Showing posts with label Nokiagate. Show all posts
Showing posts with label Nokiagate. Show all posts

Tuesday, August 18, 2009

Update to Nokiagate

After the summer it's good to catch up what has happened for "Nokiagate" lately. For those who don't know what Nokiagate is, read my posting that started it all and follow the case from here.

I did receive a couple of calls from Nokia during the summer and they were interested to hear my opinion about how they managed the situation and how their processes could be improved. I told them that it appeared as if there was no process at all to handle security reports like this and it took far too long from my initial report before action was taken. After the starting difficulties things began to go smoothly when the conversation channel was opened.

I just ran a quick test with some updated terminals I had available and here are the results (device / firmware version / result):
  • E75 / 110.48.125 / Opens connection without asking permission, content unknown.
  • 5800 / 30.0.011 / Opens connection without asking permission, content unknown.
  • N96 / 30.033 / Account can be created in offline mode, OK.
It looks that E75 and 5800 still go online without asking user's permission. However, new firmware ensures the validity of server certificate and doesn't anymore let me examine the contents, but the connection goes to ccds.serviceactivation.ext.nokia.com. Let's hope they have removed password information form the request as they earlier promised, unfortunately I cannot verify that.


//Harri

Thursday, May 14, 2009

Nokiagate: Nokia busy to fix the solution

Today I had an open and honest discussion with Nokia's representative about the Nokiagate. They have been working hard first to analyze the problem scope and then to fix it. As anyone who has been involved with mobile development surely understands, there is a huge number of different variants (operator, language, region) available for every device and also many variants of the email wizard itself. All the combinations must be fixed. When this job is done, terminal fixes will be published using the suitable channel, which is also device and market dependant. Some devices are likely to require a firmware update to fix the wizard.

The fixed email wizard will no longer send your password data to Nokia's deployment server and there will also be an offline option so that you can create an email account without any communications happening from your terminal to Nokia. To prevent future man-in-the-middle attacks, email wizard will enforce certificate validation that will prevent this kind of network traffic analyzing I've done when investigating this case. This of course raises a question how we will be able to verify that password is removed from the data...

They have also been fixing the server side implementation and current setup no longer tries to log in to your email server. Also a special security audit has taken place to ensure that confidential data really hasn't been stored to the servers. I was told that the result of the audit was that confidential data hasn't been stored, also the logs were not storing the passwords. In addition to that, some server locations have been changed.

I have a feeling that now things are moving to the right direction. There is a bug, nobody denies that. Bug has been analyzed and fixes will be deployed as soon as possible. I'm sure there will be a strict privacy audit for new solutions and hopefully we will not see problems like this again.

//Harri

Monday, April 20, 2009

Nokiagate: my response to some comments

Last week the Nokiagate issue exploded and got attention worldwide. After having read comments and discussions from different sites I must clarify some basic things.

Lots of people have wondered if the communications is encrypted or not. I have already answered this question very clearly, but I will do it again. Connection is encrypted.

Second difficult topic to understand seems to be how email works. To start the wonderful journey into mobile mail, read an old post of mine. Then think for a second what Nokia’s marketing department has tried to communicate for some time: smartphone is an old-fashioned name for a device that has a new name: multimedia computer. That’s the name for a small battery operated pocket sized computer with one special feature, ability to send data and voice over cellular network. Nice little multimedia computer doesn’t require special protocols to access web content (remember WML and WAP?), nor does it require special protocols to access your mailbox. During this year’s Mobile World Congress Nokia’s EVP Anssi Vanjoki admitted that he hates the word “smartphone” and would rather use word “computer”.

Many comments posed a question how mobile phone then could access email without sending credentials to Nokia; after all this case is about the mythical mobile mail, right? If you have a desktop computer made by Dell, do you have to send your credentials to Dell in order to read your email? What about your Fujitsu laptop, did you send your credentials to Fujitsu before email started to work? Of course you didn’t, but you think that in a case of mobile device that has to be done? Well, that's not true.

Also many people told me that this is just how push mail works in general and Blackberry in particular. They have actively forgotten that I was't talking about any “pushmail” solution but wanting to use standard protocols to access my mail, without any mobile buzzwords. Blackberry solution (and many others) include messaging proxy server that sits between your terminal and the email server, that’s fine. When user wants to access his mailbox, messaging proxy does its magic and connects to the email server with the user’s permission. In my case user connects directly to his own mailbox (after the credentials have successfully been sent to an undisclosed server) and no proxy is involved.

So, is it a big deal to send password to a 3rd party server, after all Barack Obama is a well-known Blackberry user and if that’s not a problem for him, is this really a problem for me? Honestly I don’t know about Obama’s email setup and neither do you, but I’m very sure that if somebody in his team someday discovers that his terminal is silently sending stuff abroad that wouldn’t be considered as yet another "these things just happen but our intention was good" case.

//Harri

Friday, April 17, 2009

Nokia's statement about the Nokiagate

I just received Nokia's official statement about the case I reported earlier.

Nokia's statement begin.
A Finnish blogger recently posted on his blogsite that Nokia stores users' credentials in Nokia when they try to configure their email account on their Nokia device using direct IMAP/POP access.

For the mobile email account to be created and for the user to enjoy a seamless mobile email experience, his email credentials (namely email address and password) need to be sent to the mail provider's server. In some cases, the user's credentials are sent directly to the mail provider's server, but in other cases, they securely pass through the Nokia mail server, without actually being stored.

Nokia takes security seriously in all phases of the mobile communication systems development process, and will further investigate this case using our normal processes and comprehensive testing. Also, based on the feedback that we have received, we will look into the possibility of amending the on-device email set-up instructions to ensure that end-user information handling in our devices and services is accurate.
Nokia's statement end.

My comment on that statement:
  • I completely understand and accept the need to ease the email account creation. Despite that, I still feel that sometimes sending credetials to email provider and sometimes sending those to Nokia's server is not acceptable. I want to be in control who gets my credentials.
  • I haven't claimed that Nokia stores user's credentials. I have written that credentials are sent to Nokia - I don't have any idea what happens to credentials after that.
  • I asked if credentials are stored. Now we got a clear answer that credentials are not stored. That's good.

If I may suggest a solution to Nokia, would you consider a solution that
  • tells to user exactly what's going on during the account creation
  • allows user to decide wheter wizard is used or not
  • if wizard is not used, no communications is done to Nokia's servers
  • if wizard is used, only domain part (e.g. gmail.com) is sent to Nokia server

//Harri

Thursday, April 16, 2009

Info about the "Nokiagate"

Today has been an extremely busy day here at Mobilitics and lots of questions have been asked about the Nokiagate, both in post comments and private mail. Let me answer all of those at once.

Yes, Nokia is very much aware of this. I have made a report and they are working on this. Someday they will come out and give comment.

I am not talking here about Nokia Messaging or any other service they are providing. This case is about acessing your mailbox using IMAP without any extra middleware. You input information to connect to your email account and that information goes to Nokia's server. When the deployment server has tested that your account details are OK, information comes back to your terminal and the account is created. Now communication happens between your terminal and the actual email server just as it should.

Having said that, now it must be clear to everybody that Nokia's server is actually logging in to the email account when verifying the credentials. Test sequence includes logging in to both incoming and outgoing services - if that fails, client will prompt you to check credentials. If you want to verify this, you must be able to investigate traffic coming to your email servers.

Yes, according to my tests the verification server is located outside of the European Union, which means that your credentials are also there.

//Harri

Thursday, March 26, 2009

Information about Nokia email case

Quick answers for the impatient readers:
  1. “Yes”
  2. “Yes”
  3. “It’s easy”

Below are my comments to some reactions I have seen regarding this "Nokiagate".

1) You are stupid! Don’t you know there is a new service called “Nokia Messaging”? It has to be able to retrieve your messages from the server!

Yes, I know there is a solution called Nokia Messaging (read more from here), but maybe I wasn’t clear enough in my initial post: I am configuring direct IMAP/POP access to my own/company/organization/whatever email service and I am not using nor planning to use Nokia’s messaging proxy.

Messaging proxy is a piece of software that you can use if you wish, there’s nothing wrong about that. If you want to use that, then you understand and accept that your credentials must be available to proxy - otherwise things will not work. When you signup for such a service, that is made clear to the user and he accepts it. However, this wasn’t the case in my email issue.

After email wizard has finished with the email configuration, all network connections are done from my terminal directly to the IMAP/POP email server, not to any messaging proxy. When I use email, data traffic doesn’t go via Nokia. There is no reason why my credentials should be sent anywhere else than to my email server.

2) Is the data encrypted?
Yes, the data is encrypted. Read next sentence aloud using ironic voice: “When I configure private email account into my phone, my email credentials are sent to Nokia in a secure way.”

3) Can’t believe this! Can I verify this myself?
It’s easy. First of all, you need some solution to intercept all network traffic originating from your terminal. For this purpose I used WebScarab and Wireshark. WebScarab is a tool that creates an HTTP proxy which will allow you to control both HTTP requests and responses. Install, configure and run it in your desktop. Check your desktop’s IP address and port that WebScarab is listening.

Because sniffing cellular network is beyond my skills, I used WiFi as a data bearer (email wizard will silently use cellular network if that is available). To enforce WiFi connection, put your terminal into offline mode and/or remove SIM card. Then configure a WiFi access point that will use your WebScarab desktop as a proxy (you need the IP address and port here).

When you think you are done, launch browser in phone and try to open some site. If you see the request in WebScarab, the configuration is correct. If not....well, I’dont provide support for this setup.

After configuration is working, run email wizard and see what happens.


Request to readers
I don’t have any idea which terminals have this email wizard - and if it exists does it work the same way when configuring an email account. If you find terminals behaving this way (sending passwords), please send terminal information to this post’s comments. Include terminal type and software version (you can see that by going to telephony screen and typing *#0000#).

Update
These are the devices and software versions I've tested and verified password leak:
5800 (20.0.0.12)
N79 (11.049)
E75 (110.48.78)

//Harri

Sunday, March 22, 2009

Why Nokia wants my email password?


Many new Nokia S60 terminals seem to have an "email wizard" that helps the user to configure an email account to the terminal. Wizard prompts the user to give some basic information and then in most cases wizard is able to create account with all the correct settings.

Lets use Nokia 5800, an iconic device that has sold over 1.000.000 units. When you start the email wizard, you will see a screen like this



If I click "Back", wizard closes and email account is not created. Clicking "Start" will continue the wizard, but was that answer also consent to store the personal information? Anyway, there doesn't seem to be a way to create an account without this wizard.

Let's create an account for user test.user@mycompany.com (his password is "topsecret" but I will not tell it to anybody). After you have entered this information, the wizard will open a network connection and make an HTTP request to URL

https://ccds.serviceactivation.ext.nokia.com:443/api/v1/rest/?operation=ccds.provider.determineAccount&applicationCode=email&
address=test.user@mycompany.com&password=topsecret&
mcc=244&mnc=91&carrier=sonera

Nice! I just sent to Nokia my email address, password, operator information and terminal type (in HTTP headers, not visible here). All you Nokia 5800 users around the world: did you know that? I didn't know that, nor did I like it.

Today I had an opportunity to play with a new Nokia E75, phone that's supposed to be THE email device of all business users. First impression with the device is very good, it's solid and snappy. When I checked the email client, it was behaving just as in 5800. When you create an account, wizard will send your sensitive data over the internet to Nokia's server.

When I create an email account that has absolutely nothing to do with Nokia's email services, my user credentials are sent to Nokia's server. I guess that this feature can be a show-stopper in some business environments - "hey, let's create email accounts and send our usernames and passwords to Nokia" doesn't sound that good.

According to my tests it seems that if you want to create an email account without giving your credentials to Nokia, you have two options:
  • you should give a dummy information to the wizard when it is asking for email address and password. Wizard will try to fetch settings from the internet but finally gives up and you can input the data safely.
  • put phone to offline mode when creating the account. That way phone cannot connect to any servers and when wizard notices it, you will be able to enter the email account data without sending it to the Nokia servers.

So finally, here are my questions to Nokia:
  • Why you have created an email wizard that by default sends user's email login information to your server without making that very clear and asking explicit permission to do so?
  • Why there is no option available to create an email account manually, without any wizards?
  • When user starts the wizard and continues from the first screen, does that give permission to Nokia to store my personal information?
  • If my personal information was stored to Nokia's servers because I've used email wizard to create an email account, how can I get my data removed from the server?
  • How do you use my personal data, collected from email wizard?

Update: Read also my follow up post.
Update 2: I'm trying to give answers to readers' questions here.
Update 3: Nokia's official statement is here.

//Harri