On Tue, Sep 26, 2000 at 11:21:01AM -0400, Dave Lippincott wrote:

> a) who isn't aware of the weak security on the Palm?  I noticed it the day I
> opened my PalmPilot Pro.  Those agencies that require data securty use 3rd
> party applications to secure or encrypt data on the Palm and not a button to
> 'hide' private records.

Most users don't know much about security.  Just as I suspect most
readers wouldn't know if a physical Abus or Medeco lock was more
secure.

Further, the only use of the password is to unlock the Palm.  How many
(really) keep their palm locked?

And the greater problem is that hotsyncing exposes all the records
unencrypted (barring 3rd party apps), so a pilot-xfer -u attack would
yield everything on the palm including the unsaved preferences DB.

> b) Why do they have to make their 'announcment' sound like the sky is
> falling?

Then it wouldn't be hype.  Or spin.

> What it really amounted to was a scare ad.  I'd have a little more respect
> for a company that doesn't hit me with a baseball bat before asking me to
> purchase (or just use) their product.  (IMHO)

Actually securing data is a problem on the palm.  You want strong
passwords, but graffiti makes this difficult for most users - making
them visible creates problems, then they are stored in memory you
can't always control (and thus wipe).

OTOH, the palm is much more secure because it is with you and doesn't
form a connection unless you tell it to, so while I would worry about
a PGP Passphrase on any Windows system (PRZ properly went on about
insecurity of timesharing UNIX systems), on the Palm it would be hard
to intercept.


-- 
For information on using the Palm Developer Forums, or to unsubscribe, please see 
http://www.palmos.com/dev/tech/support/forums/

Reply via email to