Stricter voicemail security cuts cellphone hacking
Forced use of passwords makes it harder to snoop into accounts
By Roland Lindala-Haumont, CBC News
Posted: Jul 7, 2011 4:08 PM ET
Last Updated: Jul 7, 2011 4:18 PM ET
Actor Hugh Grant looks at his mobile phone as he stands in front of placard in support of the "Hacked off" campaign on July 6 in London. Grant was allegedly one of the targets of voicemail hacking by News of the World reporters. Peter Macdiarmid/Getty ImagesWith sensational headlines about the News of the World phone hacking scandal coming out of Britain, many may wonder how private voicemails were accessed a few years ago and if such a thing could still happen today.
Phone security in the U.K. and Canada has improved since private investigators were allegedly paid to hack into the voicemail accounts of Milly Dowler, a 13-year old schoolgirl who was murdered in 2002; the families of the victims of the July 7, 2005, London transit bombing attacks and the families of British soldiers killed in Iraq.
'Wireless carriers have certainly come a long way from the days when voicemail could be accessed without a password.'—Security expert Sahba Kazerooni
News of the World has also been accused of targetting the voicemail accounts of celebrities and politicians.
In the half-decade since most of the phone hacking allegedly occurred, cellphone companies began to more strictly enforce voicemail security.
Much of the alleged voicemail hacking that occurred in the U.K. simply could not happen today. At the time of Milly Dowler's kidnapping and murder, many British wireless carriers used default passwords that customers never bothered to change or allowed the password feature to be bypassed entirely.
But now, major cellphone companies in Canada and the U.K. force all customers to input a secret password before they can access their voicemail.
"Wireless carriers have certainly come a long way from the days when voicemail could be accessed without a password," said mobile security expert Sahba Kazerooni, director of professional services at Toronto-based security consulting firm Security Compass.
Still, it is difficult to ensure customers follow cellphone companies' advice to use more secure passwords instead of ones that might be easy for a would-be hacker to guess, such as a date of birth, a street address or the last four digits of a person's telephone number.
Onus on phone users
According to Kazerooni, "the types of vulnerabilities that remain are ones that are much more difficult to mitigate," since the onus is on customers to choose adequate passwords.
The limiting of passwords to a range between 0-9 and not allowing the inclusion of letters or special characters also "makes guessing of brute forcing of passwords easier," he said.
Newer technologies also present threats to mobile security. While noting that there is no apparent trend similar to the News of the World hacking scandal in Canada, Dave Black of the RCMP's technical security branch told CBCNews.ca that the rise of the smartphone means there are more opportunities for hackers to go after the "computers connected to our hip pocket."
"As computers they contain a lot of data, so that makes them increasingly attractive," he said.
For example, Kazerooni pointed to the increasingly used visual voicemail technology, a smartphone feature that transcribes audio voicemail messages into text, likening it to e-mail.
"Information that's left on voicemail is often sensitive in nature, since the assumption is that only the intended recipient can hear it," he said. "People often have the habit of leaving SIN or credit card numbers on a voicemail message."
'Like putting it in a sealed letter'
The threat is similar to sending e-mail, he said, where anyone who has access to an email account can see the private information.
"Transcribing that information and sending it over e-mail is like putting it in a sealed envelope and dropping it in a mailbox," said Kazerooni.
The security expert has a few recommendations for wireless carriers, including "enforcing long and complex passwords, and requiring users to change their password on a regular basis."
Share Tools
Top News Headlines
- Unknown remains found on Dellen Millard's farm
- Police searching the farm of Dellen Millard, the 27-year-old charged with first-degree murder after the remains of Ancaster, Ont., man Tim Bosma were discovered, have found other remains on the property, but it's unclear if they are human or animal. more »
- Canadian on EI shut out amid foreign worker influx
- A jobless Canadian IT professional who is collecting employment insurance is upset because he now suspects several recent jobs he applied for went to temporary foreign workers. more »
- Can the Senate fire a senator?
- An expert on parliamentary rules says the Senate has the power to turf a senator from the chamber, as long as a majority approves the expulsion, and as long as there is cause. more »
- Nahlah Ayed: Vote-wary Iranians mull Ahmadinejad's successor
- Iranians go to the polls in less than four weeks to choose a new president. The reform movement is still smarting from its bitter defeat four years ago, but the jockeying for power is no less intense, Nahlah Ayed reports. more »
Must Watch
Latest Technology & Science News Headlines
- Xbox launch Tuesday highly anticipated
- Microsoft's next-generation Xbox expected to be revealed Tuesday, and anticipation for the entertainment console's latest evolution is running high. more »
- Astronaut Chris Hadfield adjusts to 'earthling' life
- Canada's space ambassador, Chris Hadfield, is still readapting to life on this planet after spending 146 days in zero gravity as commander of the International Space Station. For now, though, he's taking his homecoming one step at a time. more »
- Bell Mobility to appeal ruling in 911 lawsuit
- Bell Mobility says the company plans to appeal a Northwest Territories Supreme Court ruling that says the company is liable for charging 911 fees to customers that aren't receiving the service. more »
- Anteater's birth in female-only pen stumps zoo staff
- Confused Connecticut conservation officers are wondering how a female anteater, who has given birth at the centre, conceived without a male in the pen. more »
Bob McDonald's Blog
Chris Hadfield: The gravity of gravity May. 17, 2013 9:58 AM After five months of being Superman and a media superstar, Canadian astronaut Chris Hadfield is now beginning the challenging task of adapting his mortal body and brain to life back on Earth.
Quirks & Quarks
- May 18: Apps for Apes May. 17, 2013 4:26 PM Scientists at more than 2 dozen zoos around the world, including the Toronto Zoo, have been using computer tablets to stimulate our bright orange primate cousins, the orangutans. And the orangutans have been loving it.
Latest Features
- Unknown remains found on Dellen Millard's farm
- Canadian on EI shut out amid foreign worker influx
- Central Newfoundland digs out from freak snowfall
- Petition looks to rename Victoria Day
- Missing Toronto woman's parents unfazed by Millard link
- Vancouver man attacked, killed in Costa Rica
- Jeep driver apologizes after stunt kills Edmonton woman
- Rob Ford should resign if allegations true, councillors say
- Can the Senate fire a senator?

