Feeds

Nokia decrypts browser traffic, assures public not to worry

It’s acceleration, not snooping, say Finns

The essential guide to IT transformation

Just as Nokia announces numbers that look like it may avoid irrelevance, the mobile supplier has become embroiled in a privacy row centered on the behavior of its browsers.

The brouhaha hit the wires when Unisys Global Services India security architect Gaurang Pandya wrote up his investigations into the behavior of his Nokia Asha phone.

Discovering that browser traffic was being diverted to proxy servers owned by Nokia – a common behavior in the mobile world designed to improve browser performance on skinny mobile data links – Pandya began investigating what else was happening to his traffic.

The results are documented here. In brief, Pandya accuses the vendor of staging a man-in-the-middle attack against its own users: even for HTTPS traffic (his test case was https://www.google.com), he writes, the phone sends a DNS request to the Nokia-owned cloud13.browser.ovi.com domain.

This raised the question of how the ovi.com server was handling certificates. By packet-sniffing the traffic, Pandya identified Nokia certificates that the phone was pre-configured to trust – with the result that the substitution of the ovi.com server for Google didn’t throw out a security warning.

His conclusion is that this behavior gives Nokia full, unencrypted access to browser traffic.

According to TechWeek Europe, Nokia has agreed that the diversion takes place, to allow it to compress Xpress mobile browser traffic for acceleration. The company denies storing the data, and says that none of the traffic is visible to any of its staff.

“Importantly, the proxy servers do not store the content of web pages visited by our users or any information they enter into them. When temporary decryption of HTTPS connections is required on our proxy servers, to transform and deliver users’ content, it is done in a secure manner,” the vendor told TechWeek Europe.

The row comes as Nokia announced what looks like a turnaround, releasing financials showing a profit on smartphone sales, compared to an October forecast for a 10 percent loss. It announced fourth-quarter sales of 4.4 Lumia units and 9.3 of the low-end Asha smartphones. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
6 Obvious Reasons Why Facebook Will Ban This Article (Thank God)
Clampdown on clickbait ... and El Reg is OK with this
So, Apple won't sell cheap kit? Prepare the iOS garden wall WRECKING BALL
It can throw the low cost race if it looks to the cloud
EE fails to apologise for HUGE T-Mobile outage that hit Brits on Friday
Customer: 'Please change your name to occasionally somewhere'
Time Warner Cable customers SQUEAL as US network goes offline
A rude awakening: North Americans greeted with outage drama
We need less U.S. in our WWW – Euro digital chief Steelie Neelie
EC moves to shift status quo at Internet Governance Forum
BT customers face broadband and landline price hikes
Poor punters won't be affected, telecoms giant claims
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.