All the latest UK technology news, reviews and analysis

RIM woes continue as researchers discover PlayBook flaws

by Phil Muncaster

11 Aug 2011

Comment: 1

  • Tweet this

RIM PlayBook

Security researchers are urging organisations wanting to implement the BlackBerry PlayBook tablet to hold off until the operating system and some of its key technologies have stabilised, and more is known about potential security holes.

A new paper by information assurance and penetration testing firm NGS Secure revealed several minor flaws about which RIM has already been notified, as well as potential areas where more may exist in the future.

NGS research director Andy Davis told V3 that the PlayBook was rushed out owing to commercial pressures, meaning that some functionality, such as the ability to communicate natively with the Blackberry Enteprise Server, was left out.

"We're saying to businesses looking to adopt the PlayBook that they should be a bit cautious because it's an unknown quantity as key functionality has not yet been released," he said. "Commercial pressures to get this functionality out may have a negative effect on security."

Among the minor vulnerabilities discovered by NGS is a flaw in the PlayBook's built-in web browser which could enable "a more detailed view of the file system than was intended by RIM".

The research paper also discovered that the HDMI video port could trigger a software vulnerability in the device, although Davis admitted that RIM is still trying to determine the seriousness of this flaw.

"Our main focus in the research was identifiying the attack surface, finding where the vulnerabilities might be and where to focus future research," he said.

"Yes, there are vulnerabilities, although nothing massively critical, but there is an indication that there may be more."

RIM had not responded to a request for comment at the time of writing.

NGS' warning comes just weeks after the PlayBook became the only tablet to be approved for use by the US federal government, having gained the FIPS 140-2 accreditation.

It's been a tough day for RIM, which was leapfrogged by ZTE in Gartner's latest global smartphone rankings and now sites in sixth place.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

2%

14%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Functional Oracle Support Analyst

Functional Oracle Support Analyst - EBS Financials, Support...

Oracle E-Business Suite Technical Consultant

Oracle E-Business Suite Technical Consultant - EBS...

Oracle Applications DBA

Oracle Applications DBA - East London - All salaries...

Oracle Functional Consultants

Oracle Functional Consultants - Financial - Project Accounting...

To send to more than one email address, simply separate each address with a comma.