrmacht codes Alan Turning. (Though the company says the challenge itself is actually modeled on a famous lock puzzle, eventually broken by American locksmith A.C. Hobbs -- though it took him 16 days in that case.)

There, you'll find a way to enter a contest where the ultimate aim is to successfully intercept and then decode any message sent between two specific iPhones through the company's program, the £3.99 Redact Secure Messenger. (So far the app is only available for iOS, though Android, Windows Phone 8 and a desktop versions are also promised.)

[ Would you be just as happy with a less secure messaging app? See 10 Mobile Chat Apps That Beat SMS. ]

Redact says it will pick 20 applicants for the challenge, which will take place at an as-yet unknown London location. Candidates are asked a range of questions on the form, including whether they have specific IT security experience or qualifications. (You have until June 1 to apply.)

The real aim of the stunt seems to be to prove the company's chops as a credible enterprise-level security component. For example, you can get the app gratis in the U.K. if you are a member of Parliament or chief of a big listed British company.

The software is said to create a secure, "triple encrypted" peer-to-peer network connection between two specific iPhones. Only the initial connection is made through a server; that drops out as soon as the link is made. That allows the messages from one device to be sent directly to another, rather than through any third-party servers, which the company alleges is a key weakness of other smartphone messaging systems.

If you delete a message, it will be automatically wiped from the conversation thread of both phones, even if the other party doesn't want you to, and even if it has appeared on their screen. Users access the system by a special entry code, which is not kept or stored anywhere by Redact and thus cannot be hacked off its systems. You also never get a username, which Redacts claims makes it tamper-proof.

Redact is also trying to get accreditation for the system from the Communications Electronic Security Group, the British state agency that looks after the security of all the government's communications and information systems as well as important parts of the country's telecommunication infrastructure. If it does get such a stamp of approval, it could then be sanctioned for use by British civil servants and other members of the public sector. So far, only the BlackBerry 7 OS has passed that test.

"We're pretty confident it can't be done, but obviously, we anticipate tons of people trying," the firm told The Guardian newspaper Tuesday.

"We figure the longer it stays uncracked, the more secure we are."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
5/14/2013 | 2:41:16 PM
re: Can You Hack This Smartphone App For £10,000?
I think that contest like this are great
opportunities to companies to find overlooked threats and vulnerabilities in
their applications and systems. On the other hand it does create a certain
standard to let their industries know they are ready for the next level in
enterprise security. It also seems like a useful mobile applications, and offers
a secure connection. I believe that for this company it is important for them to
prove to the government the reliability of their applications by offering a
bounty for a breech.

Paul Sprague

InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVE-2012-5487
Published: 2014-09-30
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVE-2012-5488
Published: 2014-09-30
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVE-2012-5489
Published: 2014-09-30
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.