You are here: silicon.com > Software > Security Strategy

Security Strategy

Security woes surface over Microsoft's Smartphone

There are cracks in WAP

By Ben King

Published: 14 February 2002 17:35 GMT

Microsoft is telling users of its mobile applications that they can send confidential company information over wireless networks even though the technology they use isn't 100 per cent secure.

Microsoft's Smartphone 2002 - formerly known as Stinger - includes a multimode browser that supports both internet and wireless standards (HTML 3.2 and WAP 1.2.1), and includes the corresponding security standard SSL (Secure Socket Layer) and WTLS (Wireless Transport Layer Security).

The security architecture uses a two-stage process, with WTLS encrypting traffic from the handset to the WAP gateway. From the WAP gateway the traffic is encrypted with SSL.

However, whilst in the WAP gateway, the traffic is unencrypted and vulnerable to hacking. It is a problem that has been known about for years, and many banks with secure WAP applications keep their WAP gateways behind a firewall to reduce their vulnerability to this kind of attack.

Jose Lopez, security analyst at Frost and Sullivan, said: "Since cell phone operators want to have some control over the data flow, unlike other standards, the WAP standard forces data to be encrypted at the user level, decrypted at the operator level and then encrypted again."

A spokesman for Microsoft said: "Rather than inventing and implementing a new and proprietary security standard for the Smartphone browser, we instead support the existing internet and wireless standards."

However, few companies will want to implement any kind of WAP-based solution without an end-to-end security system, and buying their own WAP gateway is an expensive option few will find attractive. This leaves them with the choice of using an HTML browser or nothing at all.

Microsoft's spokesman added: "Microsoft is proposing that companies use the protocols, mark-up languages and security standards they are comfortable with. With the Smartphone browser, you can achieve the same level of security you have on regular desktop browsers."

It's difficult to tell, until Microsoft's Smartphone launches, whether an HTML-based browser application will be genuinely usable. Existing wireless HTML browsers, however, are extremely cumbersome, and with data downloads being charged by the megabit, they will be expensive.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
IP Engineer : CCIP CCNP : Contract : London

ExpertiseDNS,DHCP,POP3,SMTP,HTTP/HTTPS,SNMP, TELNET,SSH,FTP,SSL Expertise in Unix System Design and Administration Expertise in Cluster Design and ...

Spanish Speaking Data Network Engineer- N.London- Cisco- 35k

Ability to demonstrate strong technical skills in two or more of the following areas: -Physical layer LAN and WAN protocols (including but not ...

Weblogic Analyst

SSL / TLS / Digital Certificates. Government Gateway Weblogic Implementation and Configuration Analyst - Public Sector - Leeds Mandatory skills - ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: