>> I guess what it comes down to is that if someone wants
>> access to the data, they're going to do have to do more
>> than just turn on the handheld and browse around, they're
>> going to have to locate the hotsync machine and grab
>> the password during a hotsync.
>
>Read the advisory.  :)   No PC HotSync machine needed, just 
>bring along your
>Palm running NotSync:
>
>"Facing the two devices head-to-head, run the HotSync 
>application on the
>target Palm device and initiate an "IR to a PC/Handheld" 
>HotSync. NotSync,
>running on the other device, will obtain the legitimate user's encoded
>password block, decode the password, and display the result on the
>screen."

Didn't notice that.  Still, most attacks are where you left your handheld
lying out somewhere, and someone casually picks up the device and browses
around on it.  I can see the potential of people doing the IR NotSync with
their Palms, but they have to get ahold of your Palm first.  And if you're
running a third-party security app (there are many, but Brian Schau's app
PalmLock is a pretty decent one), with the IR recieve turned off in the
background...that'd be quite frustrating.  =)

-Rus

>
>
>Joseph Koral
>[EMAIL PROTECTED]

-- 
For information on using the Palm Developer Forums, or to unsubscribe, please see 
http://www.palmos.com/dev/tech/support/forums/

Reply via email to