Slashdot Log In
A Device to Grab Data From Cell Phones
Posted by
Soulskill
on Sat Aug 30, 2008 12:20 PM
from the yoink dept.
from the yoink dept.
what about writes
"Apparently there is a quick, simple, and undetectable way to grab all of your cellphone data. CNet reports on the Cellular Seizure Investigation (CSI) Stick, developed for law enforcement but available to the public, which 'connects to the data/charging port and will seamlessly grab e-mails, instant messages, dialed numbers, phone books and anything else that is stored in memory. It will even retrieve deleted files that have not been overwritten. And there is no trace whatsoever that the information has been compromised, nor any risk of corruption. This may be especially troublesome for corporate employees and those that work for government agencies.' I use mobile knox, a secure storage application, for my important data, but I would be very upset if somebody grabbed my telephone list, SMS, or anything else from my locked phone."
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
This only works on SOME phones (Score:5, Insightful)
Phones without a data port are immune.
Phones whose firmware will not send a particular piece of data over the data port are immune as long as the firmware isn't updated. Updating the firmware leaves a trace.
This goes to show that in many cases, physical access is ultimate access.
I see a market for "secure" phones where the data part of the data/charging port is disabled unless you plug in a key or type in a code. Many companies will gladly pay for such a device.
Re:This only works on SOME phones (Score:5, Informative)
I see a market for "secure" phones where the data part of the data/charging port is disabled unless you plug in a key or type in a code. Many companies will gladly pay for such a device.
You know what those "secure" phones are called? Blackberries. Go buy one today!
On a blackberry, you can have all content on the phone strongly encrypted with AES. If your company has a blackberry enterprise server, you can even make this mandatory and prevent the user from disabling content encryption.
If content encryption is on, then the blackberry won't send data via the data port or bluetooth until the password is entered. Enter the wrong password 10 times and the blackberry securely wipes itself.
Despite the proliferation of mobile phones & wireless email, no one comes close to the blackberry platform for features & security. Not iphone, not windows mobile, not nokia. Some very smart people at RIM have looked at wireless email from end-to-end. The blackberry platform has also been audited from end-to-end by many governments and tech experts. What RIM really needs is a good marketing campaign to establish themselves as a "cool" brand.
Parent
you have it backwards (Score:4, Insightful)
Despite the proliferation of mobile phones & wireless email, no one comes close to the blackberry platform for features & security. Not iphone, not windows mobile, not nokia. Some very smart people at RIM have looked at wireless email from end-to-end.
Um- wrong. Blackberry wanted to get government contracts, so they went through all the government security requirements.
You make it sound like this is some sort of rocket science. It's preposterous to suggest that only RIM has the talent to design a "secure" phone. It's not a matter of talent; it's a matter of whether or not the market demands it. We've seen it with the iPhone; after the initial crazy rush for v1.0, v2 has much more for enterprise users.
What RIM really needs is a good marketing campaign to establish themselves as a "cool" brand.
You incorrectly assume that RIM wants to compete in a "cool" market. Many companies purposefully restrict the market they target.
Parent
How much? Where? (Score:3, Interesting)
Re:How much? Where? (Score:5, Informative)
I have a couple of these at work, since my job is as a forensics investigator, and they're nifty, but they're very limited in what you can do with them since they only support Motorola and Samsung. There are better tools out there:
PDA Seizure, Cell Seizure, Pilot-Link (Open Source), BitPIM (Open Source), ForensicSIM, etc.
Parent
Re: (Score:3, Informative)
It is a forensic product. Any product in that field that changes the evidence is worthless, therefore it is entirely appropriate that it does not write anything at all to the phones.
Security Cameras, Data Sucks, I'm Not Surprised (Score:4, Insightful)
If they can make this (Score:3, Insightful)
Then why is it so hard for me to sync my phone?!
Probable Cause and Warrants (Score:3, Informative)
In the US, we used to have this requirement that the government protect our rights:
Without probable cause and a legitimate warrant based on it, there is no reasonable search or seizure, no usable evidence. There's only an armed gang assaulting and violating their victim.
A fancy new way to invade privacy is just an expensive and effective battering ram.
Re: (Score:3, Informative)
Re:Probable Cause and Warrants (Score:5, Insightful)
Clarence Thomas, as everyone not blinded by Republican loyalty knows, isn't a "Constitutional" justice. He's a rightwing pawn.
Statements like this is why you're a commie stooge, Doc. Clarence Thomas has been on the side of individual rights far more often than Ginsburg, Souter, Stevens, or Breyer.
Kelo vs Connecticut...who sided with government power and who sided with individual property rights?
Heller vs DC...who sided with government police power and who sided with an individual's right to self defense?
Raich vs US...who sided with personal growth and consumption of marijuana and who sided with the government's prosecution of such under the Commerce Clause?
As for the expectation of privacy when crossing the border, there has NEVER been an implied or explicit right. The US government has always maintained the power to search your belongings on entry. Your allegation that Thomas is somehow throwing out the Constitution with this decision illustrates your basic ignorance on the Constitution, Constitutional law, and Clarence Thomas...in other words, par for the course for you.
Parent
why are you letting strangers have your phone (Score:3, Interesting)
Of all the things you can worry about, this seems to be one of the sillier ones - a phone is one thing pretty much never out of sight or touch in public. How is anyone going to plug in anything without your permission?
Look to your Bluetooth stack if you are concerned about data leakage.
Re: (Score:3, Insightful)
Re: (Score:3, Insightful)
You want you data secured? Keep it on a secure server somewhere. Access it in a way that doesn't leave copies on your phone.
So, how does one exactly go about dialing a number without leaving a trace on the phone?
Re: (Score:3, Insightful)
Sign up with a dialing/switchboard service that uses voice recognition, maybe?
suggestModerate(parent, -1, "D'oh");
this.append(smiley);
Re:Wait... "troublesome for corporate employees"? (Score:5, Insightful)
You completely missed the point. This is not about the employee being able to keep their actions private from the world, or even their own employer. It is about the company being able to keep their actions private from the world, which obviously includes the actions of all of their employees.
It is a completely reasonable expectation, and indeed quite desirous by corporations, that an employee be able to maintain some level of privacy (and security) from the rest of the world. So when the article mentions that it is "troublesome for corporate employees" it is really talking about the implications for security for the entire company.
Parent
Re: (Score:3, Insightful)
I think its great. Theres now a way to copy DRM-laiden MP3s and ringtones from your phone.
Re:Non free is always this way. (Score:5, Insightful)
Parent
Re:Troll, mod down (Score:5, Insightful)
Parent
Plot Device Failure. (Score:3, Insightful)
This device will never be used to solve a real crime. Cell phone companies already keep the required records for billing. This will simply allow TSA and other would be snoops to dig into people's private business. I had to laugh when I saw this:
Re:Plot Device Failure. (Score:5, Funny)
That is precisely the sort of crap they spooned out when Verichip tried to persuade parents it was a good idea to have their kids RFID chipped ("If your kid is lost or kidnapped, they can be located!").
And that, my friends, was just the first salvo in the attempt to get people-chipping popularly accepted.
As I once said, the day they start chipping people is the day I start offering my services to remove them and feed them to the migrating geese that pass through our area, in little balls of bread dough.
Parent
Re: (Score:3, Funny)
Because compliance with the government's requirements are enforced by large men with guns and the power to throw people in jail forever (ask Qwest's former CEO), and compliance with your requirements... isn't.
Re:oye! (Score:5, Insightful)
I always knew that cell phones are vulnerable, but to know there is a device which can basically clone your data out, with NO trace, that's downright scary! Even when LOCKED? We should start reading our contracts and our EULAs on our phone, somehow, somewhere, there's got to be something to rely on legally, if this can happen.
Such a device is called a "computer", and many people already own one. By means of a secondary device, called a "USB cable", one can attach a computer to a cell phone and read the contents from it.
If you read the "instruction manual" that comes with your cell phone, you can see plainly that a cable can be connected between the phone and the computer and the contents read from it. No phone manual I have ever read says anything about authentication of the USB cable connection. Therefore you have already been informed of as much as you need to know, legally.
Parent
Re: (Score:3, Insightful)
Do you mean the product should be illegal, or the act of using the product as it is intended?
This is being marketed as a forensic product. The primary user of this device is going to be a forensic technician in the field. That usually implies crime scenes, etc. There are no problems legally in that context as the technician clearly has rights to be there, or is working in a lab on evidence.
So the product itself is legal as any use in a forensic capacity does not violate the 4th amendment. There are quit
Re:unfortunately, I use a blackberry! (Score:3, Interesting)
Where all the content is strongly encrypted with AES. Maybe you shouldn't have bought that iphone if you were concerned about security!
They have a model for the Blackberry in the works. Since this device is designed for forensic investigation by either law enforcement or corporate compliance investigators, I would not be surprised if it hooks into low level OS calls put in place for this purpose. The NSA has a back door into virtually all systems out there.