lunarlander Blackberry Key 2 Lite

Last updated
May 5, 2019
Phone brand
Blackberry
Phone model
KEY2 LE
Phone unlock
Biometric security
    • Fingerprint(s)
SIM card lock
Not protected by a PIN code
Find my Phone
Off (disabled)
Security & Privacy Apps
Still trying out different solutions
Browser
none
File and Photo backup
google drive

lunarlander

Level 1
Thread author
Verified
Oct 8, 2017
30
Still trying to find protection. Have no root firewall blocking all apps and system apps except for gmail. does what I require it to do.

There is a security vulnerability in the Initial Setup Process and I was attacked during the PlayStore Auto Update process. PlayStore only uses HTTPS for PAID APPS. Had to do 3 factory resets till I realized that the only way out was to go AirPlane mode, stop PlayStore Auto Updates, install no root firewall APK as the very first thing, and block all non-essential processes. Similar to how you harden a PC. Then update at my leisure. When hardening a PC, you don't go online until the PC is hardened and you are good and ready. The same principle applies here.

I think BlackBerry should take the machine offline first. And let users decide when they are ready to go online. If they are serious about security.

Have read in an old wilderssecurity.com post that most andriod av's are ineffective. But I realize that cellphone attacks have risen A LOT in the last 2 years since that post.

I have tested out MalwareBytes and ZoneAlarm on my old Samsung JBOSS and they couldn't remove the Remote Control malware/software that I was infected with. So I am skeptical.

PlayStore Play Protect is a joke: there are lots of Parental Control - Remote Monitoring Tools that will pass that test. And if any was downloaded as part of the PlayStore Auto Update, you would be setup for remote monitoring from the get go. Luckily, Androids do not give root access until you root it deliberately, and the factory image is thus good. So a Factory Reset will always give you a clean start. Otherwise, you'd have to use another OS image.

In summary, the BlackBerry KEY2 is not as secure as I had wished it to be. The weakest link is the Android OS's setup procedure, and non-HTTPS auto update. And as we all know, all you need is one weak link - it doesn't matter if everything else is securely built. That's a problem all defenders face. Advantage: attacker.
 
Last edited:

lunarlander

Level 1
Thread author
Verified
Oct 8, 2017
30
Also looking for a VPN. However I seldom use hotspots. But it should be a necessity.
The Find my Device is working, just doesn't give me Reset capability with the Trust - which I removed, trust can be abused. There isn't much on the phone, just my emails.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top