Risk
4/30/2013
11:53 AM
50%
50%

Can You Hack This Smartphone App For £10,000?

Redact says its peer-to-peer iPhone messaging app is invulnerable to third-party eavesdropping, and invites you to prove it wrong.

Samsung Galaxy S 4: 11 Clever Tricks
Samsung Galaxy S 4: 11 Clever Tricks
(click image for slideshow)
A British tech firm is so convinced its smartphone messaging app is unbreakably secure it's offering a £10,000 ($15,000) bounty to anyone who can prove it wrong.

If you're feeling up to the challenge, head on over to a micro-site called Modern Day Turing, named in honor of famous British computer scientist and breaker of Wehrmacht codes Alan Turning. (Though the company says the challenge itself is actually modeled on a famous lock puzzle, eventually broken by American locksmith A.C. Hobbs -- though it took him 16 days in that case.)

There, you'll find a way to enter a contest where the ultimate aim is to successfully intercept and then decode any message sent between two specific iPhones through the company's program, the £3.99 Redact Secure Messenger. (So far the app is only available for iOS, though Android, Windows Phone 8 and a desktop versions are also promised.)

[ Would you be just as happy with a less secure messaging app? See 10 Mobile Chat Apps That Beat SMS. ]

Redact says it will pick 20 applicants for the challenge, which will take place at an as-yet unknown London location. Candidates are asked a range of questions on the form, including whether they have specific IT security experience or qualifications. (You have until June 1 to apply.)

The real aim of the stunt seems to be to prove the company's chops as a credible enterprise-level security component. For example, you can get the app gratis in the U.K. if you are a member of Parliament or chief of a big listed British company.

The software is said to create a secure, "triple encrypted" peer-to-peer network connection between two specific iPhones. Only the initial connection is made through a server; that drops out as soon as the link is made. That allows the messages from one device to be sent directly to another, rather than through any third-party servers, which the company alleges is a key weakness of other smartphone messaging systems.

If you delete a message, it will be automatically wiped from the conversation thread of both phones, even if the other party doesn't want you to, and even if it has appeared on their screen. Users access the system by a special entry code, which is not kept or stored anywhere by Redact and thus cannot be hacked off its systems. You also never get a username, which Redacts claims makes it tamper-proof.

Redact is also trying to get accreditation for the system from the Communications Electronic Security Group, the British state agency that looks after the security of all the government's communications and information systems as well as important parts of the country's telecommunication infrastructure. If it does get such a stamp of approval, it could then be sanctioned for use by British civil servants and other members of the public sector. So far, only the BlackBerry 7 OS has passed that test.

"We're pretty confident it can't be done, but obviously, we anticipate tons of people trying," the firm told The Guardian newspaper Tuesday.

"We figure the longer it stays uncracked, the more secure we are."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
5/14/2013 | 2:41:16 PM
re: Can You Hack This Smartphone App For £10,000?
I think that contest like this are great
opportunities to companies to find overlooked threats and vulnerabilities in
their applications and systems. On the other hand it does create a certain
standard to let their industries know they are ready for the next level in
enterprise security. It also seems like a useful mobile applications, and offers
a secure connection. I believe that for this company it is important for them to
prove to the government the reliability of their applications by offering a
bounty for a breech.

Paul Sprague

InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

CVE-2014-6080
Published: 2014-12-18
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.