NEWS Microsoft is telling users of its mobile applications that they can send confidential company information over wireless networks even though the technology they use isn't 100 per cent secure. Microsoft's Smartphone 2002 - formerly known as Stinger - includes a multimode browser that supports both internet and wireless standards (HTML 3.2 and WAP 1.2.1), and includes the corresponding security standard SSL (Secure Socket Layer) and WTLS (Wireless Transport Layer Security). The security architecture uses a two-stage process, with WTLS encrypting traffic from the handset to the WAP gateway. From the WAP gateway the traffic is encrypted with SSL. However, whilst in the WAP gateway, the traffic is unencrypted and vulnerable to hacking. It is a problem that has been known about for years, and many banks with secure WAP applications keep their WAP gateways behind a firewall to reduce their vulnerability to this kind of attack. Jose Lopez, security analyst at Frost and Sullivan, said: "Since cell phone operators want to have some control over the data flow, unlike other standards, the WAP standard forces data to be encrypted at the user level, decrypted at the operator level and then encrypted again." A spokesman for Microsoft said: "Rather than inventing and implementing a new and proprietary security standard for the Smartphone browser, we instead support the existing internet and wireless standards." However, few companies will want to implement any kind of WAP-based solution without an end-to-end security system, and buying their own WAP gateway is an expensive option few will find attractive. This leaves them with the choice of using an HTML browser or nothing at all. Microsoft's spokesman added: "Microsoft is proposing that companies use the protocols, mark-up languages and security standards they are comfortable with. With the Smartphone browser, you can achieve the same level of security you have on regular desktop browsers." It's difficult to tell, until Microsoft's Smartphone launches, whether an HTML-based browser application will be genuinely usable. Existing wireless HTML browsers, however, are extremely cumbersome, and with data downloads being charged by the megabit, they will be expensive.
Security woes surface over Microsoft's Smartphone
There are cracks in WAP
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




