Showing posts with label twitter. Show all posts
Showing posts with label twitter. Show all posts

Thursday, January 01, 2009

Is Opera Mini on your Symbian phone secure?

I tweeted recently about loving the Opera Mini web browser I installed on my Nokia E71 smartphone.

Twitter user, e71nokia, says, 'Beware!'

One of the responses I received came from a Twitter user called 'e71nokia'. The response warns me that Opera Mini is supposedly not secure, and that only the Nokia browser should be used for sensitive information...



I'm deeply suspicious of a Twitter profile that has absolutely NO information about the person. Here's a screenshot of the profile page:



Note that 'e71nokia is following three people, and is being followed by four. There is NO information about this person. Nada. This leads me to believe that it's just some arbitrary person who may be a Nokia enthusiast. But certainly not an officially sanctioned Nokia spokesperson.

So I decided to check out this claim.

IS Opera Mini on my E71 secure? 

Am I in danger of having my details nabbed by hackers?

Here are my findings.

Using the search string, 'is opera mini secure', I Googled the issue.

Dev.Opera.Com says, 'You can trust Opera Mini to be secure'

The Dev.Opera.Com website, in an article dated 25 October 2007, explicitly states the following: 
Note: Security is an important matter, which Opera takes very seriously. The connection between the Opera Mini client and server is always encrypted, whether the original site is HTTP or HTTPS, therefore> you can trust Opera Mini to be secure.
Opera Mini Help says, 'Information is encrypted', but only in 'advanced versions of Opera Mini 3.0 and newer versions'.

Let's go next to Opera Mini itself... to the horse's mouth, so to speak.

In the 'Opera Mini Help' section, the FAQ has a section devoted to 'Security'. Here's what it says:
Q: Can I browse securely with Opera Mini?
A: Yes.
Q: Does Opera Mini support encrypted connections?
A: Yes. Information sent between your handset and the Web site is encrypted in the advanced version of Opera Mini 3.0 and newer versions.

In the basic version of Opera Mini 3.0, and in older versions, there is no encryption between your handset and the Opera Mini servers. See a more detailed explanation here.
That proviso is important. If you're NOT running a version of Opera Mini HIGHER THAN 3.0, your browsing is vulnerable to snooping. If you ARE running a later version, your browsing IS secure. Point blank.

Wikipedia says 'the connection [...] is always encrypted', but, Opera Mini 'does not offer true, end-to-end security'.

Finally, in the interests of being safe, I turned to the Wikipedia entry on Opera Mini.

Here's what section 3.2 Privacy and Security has to say:
Privacy and security

When using Opera Mini 4.0 or 3.0 Advanced, the connection between the mobile device and the proxy server is always encrypted for privacy and security. The encryption key is obtained on the first start by requesting that the user press random keys a certain number of times.[45] When using Opera Mini 3.0 Basic, the connection is not encrypted. Opera Mini has received some criticism because it does not offer true, end-to-end security when visiting encrypted sites such as PayPal.com.[46] When visiting an encrypted web page, the Opera Software company's servers decrypt the page, then re-encrypt it themselves, breaking end-to-end security.[47]


I'm certainly no authority on this. So my reading is open to question. As far as I can make out, what this means is that the connection between the information on my E71 and the particular website is ALWAYS intermediated by the Opera Mini servers.

This takes place through an encrypted connection AT ALL TIMES.

The one 'breaking' of security comes not in transit, but within the Opera Mini servers, between Opera Mini and the site in question... BUT this 'break' is merely to do with decrypting of the information for Opera itself to parse it. It remains encrypted to third parties.

My conclusion: Opera Mini IS safe, even though there are end-to-end security issues.

From my readings, I'm concluding that Opera Mini is indeed safe, and that the end-to-end issues don't render data vulnerable to attack, thanks to Opera Mini's data transfer being 'always encrypted'.

Is Twitter user e71nokia trustworthy?

Coming full circle to Twitter user, 'e71nokia', my guess is that his or her intentions are good. And that they're offering a conservative reading of the 'end-to-end' security 'break'. I'm suspecting that they're saying it's better to be safe than sorry. Which is a great bit of advice. 

However, I STILL don't trust an entity that offers no information about itself. I WANT e71nokia to offer proper details. A site to visit. Credentials. An explanation of why they're on Twitter. It's NOT good enough to have a blank profile doling out potentially harmful advice.

Is my understanding of the issue correct? IS Opera Mini safe for sensitive transactions?

Regarding the securty of Opera Mini... Is my understanding correct? Are there any Opera Mini boffs who can offer better clarity? This is a huge issue. If my Opera Mini transactions aren't secure, I need to know that. And I need to know about workarounds. Thoughts?

ShareThis