Risk
4/30/2013
11:53 AM
50%
50%

Can You Hack This Smartphone App For £10,000?

Redact says its peer-to-peer iPhone messaging app is invulnerable to third-party eavesdropping, and invites you to prove it wrong.

Samsung Galaxy S 4: 11 Clever Tricks
Samsung Galaxy S 4: 11 Clever Tricks
(click image for slideshow)
A British tech firm is so convinced its smartphone messaging app is unbreakably secure it's offering a £10,000 ($15,000) bounty to anyone who can prove it wrong.

If you're feeling up to the challenge, head on over to a micro-site called Modern Day Turing, named in honor of famous British computer scientist and breaker of Wehrmacht codes Alan Turning. (Though the company says the challenge itself is actually modeled on a famous lock puzzle, eventually broken by American locksmith A.C. Hobbs -- though it took him 16 days in that case.)

There, you'll find a way to enter a contest where the ultimate aim is to successfully intercept and then decode any message sent between two specific iPhones through the company's program, the £3.99 Redact Secure Messenger. (So far the app is only available for iOS, though Android, Windows Phone 8 and a desktop versions are also promised.)

[ Would you be just as happy with a less secure messaging app? See 10 Mobile Chat Apps That Beat SMS. ]

Redact says it will pick 20 applicants for the challenge, which will take place at an as-yet unknown London location. Candidates are asked a range of questions on the form, including whether they have specific IT security experience or qualifications. (You have until June 1 to apply.)

The real aim of the stunt seems to be to prove the company's chops as a credible enterprise-level security component. For example, you can get the app gratis in the U.K. if you are a member of Parliament or chief of a big listed British company.

The software is said to create a secure, "triple encrypted" peer-to-peer network connection between two specific iPhones. Only the initial connection is made through a server; that drops out as soon as the link is made. That allows the messages from one device to be sent directly to another, rather than through any third-party servers, which the company alleges is a key weakness of other smartphone messaging systems.

If you delete a message, it will be automatically wiped from the conversation thread of both phones, even if the other party doesn't want you to, and even if it has appeared on their screen. Users access the system by a special entry code, which is not kept or stored anywhere by Redact and thus cannot be hacked off its systems. You also never get a username, which Redacts claims makes it tamper-proof.

Redact is also trying to get accreditation for the system from the Communications Electronic Security Group, the British state agency that looks after the security of all the government's communications and information systems as well as important parts of the country's telecommunication infrastructure. If it does get such a stamp of approval, it could then be sanctioned for use by British civil servants and other members of the public sector. So far, only the BlackBerry 7 OS has passed that test.

"We're pretty confident it can't be done, but obviously, we anticipate tons of people trying," the firm told The Guardian newspaper Tuesday.

"We figure the longer it stays uncracked, the more secure we are."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
5/14/2013 | 2:41:16 PM
re: Can You Hack This Smartphone App For £10,000?
I think that contest like this are great
opportunities to companies to find overlooked threats and vulnerabilities in
their applications and systems. On the other hand it does create a certain
standard to let their industries know they are ready for the next level in
enterprise security. It also seems like a useful mobile applications, and offers
a secure connection. I believe that for this company it is important for them to
prove to the government the reliability of their applications by offering a
bounty for a breech.

Paul Sprague

InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2208
Published: 2014-12-28
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.

CVE-2014-2209
Published: 2014-12-28
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group permissions for a file or directory.

CVE-2014-5386
Published: 2014-12-28
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initial...

CVE-2014-6123
Published: 2014-12-28
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow local users to obtain sensitive credential information by reading installation logs.

CVE-2014-6160
Published: 2014-12-28
IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.