ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Experts question Java mobile smartcard security

Will Knight ZDNet.co.uk

Published: 17 Nov 1999 18:04 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts have questioned whether the JavaCard technology that has been adopted as the standard for securing GSM (Global System for Mobile Communications) mobile phone communications is actually so secure.

Sun Microsystems revealed Tuesday that its JavaCard architecture is to be applied by mobile phone manufacturers across Europe to enable users to experience mobile banking and e-commerce through the security of Java's architecture.

JavaCard is already used widely throughout the smartcard industry and is touted as a highly secure hardwired solution. Java may be an inherently secure programming language, but security expert Neil Barrett of Information Risk Management believes that this should not fool us into assuming that Java-based smartcard security is infallible. "Part of the reason a smartcard is more secure than a PC is that it's more difficult to get software onto a card than a PC. When you use Java you have a better chance of getting malicious software onto a card. There are any number of malicious applets already out there."

Barrett confirms that few people are trying to hack into smartcards at the moment but says that hackers and phone phreakers are likely to get more involved in this as the technology becomes more common. "The more prevalent a system is, and especially if people are relying on it for things like banking transactions, the more people are going to try to hack, break into and manipulate it."

One ex-phone hacker agrees that this issue should by no means be overlooked. "Java has got things going for it and against it. It wasn't actually designed with security in mind, it was designed to be robust. You can't gain access to hardware that the Java virtual machine says you can't, but most mobile phone manufacturers probably don't manufacture with that in mind. You also have to remember that everything has security weaknesses, some of them just haven't been discovered yet."

A spokesperson for ActiveCard, which develops part of the software architecture of JavaCard technology, claims that JavaCard should be considered solid. He says, "GSM phones featuring JavaCard technology with ActiveCard's digital identity applets put secure, convenient access to e-business transactions. As the mobile commerce market expands, users will require secure authentication solutions."

Sun Microsystems was unavailable for comment.

Take me to Hackers

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 118 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Business Analyst - Finance Analysis

THE MAIN REQUIREMENTS FOR THIS ROLE ARE AS FOLLOWS: - Specific business knowledge & technical knowledge required - Business Analyst experience Strong ...

Commodity Quantitative Developer - Top Investment Bank

You will also be structuring investment bankings most interesting transactions for these corporate and institutional clients. This is a fantastic ...

Support Manager - Financial Software - London - 50/55k

My client specialises in providing payment solutions to large blue chip clients, most notably in the banking sector, they specialise in credit ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment