The truth about BlackBerry encryption – Our messages are not encrypted

By Benzoon | September 12th, 2011 | 2 Comments »
The truth about BlackBerry encryption – Our messages are not encrypted


Research In Motion’s BlackBerry devices are well-known for it’s security. All of their messages and emails from BlackBerry to BlackBerry are encrypted. However, this is not 100% true. From an article from BerryReview and memoburn, the truth behind the BlackBerry encryption is revealed – not all BlackBerry smartphones are encrypted.

Yes, BlackBerrys using the BlackBerry Enterprise Server (BES) is secured. BES connects to existing corporate email servers like Microsoft Exchange and acts as a relay to allow employees to securely send and receive push-email on the go, with their BlackBerrys. Communications between BES and BlackBerrys are encrypted with Triple DES or AES encryption and only the company running the BES instance have the encryption keys. That means that RIM cannot provide these keys to government organisations.

However, if you are using the BlackBerry Internet Service (BIS), your emails and messages are not encrypted. That’s right, BIS users, your messages are not encrypted. So if you are planning a riot or assassination through your BlackBerry, you’ll get caught.

Unlike BlackBerry to BlackBerry communication on BES, BIS email messages are not encrypted before they travel over a mobile carrier’s network. For BIS users, only the mobile carrier’s standard 3G/2G protection applies.
Regarding this matter, RIM states:

Email messages sent between the BlackBerry Internet Service and the BlackBerry Internet Service subscriber’s BlackBerry smartphone are not encrypted. When transmitted over the wireless network, the email messages are subject to the existing or available network security model(s).

So what about your BlackBerry Messenger messages? Your BBM messages aren’t exactly encrypted as well. To give memoburn some credit, visit their website for more details about whether your BlackBerry messages are encrypted or not.

Sources: BerryReview & memoburn

Besides that, it should be mentioned, that the powerful encryption of the BES is also causing a headache for RIM in some parts of the world. I’m sure you guys remember the dispute between RIM and India. India wanted access to any message that comes from a BlackBerry and then RIM and the Indian government discussed, and discussed again and finally found a solution. Are you satisfied with the encryption of BES and BIS, please let me know in the comments.


  • http://blackberryinsight.com Hendrik

    To bad individual users can’t have their own BES, so they are stuck with BIS. Taking care of the data security on my BlackBerry is important. In fact that’s the reason why I have a BlackBerry in the first place, because it provides security tools and supports security measures. We talked about them years ago in an article about How to secure your BlackBerry.

  • KK

    Though I’m not fond of this article, I will reply to your comment, Hendrik. You can get BES Express. It’s free and it has some (the most essential) BES capabilities. Cheers!




Back to homepage