> What is the reason Palm has not given the destop applcations source.
> Or if its there can some one tell me where i can find it.

        I'm sure everyone's already seen this, but..

        http://msgs.securepoint.com/cgi-bin/get/bugtraq0102/116.html

        And yes, Palm Desktop 4.01 has fixed this, however, it's important
to note to your userbase that they should upgrade, since the 4.0 Palm
Desktop is what ships with most current/new Palm devices these days. I've
tested it on 4.0, and the flaw is there, but it is not possible using the
same mechanics to bypass it in 4.01. Great fast turnaround, Palm.

        Incidentally, what's the scoop with the "enhanced encryption" of
the OS4 model? Why are the records still stored as plain text in the pdb?
As I begin to add support for this in pilot-link, I'm pondering a way to
"Do This Right(tm)" from the desktop and conduit side of things,
potentially rebuilding the record space as encrypted.

        As another developer friend of mine recently put it:

        "This is very misleading to the consumer.  It's a little more
         secure than a document placed face down on your desk."


/d



-- 
For information on using the Palm Developer Forums, or to unsubscribe, please see 
http://www.palmos.com/dev/tech/support/forums/

Reply via email to