
There are cracks in WAP
By Ben King
Published: 14 February 2002 17:35 GMT
Microsoft is telling users of its mobile applications that they can send confidential company information over wireless networks even though the technology they use isn't 100 per cent secure.
Microsoft's Smartphone 2002 - formerly known as Stinger - includes a multimode browser that supports both internet and wireless standards (HTML 3.2 and WAP 1.2.1), and includes the corresponding security standard SSL (Secure Socket Layer) and WTLS (Wireless Transport Layer Security).
The security architecture uses a two-stage process, with WTLS encrypting traffic from the handset to the WAP gateway. From the WAP gateway the traffic is encrypted with SSL.
However, whilst in the WAP gateway, the traffic is unencrypted and vulnerable to hacking. It is a problem that has been known about for years, and many banks with secure WAP applications keep their WAP gateways behind a firewall to reduce their vulnerability to this kind of attack.
Jose Lopez, security analyst at Frost and Sullivan, said: "Since cell phone operators want to have some control over the data flow, unlike other standards, the WAP standard forces data to be encrypted at the user level, decrypted at the operator level and then encrypted again."
A spokesman for Microsoft said: "Rather than inventing and implementing a new and proprietary security standard for the Smartphone browser, we instead support the existing internet and wireless standards."
However, few companies will want to implement any kind of WAP-based solution without an end-to-end security system, and buying their own WAP gateway is an expensive option few will find attractive. This leaves them with the choice of using an HTML browser or nothing at all.
Microsoft's spokesman added: "Microsoft is proposing that companies use the protocols, mark-up languages and security standards they are comfortable with. With the Smartphone browser, you can achieve the same level of security you have on regular desktop browsers."
It's difficult to tell, until Microsoft's Smartphone launches, whether an HTML-based browser application will be genuinely usable. Existing wireless HTML browsers, however, are extremely cumbersome, and with data downloads being charged by the megabit, they will be expensive.
PHP, MYSQL, OOP Developers for a very large and well known tour operator based in Kent, 20 mins out of Waterloo. PHP, MYSQL, OOP Developers for ...
A new client of mine is looking for a WAP developer for a number of WAP portals and sites they are currently developing. This is initially a ...
Educated to A-level (or with equivalent qualification/experience), you will be part of a team that supports and maintains a technology layer which ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...