Risk
4/30/2013
11:53 AM
Connect Directly
RSS
E-Mail
50%
50%

Can You Hack This Smartphone App For £10,000?

Redact says its peer-to-peer iPhone messaging app is invulnerable to third-party eavesdropping, and invites you to prove it wrong.

Samsung Galaxy S 4: 11 Clever Tricks
Samsung Galaxy S 4: 11 Clever Tricks
(click image for slideshow)
A British tech firm is so convinced its smartphone messaging app is unbreakably secure it's offering a £10,000 ($15,000) bounty to anyone who can prove it wrong.

If you're feeling up to the challenge, head on over to a micro-site called Modern Day Turing, named in honor of famous British computer scientist and breaker of Wehrmacht codes Alan Turning. (Though the company says the challenge itself is actually modeled on a famous lock puzzle, eventually broken by American locksmith A.C. Hobbs -- though it took him 16 days in that case.)

There, you'll find a way to enter a contest where the ultimate aim is to successfully intercept and then decode any message sent between two specific iPhones through the company's program, the £3.99 Redact Secure Messenger. (So far the app is only available for iOS, though Android, Windows Phone 8 and a desktop versions are also promised.)

[ Would you be just as happy with a less secure messaging app? See 10 Mobile Chat Apps That Beat SMS. ]

Redact says it will pick 20 applicants for the challenge, which will take place at an as-yet unknown London location. Candidates are asked a range of questions on the form, including whether they have specific IT security experience or qualifications. (You have until June 1 to apply.)

The real aim of the stunt seems to be to prove the company's chops as a credible enterprise-level security component. For example, you can get the app gratis in the U.K. if you are a member of Parliament or chief of a big listed British company.

The software is said to create a secure, "triple encrypted" peer-to-peer network connection between two specific iPhones. Only the initial connection is made through a server; that drops out as soon as the link is made. That allows the messages from one device to be sent directly to another, rather than through any third-party servers, which the company alleges is a key weakness of other smartphone messaging systems.

If you delete a message, it will be automatically wiped from the conversation thread of both phones, even if the other party doesn't want you to, and even if it has appeared on their screen. Users access the system by a special entry code, which is not kept or stored anywhere by Redact and thus cannot be hacked off its systems. You also never get a username, which Redacts claims makes it tamper-proof.

Redact is also trying to get accreditation for the system from the Communications Electronic Security Group, the British state agency that looks after the security of all the government's communications and information systems as well as important parts of the country's telecommunication infrastructure. If it does get such a stamp of approval, it could then be sanctioned for use by British civil servants and other members of the public sector. So far, only the BlackBerry 7 OS has passed that test.

"We're pretty confident it can't be done, but obviously, we anticipate tons of people trying," the firm told The Guardian newspaper Tuesday.

"We figure the longer it stays uncracked, the more secure we are."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
5/14/2013 | 2:41:16 PM
re: Can You Hack This Smartphone App For £10,000?
I think that contest like this are great
opportunities to companies to find overlooked threats and vulnerabilities in
their applications and systems. On the other hand it does create a certain
standard to let their industries know they are ready for the next level in
enterprise security. It also seems like a useful mobile applications, and offers
a secure connection. I believe that for this company it is important for them to
prove to the government the reliability of their applications by offering a
bounty for a breech.

Paul Sprague

InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-4350
Published: 2014-09-19
Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.

CVE-2014-4376
Published: 2014-09-19
IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted API arguments.

CVE-2014-4390
Published: 2014-09-19
Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application.

Best of the Web
Dark Reading Radio