Firstly, emails should not be exchanged between 2 parties without strong encryption if security is critical (especially if they're being sent between servers). Messages are usually exchanged between servers in plain text or unecrypted form and many people have an opportunity to intercept them in transit (not just the ISPs in question).
Secondly, RIM's servers do not see messages in their unencrypted form. If you use a blackberry with BES (which is what virtually every government and businesses uses if they use blackberry), the message is encrypted between the blackberry and your mail server, i.e., RIM never sees the plaintext version of the email. They can't simply hand it over to the government. They don't even know who it is being sent to.
Now I suppose you might theorize that blackberry put a backdoor in their encryption software. However, this is pretty absurd for two reasons. One: blackberry's whole business depends on people being able to trust the encryption. They would lose lots of business if it ever leaked out. Two: If backdoors are what you fear, then you really need to examine _all_ devices, software, services, etc -- not just blackberries (and I'm certain RIMM has recieved far more scrutiny being the prefer provided for numerous security concious entities). By this same rationale, the French shouldn't use Exchange Server, Lotus Notes, Cisco routers, etc because they can't be absolutely certain no one has put in backdoors.
Reader Comments (Page 1 of 1)
Pete L @ Jun 20th 2007 10:22AM
@elfguy:
Firstly, emails should not be exchanged between 2 parties without strong encryption if security is critical (especially if they're being sent between servers). Messages are usually exchanged between servers in plain text or unecrypted form and many people have an opportunity to intercept them in transit (not just the ISPs in question).
Secondly, RIM's servers do not see messages in their unencrypted form. If you use a blackberry with BES (which is what virtually every government and businesses uses if they use blackberry), the message is encrypted between the blackberry and your mail server, i.e., RIM never sees the plaintext version of the email. They can't simply hand it over to the government. They don't even know who it is being sent to.
Now I suppose you might theorize that blackberry put a backdoor in their encryption software. However, this is pretty absurd for two reasons. One: blackberry's whole business depends on people being able to trust the encryption. They would lose lots of business if it ever leaked out. Two: If backdoors are what you fear, then you really need to examine _all_ devices, software, services, etc -- not just blackberries (and I'm certain RIMM has recieved far more scrutiny being the prefer provided for numerous security concious entities). By this same rationale, the French shouldn't use Exchange Server, Lotus Notes, Cisco routers, etc because they can't be absolutely certain no one has put in backdoors.